Skip to content

Security Advisory Critical: Adobe Acrobat Reader security update

アップデートID:

RHSA-2007:0017-2

タイプ:Security Advisory
重大性:Critical
発行日:2007年1月11日
最終更新日:2007年1月11日
影響のある製品: Red Hat Enterprise Linux Extras (v. 4)
OVAL: https://rhn.redhat.com/errata/RHSA-2007-0017.html
CVEs (cve.mitre.org): CVE-2006-5857
CVE-2007-0045
CVE-2007-0046

詳細

Updated acroread packages that fix several security issues are now
available for Red Hat Enterprise Linux 4.

This update has been rated as having critical security impact by the Red
Hat Security Response Team.

The Adobe Acrobat Reader allows users to view and print documents in
portable document format (PDF).

A cross site scripting flaw was found in the way the Adobe Reader Plugin
processes certain malformed URLs. A malicious web page could inject
arbitrary javascript into the browser session which could possibly lead to
a cross site scripting attack. (CVE-2007-0045)

Two arbitrary code execution flaws were found in the way Adobe Reader
processes malformed document files. It may be possible to execute arbitrary
code on a victim's machine if the victim opens a malicious PDF file.
(CVE-2006-5857, CVE-2007-0046)

All users of Acrobat Reader are advised to upgrade to these updated
packages, which contain Acrobat Reader version 7.0.9 and are not vulnerable
to these issues.


解決法


このアップデートを適用する前に、ご使用のシステムに関係するリリース済みのエラータ/Errataがすべて適用されていることを確認してください。

このアップデートは、Red Hat Networkを通じて入手できます。


アップデートパッケージ

Red Hat Enterprise Linux Extras (v. 4)

IA-32:
acroread-7.0.9-1.2.0.EL4.i386.rpm     73c315ade9b10b3a242775b392bfddc6
acroread-7.0.9-1.2.0.EL4.i386.rpm     73c315ade9b10b3a242775b392bfddc6
acroread-7.0.9-1.2.0.EL4.i386.rpm     73c315ade9b10b3a242775b392bfddc6
acroread-7.0.9-1.2.0.EL4.i386.rpm     73c315ade9b10b3a242775b392bfddc6
acroread-plugin-7.0.9-1.2.0.EL4.i386.rpm     d58a0ec78befce07f559e621087106bf
acroread-plugin-7.0.9-1.2.0.EL4.i386.rpm     d58a0ec78befce07f559e621087106bf
acroread-plugin-7.0.9-1.2.0.EL4.i386.rpm     d58a0ec78befce07f559e621087106bf
acroread-plugin-7.0.9-1.2.0.EL4.i386.rpm     d58a0ec78befce07f559e621087106bf
 
x86_64:
acroread-7.0.9-1.2.0.EL4.i386.rpm     73c315ade9b10b3a242775b392bfddc6
acroread-7.0.9-1.2.0.EL4.i386.rpm     73c315ade9b10b3a242775b392bfddc6
acroread-7.0.9-1.2.0.EL4.i386.rpm     73c315ade9b10b3a242775b392bfddc6
acroread-7.0.9-1.2.0.EL4.i386.rpm     73c315ade9b10b3a242775b392bfddc6
 
(The unlinked packages above are only available from the Red Hat Network)


バグフィックス (詳細は、bugzilla/バグジラ[英語]を御覧ください。)

221594 - CVE-2006-5857 Multiple Acrobat vulnerabilities (CVE-2007-0045 CVE-2007-0046)


参照





ここに在るパッケージはセキュリティの為、Red Hat, Inc. によって、GPG認証されています。
認証キー及び詳細は以下を御覧下さい。
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/