Adobe_Acrobat_Reader_(Unix)_Shell_Metacharacter_Code_Execution_attack

Strike ID:
G04-3hi01
CVSS:
10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
False Positive:
t
Variants:
1
Year:
2004

Description

There is a vulnerability in the way Adobe Acrobat Reader validates a filename within the uudecode function. A specially crafted filename can allow an attacker to execute arbitrary programs with privileges equivalent to the user that opened the malicious PDF document. In the attack case, the vulnerable software will report that it was not able to open the PDF document that was sent to the victim. The attacker supplied code will then execute arbitrary commands on the target with the privileges of the victim. The behaviour of the target depends on the commands being executed.

CVE

References

Bid