—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA1
Liebe Kolleginnen und Kollegen,
soeben erreichte uns nachfolgendes Sun Security Advisory. Wir geben
diese Informationen unveraendert an Sie weiter.
Bitte beachten Sie, dass dies ein Update des Advisories ist, das die
folgenden Aenderungen betrifft:
Mit diesem Update stellt Sun Patches fuer Solaris 10 zur Verfuegung.
CVE-2009-0198 / CVE-2009-0509 / CVE-2009-0510 / CVE-2009-0511 /
CVE-2009-0512 / CVE-2009-0888 / CVE-2009-0889 / CVE-2009-1855 /
CVE-2009-1856 / CVE-2009-1857 / CVE-2009-1858 / CVE-2009-1859 /
CVE-2009-1861 / CVE-2009-2028 – Schwachstellen in Adobe Reader und Adobe
Acrobat
In Adobe Reader und Adobe Acrobat befinden sich mehrere
Schwachstellen, u. a. auch Integer und Heap Overflows beim Verarbeiten
von JPEG2000 Bildern. Angreifer koennen diese Schwachstellen dazu
ausnutzen, beliebigen Code mit den Rechten des Benutzers auszufuehren,
wenn dieser eine entsprechend aufgebaute PDF-Datei oeffnet. Dies kann
z.B. als Attachment einer E-Mail oder innerhalb einer HTML-Seite sein
oder auch auf Wechselmedien oder Netzwerklaufwerken.
Die Schwachstelle laesst sich ebenfalls ausnutzen, wenn der Windows
Indexing Service oder andere lokale Suchmaschinen Code des Adobe
Reader verwenden, um Informationen aus Dokumenten zu extrahieren und
die Suchmaschine auf eine entsprechend aufgebaute PDF-Datei trifft.
Betroffen sind die folgenden Software Pakete und Plattformen:
Package SUNWacroread
SPARC Plattform
* Solaris 10 ohne Patch 121104-10
Vom Hersteller werden ueberarbeitete Pakete zur Verfuegung gestellt.
Hersteller Advisory:
http://sunsolve.sun.com/search/document.do?assetkey=1-66-265330-1
(c) der deutschen Zusammenfassung bei DFN-CERT Services GmbH; die
Verbreitung, auch auszugsweise, ist nur unter Hinweis auf den Urheber,
DFN-CERT Services GmbH, und nur zu nicht kommerziellen Zwecken
gestattet.
Mit freundlichen Gruessen,
Michael Groening, DFN-CERT
– —
Michael Groening (Incident Response Team)
DFN-CERT Services GmbH, https://www.dfn-cert.de, Phone +49 40 808077-555
Sitz / Register: Hamburg, AG Hamburg, HRB 88805, Ust-IdNr.: DE 232129737
Sachsenstrasse 5, 20097 Hamburg/Germany, CEO: Dr. Klaus-Peter Kossakowski
Automatische Warnmeldungen https://www.cert.dfn.de/autowarn
Solution Type Sun Alert
Solution 265330 : Multiple Security Vulnerabilities in Adobe Reader
for Solaris 10 May Allow Execution of Arbitrary Code or Cause Denial of
Service (DoS) (Adobe Security Bulletin APSB09-07)
Related Categories
* Home>Content>Sun Alert Criteria Categories>Security
* Home>Content>Sun Alert Release Phase>Resolved
Bug ID
6854786
Product
Solaris 10 Operating System
Date of Workaround Release
11-Aug-2009
Date of Resolved Release
01-Sep-2009
SA Document Body
Multiple security vulnerabilities in Adobe Reader and Acrobat:
1. Impact
Multiple security vulnerabilities in Adobe Reader and Acrobat versions
prior to 9.1.2, 8.1.6, and 7.1.3 may allow a remote unprivileged user
to execute arbitrary code with the privileges of the user running Adobe
Reader or crash the Adobe Reader application, thereby causing a Denial
of Service (DoS) condition.
These issues are also described in the following documents:
APSB09-07 at: http://www.adobe.com/support/security/bulletins/apsb09-07.htm
l
US-CERT-TA09-161A at: http://www.us-cert.gov/cas/techalerts/TA09-161A.html
CVE-2009-0198 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-01
98
CVE-2009-0509 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-05
09
CVE-2009-0510 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-05
10
CVE-2009-0511 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-05
11
CVE-2009-0512 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-05
12
CVE-2009-0888 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-08
88
CVE-2009-0889 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-08
89
CVE-2009-1855 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-18
55
CVE-2009-1856 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-18
56
CVE-2009-1857 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-18
57
CVE-2009-1858 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-18
58
CVE-2009-1859 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-18
59
CVE-2009-1861 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-18
61
2. Contributing Factors
These issues can occur in the following release:
SPARC Platform
* Solaris 10 without patch 121104-10
Note 1: Solaris 8, Solaris 9, Solaris 10 on the x86 platform, and
OpenSolaris do not ship Adobe Reader and therefore are not affected by
this issue.
Note 2: All versions of Adobe Reader 9 and Adobe Acrobat 9 prior to
9.1.2 are affected by these issues. All versions of Adobe Acrobat 8
prior to 8.1.6 and all versions of Adobe Acrobat 7 prior to Acrobat
7.1.3 are affected by these issues as well.
To determine the version of Adobe Reader installed on the system, the
following command can be run:
$ /usr/bin/acroread -version
7.0.1
Earlier versions of Adobe Reader on Solaris 10 only shipped acroread in
/usr/sfw/bin which do not support the “-version” option, so for such
instances, the following command can be used instead:
$ cat `pkgchk -l -P AcroVersion SUNWacroread | awk ‘/Pathname/ { print $2 }
‘`
5.0.10
3. Symptoms
There are no predictable symptoms that would indicate that these issues
have been exploited to execute arbitrary code.
4. Workaround
To avoid the described issues, do not load PDF files from untrusted
sources.
5. Resolution
These issues are addressed in the following releases:
SPARC Platform
* Solaris 10 with patch 121104-10 or later
For more information on Security Sun Alerts, see Technical Instruction
ID 213557.
This Sun Alert notification is being provided to you on an “AS IS”
basis. This Sun Alert notification may contain information provided by
third parties. The issues described in this Sun Alert notification may
or may not impact your system(s). Sun makes no representations,
warranties, or guarantees as to the information contained herein. ANY
AND ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION
WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR
NON-INFRINGEMENT, ARE HEREBY DISCLAIMED. BY ACCESSING THIS DOCUMENT YOU
ACKNOWLEDGE THAT SUN SHALL IN NO EVENT BE LIABLE FOR ANY DIRECT,
INDIRECT, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES THAT ARISE OUT
OF YOUR USE OR FAILURE TO USE THE INFORMATION CONTAINED HEREIN. This
Sun Alert notification contains Sun proprietary and confidential
information. It is being provided to you pursuant to the provisions of
your agreement to purchase services from Sun, or, if you do not have
such an agreement, the Sun.com Terms of Use. This Sun Alert
notification may only be used for the purposes contemplated by these
agreements.
Copyright 2000-2009 Sun Microsystems, Inc., 4150 Network Circle, Santa
Clara, CA 95054 U.S.A. All rights reserved.
Modification History
01-Sep-2009: Updated Contributing Factors and Resolution sections. Resolved.
Attachments
This solution has no attachment
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1.4.2 (GNU/Linux)
iD8DBQFKp6Jak0kIxZMiiQ8RAkbCAJsGpIjmpHhBNoZDu2f3Ch5M5reh/wCgsezp
c2ZY0OHQDktMwcWKPfpAYzY=
=SbEz
—–END PGP SIGNATURE—–