Adobe Acrobat / Adobe Reader Disclosure of Sensitive Information
- 0
- Add a Comment
“Critical: Moderately critical Impact: Exposure of sensitive information Where: From remote Solution Status: Unpatched
Software:Adobe Acrobat 6.x, Adobe Reader 6.x
Jelmer has discovered a vulnerability in Adobe Acrobat and Adobe Reader, which can be exploited by malicious people to disclose sensitive information.
The problem is that embedded Macromedia flash files are executed in a local context. This can be exploited to read local files by embedding a specially crafted flash file in a PDF file located on e.g. a malicious web site.
The vulnerability has been confirmed on Adobe Reader 6.01 and 6.02 for Windows.
Solution: Disable Javascript in Adobe Acrobat and Adobe Reader.” Or you can do what I do - use Acrobat Reader 5.1.
