Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Windows >> Adobe PDF Plug-In < 8.0


Vulnerability Assessment Details

Adobe PDF Plug-In < 8.0

Vulnerability Assessment Summary
Checks version of nppdf32.dll

Detailed Explanation for this Vulnerability Assessment

Summary :

The browser test on the remote Windows host is affected by multiple
issues.

Description :

The version of Adobe PDF Plug-In installed on the remote host is
earlier than 7.0.9 / 8.0 and reportedly fails to properly sanitize
input to the 'FDF', 'XML', or 'XFDF' fields used by its 'Open
Parameters' feature. By tricking a user to access a specially-crafted
link and depending on the browser with which the test is used, a
remote attacker may be able to leverage these issues to conduct
arbitrary code execution, denial of service, cross-site script
forgery, or cross-site scripting attacks against a user on the remote
host.

See also :

http://www.wisec.it/vulns.php?page=9
http://www.securityfocus.com/archive/1/455801/30/0/threaded
http://www.kb.cert.org/vuls/id/815960
http://www.adobe.com/support/security/advisories/apsa07-01.html
http://www.adobe.com/support/security/bulletins/apsb07-01.html

Solution :

Either disable displaying of PDF documents in web browsers or upgrade
to Adobe Reader / Acrobat 8.0 / 7.0.9 or later.

Network Security Threat Level:

High / CVSS Base Score : 7.0
(AV:R/AC:L/Au:NR/C:P/I:P/A:P/B:N)

Networks Security ID: 21858

Vulnerability Assessment Copyright: This script is Copyright (C) 2007 Tenable Network Security

Cables, Connectors


Juniper EX4300-48T-AFO 48P 1GbE 2 PSU Switch picture

Juniper EX4300-48T-AFO 48P 1GbE 2 PSU Switch

$279.00



Juniper (EX2200-C-12T-2G) 12 Port Managed Compact Switch  picture

Juniper (EX2200-C-12T-2G) 12 Port Managed Compact Switch 

$75.00



Juniper Networks EX3400 48-Port 4-SFP PoE+ Running Junos P/N: EX3400-48P Tested picture

Juniper Networks EX3400 48-Port 4-SFP PoE+ Running Junos P/N: EX3400-48P Tested

$399.99



Juniper EX2200-24P-4G 24 Port PoE Gigabit Switch SAME DAY SHIP 1 YEAR WARRANTY picture

Juniper EX2200-24P-4G 24 Port PoE Gigabit Switch SAME DAY SHIP 1 YEAR WARRANTY

$39.99



Juniper (EX2200-C-12P-2G) 12 Port Managed Compact Switch picture

Juniper (EX2200-C-12P-2G) 12 Port Managed Compact Switch

$70.00



Juniper EX3300-24P Juniper 24 Port Gigabit PoE+ Switch - Same Day Shipping picture

Juniper EX3300-24P Juniper 24 Port Gigabit PoE+ Switch - Same Day Shipping

$103.00



Juniper EX4300-48T 48 Port Gigabit 4 QSFP 40G Dual Power Supply Network Switch picture

Juniper EX4300-48T 48 Port Gigabit 4 QSFP 40G Dual Power Supply Network Switch

$179.00



Juniper EX3400-48P 48-Ports 1GB PoE+ & 4-Ports SFP+ & 2-Ports QSFP+ & 1AC Switch picture

Juniper EX3400-48P 48-Ports 1GB PoE+ & 4-Ports SFP+ & 2-Ports QSFP+ & 1AC Switch

$299.95



JUNIPER EX4550-32F-AFO 32-PORT 1/10GbE SFP+ ETHERNET SWITCH Tested/Reset picture

JUNIPER EX4550-32F-AFO 32-PORT 1/10GbE SFP+ ETHERNET SWITCH Tested/Reset

$749.99



Juniper EX4300-48T 48-Ports Ethernet Switch w/Dual Power picture

Juniper EX4300-48T 48-Ports Ethernet Switch w/Dual Power

$269.00



Discussions

No Discussions have been posted on this vulnerability.