Summary
This host is installed with Adobe Reader and is prone to multiple vulnerabilities.
Impact
Successful exploitation will allow attackers to cause memory corruption, execution of arbitrary code, execution of arbitrary script code in a user's browser session in context of an affected site and conduct cross site request forgery attacks.
Impact Level: System/Application
Solution
Upgrade to Adobe Reader version 7.0.9 or later. For updates refer to http://get.adobe.com/reader
Insight
Flaws exist due to,
- Input passed to a hosted PDF file is not properly sanitised by the browser plug-in before being returned to users.
- Input passed to a hosted PDF file is not properly handled by the browser plug-in.
Affected
Adobe Reader version 7.0.8 and prior on Mac OS X.
Detection
Get the installed version with the help of detect NVT and check the version is vulnerable or not.
References
Severity
Classification
-
CVE CVE-2006-5857, CVE-2007-0044, CVE-2007-0046, CVE-2007-0047 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities