FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

acroread -- insecure temporary file creation

Affected packages
0 <= acroread4
0 <= acroread5
acroread < 7.0.0
5.*,1 < acroread < 7.0.0,1

Details

VuXML ID 107692a1-ee6c-11d9-8310-0001020eed82
Discovery 2005-06-29
Entry 2005-07-06

Secunia Research reports:

Secunia has discovered a security issue in Adobe Reader for Linux, which can be exploited by malicious, local users to gain knowledge of sensitive information.

The problem is caused due to temporary files being created with permissions based on a user's umask in the "/tmp" folder under certain circumstances when documents are opened.

Successful exploitation allows an unprivileged user to read arbitrary users' documents.

References

CVE Name CVE-2005-1912
URL http://secunia.com/secunia_research/2005-6/advisory/