heise Security IT security news and services at heise Security UK
12 March 2008, 16:04

Vulnerability in UNIX version of Adobe Acrobat Reader

Adobe has published a security advisory concerning a vulnerability in UNIX version 8.1.2 of its Acrobat Reader. The vendor writes that a flaw in the launcher script, acroread, can be exploited to escalate system privileges and edit or delete files. Temporary data are saved with the wrong privileges, allowing symlink attacks to be executed. The flaw can only be exploited locally. No update has yet been made available, but Adobe says it is working on one.

Advertisement

See also:

(mba)

  • Bookmark & Share
  • digg this
  • submit to slashdot
  • post to delicious
  • StumbleUpon
  • submit to reddit