Name:
Adobe.Reader.CollectEmailInfo.JavaScript.Method.Bu
Released Date:
Feb 15 2008
Severity:
critical
CVE:
2007-5659
2008-0655

FortiGuard Center > Vulnerability Encyclopedia


In-Depth Analysis

Description
This indicates an attempt to exploit a buffer overflow vulnerability in the Adobe PDF reader JavaScript engine.

By passing overly long parameters to the method "Collab.collectEmailInfo()", an attacker can execute arbitrary code on a vulnerable computer. To exploit this the attacker must trick the victim into opening a maliciously crafted PDF document.
 
Impact
System Compromise: remote attackers can gain control of vulnerable systems.
 
Affected Products
Versions older than Adobe Reader and Acrobat before 8.1.2
Aliases
Adobe.Reader.CollectEmailInfo.JavaScript.Method.Buffer.Overflow
References
http://www.frsirt.com/english/advisories/2008/0425
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5659
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0655
http://www.zerodayinitiative.com/advisories/ZDI-08-004.html
Recommended Actions
Update to at least version 8.1.2

 
 
SITE MAP  |  LEGAL NOTICES

      © 2003 FORTINET INC. ALL RIGHTS RESERVED