This script is Copyright (C) 2009-2016 Tenable Network Security, Inc.
The remote SuSE 9 host is missing a security-related patch.
The Adobe Acrobat Reader has been updated to version 7.0.9.
For SUSE Linux Enterprise Server 9 this version now includes its own
GLIB2, ATK, PANGO and GTK2 libraries, since Acroread 7.0.x requires a
minimum level of GTK2 2.4.
This update also includes following security fixes :
- A memory corruption problem was fixed in Adobe Acrobat
Reader can potentially lead to code execution.
- Universal cross-site request forgery (CSRF) problems
were fixed in the Acrobat Reader plugin which could be
exploited by remote attackers to conduct CSRF attacks
using any site that is providing PDFs. (CVE-2007-0044)
- Cross-site scripting problems in the Acrobat Reader
plugin were fixed, which could be exploited by remote
attackers to conduct XSS attacks against any site that
is providing PDFs. (CVE-2007-0045)
- A double free problem in the Acrobat Reader plugin was
fixed which could be used by remote attackers to
potentially execute arbitrary code. Note that all
platforms using Adobe Reader currently have counter
measures against such attack where it will just cause a
controlled abort(). (CVE-2007-0046)
- CVE-2007-0047 and CVE-2007-0048 affect only Microsoft
Windows and Internet Explorer.
See also :
Apply YOU patch number 11433.
Risk factor :
High / CVSS Base Score : 9.3
Public Exploit Available : true