Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. It includes two new package versions. It includes two new package versions.. SUSE Security Update: Security update for Acrobat Reader ______________________________________________________________________________ Announcement ID: SUSE-SU-2012:0086-1 Rating: important References: #735275 Cross-References: CVE-2011-2462 CVE-2011-4369 Affected Products: SUSE Linux Enterprise Desktop 11 SP1 SUSE Linux Enterprise Desktop 10 SP4 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. It includes two new package versions. Description: Acrobat Reader was updated to version 9.4.7 to fix two security issues (CVE-2011-2462, CVE-2011-4369) Security Issue references: * CVE-2011-4369 * CVE-2011-2462 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Desktop 11 SP1: zypper in -t patch sledsp1-acroread-5649 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Desktop 11 SP1 (noarch) [New Version: 9.4.6]: acroread-cmaps-9.4.6-0.4.2.2 acroread-fonts-ja-9.4.6-0.4.2.2 acroread-fonts-ko-9.4.6-0.4.2.2 acroread-fonts-zh_CN-9.4.6-0.4.2.2 acroread-fonts-zh_TW-9.4.6-0.4.2.2 - SUSE Linux Enterprise Desktop 11 SP1 (i586) [New Version: 9.4.7]: acroread-9.4.7-0.2.2.1 - SUSE Linux Enterprise Desktop 10 SP4 (noarch) [New Version: 9.4.6]: acroread-cmaps-9.4.6-0.5.9 acroread-fonts-ja-9.4.6-0.5.9 acroread-fonts-ko-9.4.6-0.5.9 acroread-fonts-zh_CN-9.4.6-0.5.9 acroread-fonts-zh_TW-9.4.6-0.5.9 - SUSE Linux Enterprise Desktop10 SP4 (i586) [New Version: 9.4.7]: acroread-9.4.7-0.5.1 References: https://www.suse.com/security/cve/CVE-2011-2462.html https://www.suse.com/security/cve/CVE-2011-4369.html . Important SUSE patch for Adobe Reader resolves multiple vulnerabilities and offers installation guidance.. SUSE Update, Acrobat Reader Security, Linux Update. . Severity: Important. LinuxSecurity.com Team
acrobat reader was updated to version 9.4.6 to fix several security issues that acrobat reader was updated to version 9.4.6 to fix several security issues that could allow attackers to execute arbitrary code or to cause a denial of service could allow attackers to execute arbitrary code or to cause a denial of service via specially crafted PDF documents. 2) Solution or Work-Around. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________ SUSE Security Announcement Package: acroread Announcement ID: SUSE-SA:2011:044 Date: Wed, 16 Nov 2011 09:00:00 +0000 Affected Products: openSUSE 11.3 openSUSE 11.4 SUSE Linux Enterprise Desktop 11 SP1 SUSE Linux Enterprise Desktop 10 SP4 Vulnerability Type: remote code execution CVSS v2 Base Score: 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P) SUSE Default Package: no Cross-References: CVE-2011-1353, CVE-2011-2431, CVE-2011-2432, CVE-2011-2433, CVE-2011-2434, CVE-2011-2435, CVE-2011-2436, CVE-2011-2437, CVE-2011-2438, CVE-2011-2439, CVE-2011-2440, CVE-2011-2441, CVE-2011-2442 Content of This Advisory: 1) Security Vulnerability Resolved: acrobat reader updates fix potential code execution Problem Description 2) Solution or Work-Around 3) Special Instructions and Notes 4) Package Location and Checksums 5) Pending Vulnerabilities, Solutions, and Work-Arounds: none 6) Authenticity Verification and Additional Information ______________________________________________________________________________ 1) Problem Description and Brief Discussion acrobat reader was updated to version 9.4.6 to fixseveral security issues that could allow attackers to execute arbitrary code or to cause a denial of service via specially crafted PDF documents. 2) Solution or Work-Around There is no known workaround, please install the update packages. 3) Special Instructions and Notes Please update. 