English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Adobe Reader/Acrobat Multiple Vulnerabilities


Secunia ID

SA48733

CVE-ID

CVE-2012-0724, CVE-2012-0725, CVE-2012-0751, CVE-2012-0752, CVE-2012-0753, CVE-2012-0754, CVE-2012-0755, CVE-2012-0756, CVE-2012-0767, CVE-2012-0768, CVE-2012-0769, CVE-2012-0772, CVE-2012-0773, CVE-2012-0774, CVE-2012-0775, CVE-2012-0776, CVE-2012-0777

Release Date

11 Apr 2012

Last Change

19 Apr 2012

Criticality

Highly Critical

Solution Status

Vendor Patch

Software

Adobe Acrobat 9.x
Adobe Acrobat X 10.x
Adobe Reader 9.x
Adobe Reader X 10.x

Where

From remote

Impact
System access

This covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user.

Cross-Site Scripting

Cross-Site Scripting vulnerabilities allow a third party to manipulate the content or behaviour of a web application in a user's browser, without compromising the underlying system.

Different Cross-Site Scripting related vulnerabilities are also classified under this category, including "script insertion" and "cross-site request forgery".

Cross-Site Scripting vulnerabilities are often used against specific users of a website to steal their credentials or to conduct spoofing attacks.

Exposure of sensitive information

Vulnerabilities where documents or credentials are leaked or can be revealed either locally or from remote.

Security Bypass

This covers vulnerabilities or security issues where malicious users or people can bypass certain security mechanisms of the application.

The actual impact varies significantly depending on the design and purpose of the affected application.

Description

Multiple vulnerabilities have been reported in Adobe Reader and Adobe Acrobat, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, gain knowledge of potentially sensitive information, and compromise a user's system.

1) An integer overflow error when handling Control Value Table (cvt) streams containing a MINDEX opcode (0x26) can be exploited to cause a buffer overflow by e.g. tricking a user into opening a malicious PDF file containing specially crafted embedded TrueType Fonts (TTF).

2) An unspecified error when handling JavaScript can be exploited to corrupt memory.

3) The application loads executables (e.g. msiexec.exe) in an insecure manner. This can be exploited to run an arbitrary program by tricking a user into e.g. opening a file located on a remote WebDAV or SMB share and repairing the installation.

4) An unspecified error within the JavaScript API can be exploited to corrupt memory.

NOTE: This vulnerability affects the Macintosh and Linux versions only.

5) The application bundles a vulnerable version of Adobe Flash Player.

For more information:
SA48033
SA48281
SA48623

NOTE: This vulnerability affects Adobe Reader X and Adobe Acrobat X only.

Successful exploitation of vulnerabilities #1 - #4 may allow execution of arbitrary code.

The vulnerabilities are reported in the following products:
* Adobe Reader X versions 10.1.2 and prior for Windows and Macintosh.
* Adobe Reader versions 9.5 and prior for Windows and Macintosh.
* Adobe Reader versions 9.4.6 and prior for Linux.
* Adobe Acrobat X versions 10.1.2 and prior for Windows and Macintosh.
* Adobe Acrobat versions 9.5 and prior for Windows and Macintosh.

Solution

Apply updates.

Adobe Reader X versions 10.1.2 and prior for Windows and Macintosh:
Update to version 10.1.3

Adobe Reader versions 9.5 and prior for Windows and Macintosh:
Upgrade to version Adobe Reader X 10.1.3 or update to version 9.5.1.

Adobe Reader versions 9.4.6 and prior for Linux:
Update to version 9.5.1.

Adobe Acrobat X versions 10.1.2 and prior for Windows and Macintosh:
Update to version 10.1.3.

Adobe Acrobat versions 9.5 and prior for Windows and Macintosh:
Update to version 9.5.1.

Reported by

1) Peter Vreugdenhil, HP DVLabs
3) Mitja Kolsek, ACROS Security

The vendor credits:
2) Soroush Dalili
4) James Quirk, Los Alamos

Original Advisory

Adobe:
http://www.adobe.com/support/security/bulletins/apsb12-08.html

ACROS Security:
http://blog.acrossecurity.com/2012/04/adobe-reader-x-1012-msiexecexe-planting.html

DVLabs:
http://dvlabs.tippingpoint.com/advisory/TPTI-12-03