The uudecoding feature in Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arbitrary code via shell metacharacters ("`" or backtick) in the filename of the PDF file that is provided to the uudecode command.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:49
Type | Values Removed | Values Added |
---|---|---|
References | () http://security.gentoo.org/glsa/glsa-200408-14.xml - Vendor Advisory | |
References | () http://www.adobe.com/support/techdocs/322914.html - | |
References | () http://www.idefense.com/application/poi/display?id=124&type=vulnerabilities - | |
References | () http://www.redhat.com/support/errata/RHSA-2004-432.html - | |
References | () http://www.securityfocus.com/bid/10931 - Patch, Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/16973 - |
Information
Published : 2004-08-18 04:00
Updated : 2024-11-20 23:49
NVD link : CVE-2004-0630
Mitre link : CVE-2004-0630
CVE.ORG link : CVE-2004-0630
JSON object : View
Products Affected
adobe
- acrobat_reader
CWE