Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:STC:ADOBE:PDF-EBUK-FORMSTR

Severity

High

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Adobe Acrobat Reader EBook Format String Vulnerability

Release Date

2013/06/27

Update Number

2276

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Adobe Acrobat Reader EBook Format String Vulnerability


This signature detects attempts to exploit a known vulnerability against Adobe Acrobat Reader Ebook. A successful attack can lead to arbitrary code execution.

Extended Description

Adobe Acrobat/Acrobat Reader is reported prone to a remote format string vulnerability. The vulnerability is present in the ETD file parser when processing tag values. Reports indicate that the values supplied for certain tags are used as the format string in an unspecified formatted output function. Because an attacker can control the format string and the variables passed to the formatted output function, this vulnerability may be exploited to write to arbitrary locations within the memory of the process.

Affected Products

  • Adobe Acrobat 3.0.0
  • Adobe Acrobat 3.1.0
  • Adobe Acrobat 4.0.0
  • Adobe Acrobat 4.0.0 5
  • Adobe Acrobat 4.0.0 5c
  • Adobe Acrobat 4.0.5 A
  • Adobe Acrobat 5.0.0
  • Adobe Acrobat 5.0.5
  • Adobe Acrobat 6.0.0
  • Adobe Acrobat 6.0.1
  • Adobe Acrobat 6.0.2
  • Adobe Reader 3.0.0
  • Adobe Reader 4.0.0
  • Adobe Reader 4.0.0 5
  • Adobe Reader 4.0.0 5c
  • Adobe Reader 4.0.5 A
  • Adobe Reader 5.0.0
  • Adobe Reader 5.0.5
  • Adobe Reader 5.1.0
  • Adobe Reader 6.0.0
  • Adobe Reader 6.0.1
  • Adobe Reader 6.0.2

References

  • BugTraq: 11934
  • CVE: CVE-2004-1153

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out