CAN-2005-2470 Adobe Acrobat Reader plug-in buffer overflow

Bug #2057 reported by Daniel Robitaille
10
Affects Status Importance Assigned to Milestone
acroread (Ubuntu)
Fix Released
Medium
MOTU
Warty
Invalid
Medium
Trent Lloyd
Hoary
Invalid
Medium
Trent Lloyd
Breezy
Fix Released
Medium
Trent Lloyd

Bug Description

It seems the Acrobat reader found in the Multiverse repository in all versions of Ubuntu (Warty, Hoary, and Breezy) is vulnerable to CAN-2005-2470. The only advice from Adobe is to upgrade to Adobe Reader 7.0.1

http://www.adobe.com/support/techdocs/321644.html

CVE References

Changed in acroread:
assignee: nobody → motu
Revision history for this message
Trent Lloyd (lathiat) wrote :

Thanks for the report Daniel.

This is a binary package, only fix is to upgrade to the latest version, which is unacceptable for a stable release.

Leaving as new for breezy as this could potentially be updated before release but I'm not doing that now.

Changed in acroread:
assignee: nobody → lathiat
status: New → Rejected
assignee: nobody → lathiat
status: New → Rejected
Revision history for this message
Trent Lloyd (lathiat) wrote :

7.0.1 has now been uploaded to breezy, thanks to Reinhard Tartler

Changed in acroread:
assignee: nobody → lathiat
status: New → Fixed
status: New → Fixed
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.