Welcome, Guest

Nortel Response to Adobe APSB09-06 - Security Updates for Adobe Reader and Acrobat

Description: A critical vulnerability has been identified in Adobe Reader 9.1 and Acrobat 9.1 and earlier versions. This vulnerability (CVE-2009-1492) would cause the application to crash and could potentially allow an attacker to take control of the affected system. A second vulnerability has also been reported that appears to affect Adobe Reader for UNIX only (CVE-2009-1493). Some Nortel products contain this software as a component and thus are potentially affected by the vulnerabilities addressed. This bulletin provides a multi-product consolidated response for the Nortel products which are potentially affected. This bulletin addresses the following common vulnerability identifier: 1) CVE-2009-1492 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1492) The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments. 2) CVE-2009-1493 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1493) The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 8.1.4 and 9.1 on Linux allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument. Before taking any action please ensure that you are viewing the latest official version of this security advisory by referencing http://www.nortel.com/securityadvisories
Type: Security Advisories
Number: 2009009540, Rev 1
Status: Retired
Date: 2009-12-10


Bulletin Downloads
Title Extension File Size Language
    Nortel Response to Adobe APSB09-06 - Security Updates for Adobe Reader and Acrobat
Checksum: 0984980c9eb6fa3badb1047710823e0b  [MD5]
[pdf] 22589 bytes English  




Associated Products
BroadBand STP
Business Communications Manager 200
Business Communications Manager 400
Business Communications Manager 1000
CallPilot
CDMA Networks
CDMA SuperNode Data Manager
Circuit Switching
Communication Server 2000
Communication Server 2000 Core Manager
Communication Server 2000 Session Server Trunks
Communication Server 2000-Compact
Communication Server 2100
DMS-100 SSP
DMS-100/200 Local Switching Systems
DMS-250
DMS-500
DMS-Global Services Platform
DMS-STP
DMS-STP/SSP IntegratedNode (INode)
Extended Peripheral Module (XPM)
GSM Networks
 
GSM-UMTS Mobile Switching Center Server
GSM-UMTS SuperNode Data Manager
Integrated Access - Cable
Integrated Element Management System (IEMS)
Media Processing Server (MPS) 1000
Media Processing Server (MPS) 500
Meridian SL-100
Optivity Telephony Manager for SL-100
Packet Transit - AAL2
Packet Transit - IP
Packet Trunking - AAL1
Periphonics Speech Platform
Self-Service Portfolio
Spectrum Peripheral Module (SPM)
Speech and Self-Service
SuperNode Data Manager
Survivable Remote Gateway 200/400
UMTS Networks
Universal Access - AAL1
Universal Access - IP
VoIP Infrastructure Solutions
XA-Core