Adobe Reader multiple vulnerabilities(APSB08-19), update to 8.1.3

Bug #293861 reported by Fumihito YOSHIDA
254
Affects Status Importance Assigned to Milestone
Ubuntu Japanese Kaizen Project
Fix Released
High
Jun Kobayashi

Bug Description

--Upstream advisory:-----------------------------------------------
http://www.adobe.com/support/security/bulletins/apsb08-19.html

CVE number: CVE-2008-2992, CVE-2008-2549, CVE-2008-4812, CVE-2008-4813, CVE-2008-4817, CVE-2008-4816, CVE-2008-4814, CVE-2008-4815

Critical vulnerabilities have been identified in Adobe Reader and Acrobat 8.1.2 and earlier versions. These vulnerabilities would cause the application to crash and could potentially allow an attacker to take control of the affected system.

Adobe recommends users of Acrobat and Adobe Reader update their product installations using the instructions above to protect themselves from potential vulnerabilities.

This update resolves multiple input validation errors that could potentially lead to code execution. (CVE-2008-4812)

This update resolves multiple input validation issues that could potentially lead to remote code execution. (CVE-2008-4813)

This update resolves an input validation issue in a JavaScript method that could potentially lead to remote code execution. (CVE-2008-2992)

An input validation issue in the Download Manager used by Adobe Reader that could potentially lead to remote code execution during the download process has been resolved. (CVE-2008-4817)

A Windows-only issue in the Download Manager used by Adobe Reader that could lead to a user’s Internet Security options being changed during the download process has been resolved. (CVE-2008-4816)

This update resolves an input validation issue in a JavaScript method that could potentially lead to remote code execution. (CVE-2008-4814)

This update resolves a potential Unix-only privilege escalation issue (CVE-2008-4815)

This update resolves a publicly-published denial of service issue. (CVE-2008-2549)
-------------------------------------------------------------------------

Adobe Reader 8.1.3 has been released. We have to bump 8.1.2_SU1 => 8.1.3.

Fumihito YOSHIDA (hito)
Changed in ubuntu-jp-improvement:
importance: Undecided → High
status: New → Triaged
Revision history for this message
Fumihito YOSHIDA (hito) wrote :
Jun Kobayashi (jkbys)
Changed in ubuntu-jp-improvement:
assignee: nobody → jkbys
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.