Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2007-0046
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-0046

Description:
Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute arbitrary code by causing an error via a javascript: URI call to document.write in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/31272

SUSE
  http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html

SUNALERT
  http://sunsolve.sun.com/search/document.do?assetkey=1-26-102847-1

ST
  1017469

SREASON
  http://securityreason.com/securityalert/2090

SAID
  Secunia Advisory: SA23691
  Secunia Advisory: SA23812
  Secunia Advisory: SA23877
  Secunia Advisory: SA23882
  Secunia Advisory: SA24533

REDHAT
  http://www.redhat.com/support/errata/RHSA-2007-0021.html

MISC
  http://www.wisec.it/vulns.php?page=9
  http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf

GENTOO
  http://security.gentoo.org/glsa/glsa-200701-16.xml

CONFIRM
  http://www.adobe.com/support/security/bulletins/apsb07-01.html

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/455801/100/0/threaded


Return to the previous page.