4) Package Location and Checksums The preferred method for installing security updates is to use the YaST "Online Update" module or the "zypper" commandline tool. The package and patch management stack will detect which updates are required and automatically perform the necessary steps to verify and install them. Alternatively, download the update packages for your distribution manually and verify their integrity by the methods listed in Section 6 of this announcement. Then install the packages using the command rpm -Fhv to apply the update, replacing with the filename of the downloaded RPM package. x86 Platform: openSUSE 11.4: http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.4/rpm/i586/acroread-9.4.6-0.5.1.i586.rpm openSUSE 11.3: http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.3/rpm/i586/acroread-9.4.6-0.2.1.i586.rpm Sources: openSUSE 11.4: openSUSE 11.3: Our maintenance customers are notified individually. The packages are offered for installation from the maintenance web: SUSE Linux Enterprise Desktop 10 SP4 SUSE Linux Enterprise Desktop 11 SP1 ______________________________________________________________________________ 5) Pending Vulnerabilities, Solutions, and Work-Arounds: none ______________________________________________________________________________ 6) Authenticity Verification and Additional Information - Announcement authenticity verification: SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in eachannouncement. All SUSE security announcements are published with a valid signature. To verify the signature of the announcement, save it as text into a file and run the command gpg --verify replacing with the name of the file where you saved the announcement. The output for a valid signature looks like: gpg: Signature made using RSA key ID 3D25D3D9 gpg: Good signature from "SuSE Security Team " where is replaced by the date the document was signed. If the security team's key is not contained in your key ring, you can import it from the first installation CD. To import the key, use the command gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc - Package authenticity verification: SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and the integrity of a package needs to be verified to ensure that it has not been tampered with. The internal rpm package signatures provide an easy way to verify the authenticity of an RPM package. Use the command rpm -v --checksig to verify the signature of the package, replacing with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from
An update that fixes 13 vulnerabilities is now available. An update that fixes 13 vulnerabilities is now available. An update that fixes 13 vulnerabilities is now available. It includes one version update. It includes one version update.. openSUSE Security Update: acroread ______________________________________________________________________________ Announcement ID: openSUSE-SU-2011:1238-1 Rating: critical References: #717724 Cross-References: CVE-2011-1353 CVE-2011-2431 CVE-2011-2432 CVE-2011-2433 CVE-2011-2434 CVE-2011-2435 CVE-2011-2436 CVE-2011-2437 CVE-2011-2438 CVE-2011-2439 CVE-2011-2440 CVE-2011-2441 CVE-2011-2442 Affected Products: openSUSE 11.4 openSUSE 11.3 ______________________________________________________________________________ An update that fixes 13 vulnerabilities is now available. It includes one version update. Description: acrobat reader was updated to version 9.4.6 to fix several security issues (CVE-2011-1353, CVE-2011-2431, CVE-2011-2432, CVE-2011-2433, CVE-2011-2434, CVE-2011-2435, CVE-2011-2436, CVE-2011-2437, CVE-2011-2438, CVE-2011-2439, CVE-2011-2440, CVE-2011-2441, CVE-2011-2442) Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 11.4: zypper in -t patch acroread-5411 - openSUSE 11.3: zypper in -t patch acroread-5411 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 11.4 (i586) [New Version: 9.4.6]: acroread-9.4.6-0.5.1 - openSUSE 11.3 (i586) [New Version: 9.4.6]: acroread-9.4.6-0.2.1 References: https://www.suse.com/security/cve/CVE-2011-1353.html https://www.suse.com/security/cve/CVE-2011-2431.html https://www.suse.com/security/cve/CVE-2011-2432.html https://www.suse.com/security/cve/CVE-2011-2433.html https://www.suse.com/security/cve/CVE-2011-2434.html https://www.suse.com/security/cve/CVE-2011-2435.html https://www.suse.com/security/cve/CVE-2011-2436.html https://www.suse.com/security/cve/CVE-2011-2437.html https://www.suse.com/security/cve/CVE-2011-2438.html https://www.suse.com/security/cve/CVE-2011-2439.html https://www.suse.com/security/cve/CVE-2011-2440.html https://www.suse.com/security/cve/CVE-2011-2441.html https://www.suse.com/security/cve/CVE-2011-2442.html . Important patch for Adobe Acrobat Reader on openSUSE tackling various security flaws to enhance system protection.. acrobat Reader update, openSUSE security, software patching, critical vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Specially crafted PDF documents could crash acroread or lead to Specially crafted PDF documents could crash acroread or lead to execution of arbitrary code (CVE-2010-1240, CVE-2010-2862). execution of arbitrary code (CVE-2010-1240, CVE-2010-2862). This update also incorporate the Adobe Flash Player update APSB10-16 for the bundled flash player parts (CVE-2010-0209, CVE-2010-2188, CVE-2010-2213, [More...]. