CVE-2008-0883Link Following in Adobe Acrobat Reader

CWE-59Link Following4 documents4 sources
Severity
3.7LOWNVD
EPSS
0.1%
top 74.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 6
Latest updateMay 1

Description

acroread in Adobe Acrobat Reader 8.1.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files related to SSL certificate handling.

CVSS vector

AV:L/AC:H/C:P/I:P/A:PExploitability: 1.9 | Impact: 6.4

Affected Packages1 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-whm3-pjww-fw7w: acroread in Adobe Acrobat Reader 82022-05-01

📋Vendor Advisories

1
Red Hat
acroread: insecure handling of temporary files2008-02-21

💬Community

1
Bugzilla
CVE-2008-0883 acroread: insecure handling of temporary files2008-03-06
CVE-2008-0883 — Link Following in Adobe Acrobat Reader | cvebase