Nortel Response to Adobe Reader Vulnerabilities (APSA08-01)
| Description: |
Adobe has recently released fixes for multiple vulnerabilities that exist in Adobe Reader and Adobe Acrobat Professional when viewing PDFs. Some Nortel products contain this software as a component any may be affected. This bulletin provides a multi-product consolidated response for the Nortel products which are potentially affected by these vulnerabilities. The Adobe security advisory is available at: http://www.adobe.com/support/security/advisories/apsa08-01.html Before taking any action please ensure that you are viewing the latest official version of this security advisory by referencing http://www.nortel.com/securityadvisories Some of the issues addressed by apsa08-01 have unknown impacts while others can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a user's system. Following is an overview of the vulnerabilities: 1) Multiple boundary errors in several unspecified JavaScript methods can be exploited to cause stack-based buffer overflows via a specially crafted .PDF file. Successful exploitation allows execution of arbitrary code. 2) An unspecified insecure JavaScript method in EScript.api can be exploited to execute arbitrary code via a specially crafted .PDF file. 3) An error in the loading of "Security Provider" libraries can be exploited to execute arbitrary code by e.g. tricking a user into opening a .PDF file in a directory that contains a malicious library with the same filename as a "Security Provider" library. 4) The insecure JavaScript method "DOC.print()" can be exploited to silently print a specially crafted PDF file. Other vulnerabilities also exist, for which no details are currently available. The vulnerabilities affect the following versions: * Adobe Reader 8.1.1 and earlier * Adobe Acrobat Professional, 3D and Standard 8.1.1 and earlier For more information: Please contact your next level of support or visit http://www.nortel.com/contact for support numbers within your region. Nortel securi |
| Type: |
Security Advisories |
| Number: |
2008008642, Rev 1 |
| Status: |
Retired |
| Date: |
2008-07-03 |