SUSE update for acroread
Secunia Advisory: SA23882
Release Date: 2007-01-23
Popularity: 7,274 views

Critical:
Highly critical
Impact: Hijacking
Cross Site Scripting
DoS
System access
Where: From remote
Solution Status: Vendor Patch

OS:SUSE Linux 10
SUSE Linux 10.1
SUSE Linux 9.3
SUSE Linux Enterprise Server 10

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2006-5857
CVE-2007-0044
CVE-2007-0045
CVE-2007-0046
CVE-2007-0047
CVE-2007-0048


Description:
SUSE has issued an update for acroread. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks, as a vector for conducting cross-site request forgery attacks, or to potentially compromise a user's system.

For more information:
SA23483
SA23666

Solution:
Apply updated packages.

x86 Platform:

openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/acroread-7.0.9-2.1.i586.rpm
c37b991bf98afafafe7cef049b19c432

SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/acroread-7.0.9-1.2.i586.rpm
1c2d6f4028f856b208c7a63a1a085ae2

SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/upda.../rpm/i586/acroread-7.0.9-2.1.i586.rpm
065c5b67a4194558d70f23671f0800db

SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/acroread-7.0.9-2.1.i586.rpm
da0c72bc6379fa546f581d5b73eab620

Sources:

openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/src/acroread-7.0.9-2.1.nosrc.rpm
c29bf975f673b532189ced3754693ed0

SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.1/rpm/src/acroread-7.0.9-1.2.nosrc.rpm
6cbe0b868a4bfffa536311e933f402a2

SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/upda.../rpm/src/acroread-7.0.9-2.1.nosrc.rpm
668ca101366dc4e66cb4670de282b6be

SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/src/acroread-7.0.9-2.1.src.rpm
3e8a7e56bad5c5cba050f7c69c40d5fa

Our maintenance customers are notified individually. The packages are
offered for installation from the maintenance web:

Novell Linux Desktop 9:
http://support.novell.com/techcenter/psdb/e4aa9329743e7c8bb35f09a113da0938.html

SUSE SLED 10:
http://support.novell.com/techcenter/psdb/af82ce465dd28a7a87602e1069a0e963.html

Original Advisory:
http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html

Other References:
SA23483:
http://secunia.com/advisories/23483/

SA23666:
http://secunia.com/advisories/23666/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Subdreamer Light Global Variables SQL Injection Vulnerability // 74 views
2. Adobe Flash Player Multiple Vulnerabilities // 39 views
3. Microsoft Office Two Code Execution Vulnerabilities // 20 views
4. Microsoft Word Malformed Object Pointer Vulnerability // 19 views
5. Sun Java System Web Proxy Server SOCKS Module Buffer Overflows // 18 views
6. Sun Java JDK / JRE Multiple Vulnerabilities // 17 views
7. VLC Media Player Multiple Vulnerabilities // 17 views
8. phpBB "cur_password" Cross-Site Scripting Vulnerability // 16 views
9. Opera Multiple Vulnerabilities // 15 views
10. phpBB "gen_rand_string()" Predictable RNG Weakness // 12 views