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________ SUSE Security Announcement Package: acroread Announcement ID: SUSE-SA:2010:037 Date: Wed, 01 Sep 2010 11:00:00 +0000 Affected Products: openSUSE 11.1 openSUSE 11.2 openSUSE 11.3 SUSE Linux Enterprise Desktop 10 SP3 SUSE Linux Enterprise Desktop 11 SUSE Linux Enterprise Desktop 11 SP1 Vulnerability Type: remote code execution CVSS v2 Base Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C) SUSE Default Package: no Cross-References: CVE-2010-0209, CVE-2010-1240, CVE-2010-2188 CVE-2010-2213, CVE-2010-2214, CVE-2010-2215 CVE-2010-2216, CVE-2010-2862 Content of This Advisory: 1) Security Vulnerability Resolved: Acrobat Reader security update Problem Description 2) Solution or Work-Around 3) Special Instructions and Notes 4) Package Location and Checksums 5) Pending Vulnerabilities, Solutions, and Work-Arounds: - See SUSE Security Summary Report 6) Authenticity Verification and Additional Information ______________________________________________________________________________ 1) Problem Description and Brief Discussion Specially craftedPDF documents could crash acroread or lead to execution of arbitrary code (CVE-2010-1240, CVE-2010-2862). This update also incorporate the Adobe Flash Player update APSB10-16 for the bundled flash player parts (CVE-2010-0209, CVE-2010-2188, CVE-2010-2213, CVE-2010-2214, CVE-2010-2215, CVE-2010-2216). Please see Adobe's site for more information: 2) Solution or Work-Around There is no known workaround, please install the update packages. 3) Special Instructions and Notes Please close and restart all running instances of acroread after the update. 4) Package Location and Checksums The preferred method for installing security updates is to use the YaST Online Update (YOU) tool. YOU detects which updates are required and automatically performs the necessary steps to verify and install them. Alternatively, download the update packages for your distribution manually and verify their integrity by the methods listed in Section 6 of this announcement. Then install the packages using the command rpm -Fhv to apply the update, replacing with the filename of the downloaded RPM package. x86 Platform: openSUSE 11.3: http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.3/rpm/i586/acroread-9.3.4-0.2.1.i586.rpm openSUSE 11.2: http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.2/rpm/i586/acroread-9.3.4-0.3.1.i586.rpm openSUSE 11.1: http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/i586/acroread-9.3.4-0.3.1.i586.rpm Platform Independent: openSUSE 11.2: http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.2/rpm/noarch/acroread-cmaps-9.3.4-0.3.1.noarch.rpm http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.2/rpm/noarch/acroread-fonts-ja-9.3.4-0.3.1.noarch.rpm http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.2/rpm/noarch/acroread-fonts-ko-9.3.4-0.3.1.noarch.rpm http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.2/rpm/noarch/acroread-fonts-zh_CN-9.3.4-0.3.1.noarch.rpm http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.2/rpm/noarch/acroread-fonts-zh_TW-9.3.4-0.3.1.noarch.rpm openSUSE 11.1: http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/noarch/acroread-cmaps-9.3.4-0.3.1.noarch.rpm http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/noarch/acroread-fonts-ja-9.3.4-0.3.1.noarch.rpm http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/noarch/acroread-fonts-ko-9.3.4-0.3.1.noarch.rpm http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/noarch/acroread-fonts-zh_CN-9.3.4-0.3.1.noarch.rpm http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/noarch/acroread-fonts-zh_TW-9.3.4-0.3.1.noarch.rpm Sources: openSUSE 11.3: openSUSE 11.2: openSUSE 