Upstream information
Description
The JavaScript for Acrobat API in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 does not properly implement the (1) Privileged Context and (2) Safe Path restrictions for unspecified JavaScript methods, which allows remote attackers to create arbitrary files, and possibly execute arbitrary code, via the cPath parameter in a crafted PDF file. NOTE: some of these details are obtained from third party information.NVD CVSS v2 Base Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Novell/SUSE information
Novell Bugzilla entry: 546083 SUSE Security Advisories:- SUSE-SA:2009:049, published Mon, 26 Oct 2009 12:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| openSUSE 10.3 |
| Builds |
| SUSE Linux Enterprise Desktop 10 SP2 for AMD64 and Intel EM64T SUSE Linux Enterprise Desktop 10 SP2 for x86 |
| sled10-sp2.x86-64 sled10-sp2.x86 ZYPP Patch Nr: 6584 |
| SUSE Linux Enterprise Desktop 10 SP3 for AMD64 and Intel EM64T SUSE Linux Enterprise Desktop 10 SP3 for x86 |
| sled10-sp3.x86-64 sled10-sp3.x86 ZYPP Patch Nr: 6583 |
| SUSE Linux Enterprise Desktop 10 SP2 for AMD64 and Intel EM64T SUSE Linux Enterprise Desktop 10 SP2 for x86 |
| sled10-sp2.x86-64 sled10-sp2.x86 ZYPP Patch Nr: 6582 |
| SUSE Linux Enterprise Desktop 10 SP3 for AMD64 and Intel EM64T SUSE Linux Enterprise Desktop 10 SP3 for x86 |
| sled10-sp3.x86 sled10-sp3.x86-64 ZYPP Patch Nr: 6585 |
List of products where fixes are in QA
SUSE Linux Enterprise Desktop 10 SP3 for AMD64 and Intel EM64TSUSE Linux Enterprise Desktop 10 SP3 for AMD64 and Intel EM64T
SUSE Linux Enterprise Desktop 10 SP3 for x86
SUSE Linux Enterprise Desktop 10 SP3 for x86
