SuSE9 Security Update : Acrobat Reader (YOU Patch Number 10316)

medium Nessus Plugin ID 58225

Synopsis

The remote SuSE 9 host is missing a security-related patch.

Description

This update fixes a buffer overflow in Acrobat Reader versions 5 and 7, where an attacker could execute code by providing a handmade PDF to the viewer.

The Acrobat Reader 5 versions of 9.1 and 9.2 were upgraded to Acrobat Reader 7. This version upgrade can cause new dependencies to appear, please check with the YaST Software Package Installation frontend if there are new dependencies and install the required packages.

Since this attack could be done via E-Mail messages or webpages, this should be considered to be remote exploitable.

This issue is tracked by the Mitre CVE ID CVE-2005-1625.

Solution

Apply YOU patch number 10316.

See Also

https://www.suse.com/security/cve/CVE-2005-1625/

Plugin Details

Severity: Medium

ID: 58225

File Name: suse9_10316.nasl

Version: 1.6

Type: local

Agent: unix

Published: 4/23/2012

Updated: 1/14/2021

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.7

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: cpe:/o:suse:suse_linux

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Patch Publication Date: 7/19/2005

Reference Information

CVE: CVE-2005-1625