11.1: Our maintenance customers are notified individually. The packages are offered for installation from the maintenance web: SUSE Linux Enterprise Desktop 10 SP3 SUSE Linux Enterprise Desktop 11 SP1 SUSE Linux Enterprise Desktop 11 ______________________________________________________________________________ 5) Pending Vulnerabilities, Solutions, and Work-Arounds: - See SUSE Security Summary Report ______________________________________________________________________________ 6) Authenticity Verification and Additional Information - Announcement authenticity verification: SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature. To verify the signature of the announcement, save it as text into a file and run the command gpg --verify replacing with the name of the file where yousaved the announcement. The output for a valid signature looks like: gpg: Signature made using RSA key ID 3D25D3D9 gpg: Good signature from "SuSE Security Team " where is replaced by the date the document was signed. If the security team's key is not contained in your key ring, you can import it from the first installation CD. To import the key, use the command gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc - Package authenticity verification: SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and the integrity of a package needs to be verified to ensure that it has not been tampered with. The internal rpm package signatures provide an easy way to verify the authenticity of an RPM package. Use the command rpm -v --checksig to verify the signature of the package, replacing with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from
The Adobe Acrobat Reader "acroread" received fixes for two The Adobe Acrobat Reader "acroread" received fixes for two vulnerabilities in the JavaScript API that allowed attackers vulnerabilities in the JavaScript API that allowed attackers to execute arbitrary code with a malformed PDF file. (CVE-2009-1492,CVE-2009-1493) 2) Solution or Work-Around. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________ SUSE Security Announcement Package: acroread Announcement ID: SUSE-SA:2009:027 Date: Wed, 20 May 2009 17:00:00 +0000 Affected Products: openSUSE 10.3 openSUSE 11.0 openSUSE 11.1 SUSE Linux Enterprise Desktop 10 SP2 SLES 11 DEBUGINFO SLED 11 Vulnerability Type: remote code execution Severity (1-10): 8 SUSE Default Package: yes Cross-References: CVE-2009-1492, CVE-2009-1493 Content of This Advisory: 1) Security Vulnerability Resolved: acroread remote code execution Problem Description 2) Solution or Work-Around 3) Special Instructions and Notes 4) Package Location and Checksums 5) Pending Vulnerabilities, Solutions, and Work-Arounds: See SUSE Security Summary Report. 6) Authenticity Verification and Additional Information ______________________________________________________________________________ 1) Problem Description and Brief Discussion The Adobe Acrobat Reader "acroread" received fixes for two vulnerabilities in the JavaScript API that allowed attackers to execute arbitrary code with a malformed PDF file. (CVE-2009-1492,CVE-2009-1493) 2) Solution or Work-Around There is no known workaround, please install the updatepackages. 3) Special Instructions and Notes Please close and restart all running instances of acroread after the update. 4) Package Location and Checksums The preferred method for installing security updates is to use the YaST Online Update (YOU) tool. YOU detects which updates are required and automatically performs the necessary steps to verify and install them. Alternatively, download the update packages for your distribution manually and verify their integrity by the methods listed in Section 6 of this announcement. Then install the packages using the command rpm -Fhv to apply the update, replacing with the filename of the downloaded RPM package. x86 Platform: openSUSE 11.1: http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.1/rpm/i586/acroread-8.1.5-0.1.1.i586.rpm openSUSE 11.0: http://ftp5.gwdg.de/pub/opensuse/discontinued/update/11.0/rpm/i586/acroread-8.1.5-0.1.i586.rpm openSUSE 10.3: http://ftp5.gwdg.de/pub/opensuse/discontinued/update/10.3/rpm/i586/acroread-8.1.5-0.1.i586.rpm Sources: openSUSE 11.1: openSUSE 11.0: openSUSE 10.3: Our maintenance customers are notified individually. The packages are offered for installation from the maintenance web: SUSE Linux Enterprise Desktop 10 SP2 SLED 11 ______________________________________________________________________________ 5) Pending Vulnerabilities, Solutions, and Work-Arounds: See SUSE Security Summary Report. ______________________________________________________________________________ 6) Authenticity Verification and Additional Information - Announcement authenticity verification: SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature. To verify the signature of the announcement,save it as text into a file and run the command gpg --verify replacing with the name of the file where you saved the announcement. The output for a valid signature looks like: gpg: Signature made using RSA key ID 3D25D3D9 gpg: Good signature from "SuSE Security Team " where is replaced by the date the document was signed. If the security team's key is not contained in your key ring, you can import it from the first installation CD. To import the key, use the command gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc - Package authenticity verification: SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and the integrity of a package needs to be verified to ensure that it has not been tampered with. The internal rpm package signatures provide an easy way to verify the authenticity of an RPM package. Use the command rpm -v --checksig to verify the signature of the package, replacing with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from
Various unspecified security problems have been fixed in Acrobat Various unspecified security problems have been fixed in Acrobat Reader version 7.0.8. Reader version 7.0.8. Adobe does not provide detailed information about the nature of the security problems. Therefore, it is necessary to assume that remote code execution is possible.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________ SUSE Security Announcement Package: acroread Announcement ID: SUSE-SA:2006:041 Date: Tue, 04 Jul 2006 14:00:00 +0000 Affected Products: SUSE LINUX 10.1 SUSE LINUX 10.0 SUSE LINUX 9.3 SUSE LINUX 9.2 SUSE SLES 9 Vulnerability Type: unknown Severity (1-10): 8 SUSE Default Package: yes Cross-References: CVE-2006-3093 Content of This Advisory: 1) Security Vulnerability Resolved: Acroread security upgrade to 7.0.8 Problem Description 2) Solution or Work-Around 3) Special Instructions and Notes 4) Package Location and Checksums 5) Pending Vulnerabilities, Solutions, and Work-Arounds: See SUSE Security Summary Report. 6) Authenticity Verification and Additional Information ______________________________________________________________________________ 1) Problem Description and Brief Discussion Various unspecified security problems have been fixed in Acrobat Reader version 7.0.8. Adobe does not provide detailed information about the nature of the security problems. Therefore, it is necessary to assume that remote code execution is possible. Adobe does not provide update packages for Acroread that are compatible with some of our releases from the past. Therefore, updatesare missing (and might not be provided) for the products listed as follows. As a solution to Adobe acroread security problems on older products we suggest removal of the package from exposed systems and to use the longer maintained open source PDF viewers. - SUSE Linux Enterprise Server 9, Open Enterprise Server, Novell Linux POS 9 Acrobat Reader 7.0.8 has a new requirement on GTK+ 2.4 libraries (previously GTK+ 2.2). Since the above products contain only GTK+ 2.2, the Acrobat Reader 7.0.8 provided by Adobe is currently not functional. We have postponed the updates and wait for Adobe to clarify this problem. - SUSE Linux Enterprise Server 8, SUSE Linux Enterprise Desktop 1 These versions only support Acrobat Reader 5 and could not be upgraded for Acrobat Reader 7 due to glibc and GTK+ requirements. We discontinued security support for Acrobat Reader on those products some time ago already. This issue is tracked by the Mitre CVE ID CVE-2006-3093. 2) Solution or Work-Around Please install the update packages. You can also use the open source PDF viewer replacements, as for instance xpdf, kpdf, evince, gpdf or similar programs. 3) Special Instructions and Notes Please close and restart all running instances of acroread after the update. 4) Package Location and Checksums The preferred method for installing security updates is to use the YaST Online Update (YOU) tool. YOU detects which updates are required and automatically performs the necessary steps to verify and install them. Alternatively, download the update packages for your distribution manually and verify their integrity by the methods listed in Section 6 of this announcement. Then install the packages using the command rpm -Fhv to apply the update, replacing with the filename of the downloaded RPM package. x86 Platform: SUSE LINUX 10.1: 0a439b3541fec2329b55f3b9b3bc4858 SUSE LINUX 10.0: 76d13f4fd89e25549a363ae443cbab04 SUSE LINUX 9.3: 953a36fb273d1245a122ea9a0774fcc2 SUSE LINUX 9.2: 4691f003b517f23bad4b923f24f45133 Sources: SUSE LINUX 10.1: cdf32850c4a770fe4458df7e78fd0dbe SUSE LINUX 10.0: 76eb5e155e370109b0d55226e8b94895 SUSE LINUX 9.3: e55b674570116b348ba7091f2b8b906e SUSE LINUX 9.2: 97fdaba08621d339fdfde9b94db62a70 Our maintenance customers are notified individually. The packages are offered for installation from the maintenance web: SUSE SLES 9 ______________________________________________________________________________ 5) Pending Vulnerabilities, Solutions, and Work-Arounds: See SUSE Security Summary Report. ______________________________________________________________________________ 6) Authenticity Verification and Additional Information - Announcement authenticity verification: SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature. To verify the signature of the announcement, save it as text into a file and run the command gpg --verify replacing with the name of the file where you saved the announcement. The output for a valid signature looks like: gpg: Signature made using RSA key ID 3D25D3D9 gpg: Good signature from "SuSE Security Team " where is replaced by the date the document was signed. If the security team's key is not contained in your key ring, you can import it from the first installation CD. To import the key, use the command gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc - Package authenticity verification: SUSE update packages are available on many mirror FTP servers all over the world. While this service is consideredvaluable and important to the free and open source software community, the authenticity and the integrity of a package needs to be verified to ensure that it has not been tampered with. There are two verification methods that can be used independently from each other to prove the authenticity of a downloaded file or RPM package: 1) Using the internal gpg signatures of the rpm package 2) MD5 checksums as provided in this announcement 1) The internal rpm package signatures provide an easy way to verify the authenticity of an RPM package. Use the command rpm -v --checksig to verify the signature of the package, replacing with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from
This update fixes a buffer overflow in Acrobat Reader versions 5, This update fixes a buffer overflow in Acrobat Reader versions 5, where an attacker could execute code by providing a handcrafted PDF where an attacker could execute code by providing a handcrafted PDF to the viewer. The Acrobat Reader 5 versions of SUSE Linux 9.0 up to 9.2, SUSE Linux Enterprise Server 9 and Novell Linux Desktop 9 [More...]. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________ SUSE Security Announcement Package: acroread 5 Announcement ID: SUSE-SA:2005:042 Date: Thu, 14 Jul 2005 15:00:00 +0000 Affected Products: 9.0, 9.1, 9.2 SUSE Linux Desktop 1 SUSE Linux Enterprise Server 8, 9 Novell Linux Desktop 9 Open Enterprise Server 9 Vulnerability Type: remote code execution Severity (1-10): 8 SUSE Default Package: yes Cross-References: CAN-2005-1625 Content of This Advisory: 1) Security Vulnerability Resolved: Buffer overflow in Acrobat Reader 5 Problem Description 2) Solution or Work-Around 3) Special Instructions and Notes 4) Package Location and Checksums 5) Pending Vulnerabilities, Solutions, and Work-Arounds: See SUSE Security Summary Report. 6) Authenticity Verification and Additional Information ______________________________________________________________________________ 1) Problem Description and Brief Discussion This update fixes a buffer overflow in Acrobat Reader versions 5, where an attacker could execute code by providing a handcrafted PDF to the viewer. The Acrobat Reader 5 versions of SUSE Linux 9.0 up to 9.2, SUSE Linux Enterprise Server 9 and Novell LinuxDesktop 9 were upgraded to Acrobat Reader 7. Unfortunately this version upgrade introduces new dependencies. Please use the YaST module "Install or Remove Software" to check if there are new dependencies and install the required packages. Since Adobe does no longer provide updated packages that work on SUSE Linux Enterprise Server 8, United Linux 1, and SUSE Linux Desktop 1 we are unable to provide fixed packages for these products. The SUSE Security Team strongly advises to deinstall the acroread package on these platforms and use alternate PDF viewers like xpdf, kpdf, gpdf or gv. Since this attack could be done via E-Mail messages or web pages, this should be considered to be remote exploitable. This issue is tracked by the Mitre CVE ID CAN-2005-1625. 2) Solution or Work-Around Install the upgraded packages. 3) Special Instructions and Notes On SUSE Linux Enterprise Server 8 and SUSE Linux Desktop 1, deinstall the acroread package using: rpm -e acroread On all other platforms, start the YaST "Install and Remove Software" dialog and solve potential conflicts that are the results of this version upgrade. 4) Package Location and Checksums The preferred method for installing security updates is to use the YaST Online Update (YOU) tool. YOU detects which updates are required and automatically performs the necessary steps to verify and install them. Alternatively, download the update packages for your distribution manually and verify their integrity by the methods listed in Section 6 of this announcement. Then install the packages using the command rpm -Fhv to apply the update, replacing with the filename of the downloaded RPM package. Our maintenance customers are notified individually. The packages are offered for installation from the maintenance web. x86 Platform: SUSE Linux 9.3: 1adefcf655eda81fd6df960e19957935 SUSE Linux 9.2: d8acc30fd018f79add163efca641ed56 9f29b592c1ff6b30f31fd1e1d99e4a6c 98535e2474fb009c2de160b22ec269b7 SUSE Linux 9.1: 499c9ec2b868240e0642164ff449a67c source rpm(s): ec0733e544a324ca37f5a7a92ed75e14 SUSE Linux 9.0: 0ac3ed2c776fbe02b26315078c80bb6e source rpm(s): 2a2c275b272ee60c9e8b08e072f9cb36 ______________________________________________________________________________ 5) Pending Vulnerabilities, Solutions, and Work-Arounds: See SUSE Security Summary Report. ______________________________________________________________________________ 6) Authenticity Verification and Additional Information - Announcement authenticity verification: SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature. To verify the signature of the announcement, save it as text into a file and run the command gpg --verify replacing with the name of the file where you saved the announcement. The output for a valid signature looks like: gpg: Signature made using RSA key ID 3D25D3D9 gpg: Good signature from "SuSE Security Team " where is replaced by the date the document was signed. If the security team's key is not contained in your key ring, you can import it from the first installation CD. To import the key, use the command gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc - Package authenticity verification: SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and the integrity of a package needs to be verified to ensure that it has not been tampered with. There are two verification methods that can beused independently from each other to prove the authenticity of a downloaded file or RPM package: 1) Using the internal gpg signatures of the rpm package 2) MD5 checksums as provided in this announcement 1) The internal rpm package signatures provide an easy way to verify the authenticity of an RPM package. Use the command rpm -v --checksig to verify the signature of the package, replacing with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from
Get the latest Linux and open source security news straight to your inbox.