CVE-2008-4815
published 2008-11-05CVE-2008-4815: Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.2 and earlier on Unix and Linux allows attackers to gain privileges via a Trojan Horse…
PriorityP339high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
7.82%
94.0th percentile
Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.2 and earlier on Unix and Linux allows attackers to gain privileges via a Trojan Horse program in an unspecified directory that is associated with an insecure RPATH.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | <= 8.1.2 | — |
| adobe | acrobat | — | — |
| adobe | acrobat_reader | <= 8.0 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Reader: insecure RPATH flaw
vendor_redhat·2008-11-04·CVSS 7.5
CVE-2008-4815 [HIGH] Reader: insecure RPATH flaw
Reader: insecure RPATH flaw
Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.2 and earlier on Unix and Linux allows attackers to gain privileges via a Trojan Horse program in an unspecified directory that is associated with an insecure RPATH.
GHSA
GHSA-qxh6-vf7m-96cv: Untrusted search path vulnerability in Adobe Reader and Acrobat 8
ghsa_unreviewed·2022-05-14
CVE-2008-4815 [HIGH] GHSA-qxh6-vf7m-96cv: Untrusted search path vulnerability in Adobe Reader and Acrobat 8
Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.2 and earlier on Unix and Linux allows attackers to gain privileges via a Trojan Horse program in an unspecified directory that is associated with an insecure RPATH.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-4815 Adobe Reader: insecure RPATH flaw
bugzilla·2008-11-04·CVSS 7.5
CVE-2008-4815 [HIGH] CVE-2008-4815 Adobe Reader: insecure RPATH flaw
CVE-2008-4815 Adobe Reader: insecure RPATH flaw
Adobe Reader was built to use insecure RPATH in the binary.
This issue could possibly be exploited by a local attacker to run arbitrary
code as some other user if victim user can be convinced to run Adobe Reader
in an attacker controlled directory with specially crafted content.
Discussion:
Public now via upstream security bulletin:
http://www.adobe.com/support/security/bulletins/apsb08-19.html
---
This issue was addressed in:
Red Hat Enterprise Linux Extras:
http://rhn.redhat.com/errata/RHSA-2008-0974.html
arXiv
Integrating Network and Attack Graphs for Service-Centric Impact Analysis
arxiv_fulltext·2026-02-11
Integrating Network and Attack Graphs for Service-Centric Impact Analysis
Integrating Network and Attack Graphs for Service-Centric Impact Analysis
Joni Herttuainene1
Vesa Kuikka
Kimmo K. Kaski
e1e-mail: [email protected]
Department of Computer Science, Aalto University School of Science,
P.O. Box 11000, 00076 Aalto, Finland
Received: date / Accepted: date
## Abstract
We present a novel methodology for modelling, visualising, and analysing cyber threats, attack paths, as well as their impact on user services in enterprise or infrastructure networks of digital devices and services they provide. Using probabilistic methods to track the propagation of an attack through attack graphs, via the service or application layers, and on physical communication networks, our model enables us to analyse cyber attacks at different levels of detail. Understanding
http://download.oracle.com/sunalerts/1019937.1.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlhttp://secunia.com/advisories/32700http://secunia.com/advisories/32872http://www.adobe.com/support/security/bulletins/apsb08-19.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0974.htmlhttp://www.securityfocus.com/bid/32100http://www.securitytracker.com/id?1021140http://www.us-cert.gov/cas/techalerts/TA08-309A.htmlhttp://www.vupen.com/english/advisories/2008/3001http://www.vupen.com/english/advisories/2009/0098https://bugzilla.redhat.com/show_bug.cgi?id=469882https://exchange.xforce.ibmcloud.com/vulnerabilities/46335http://download.oracle.com/sunalerts/1019937.1.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.htmlhttp://secunia.com/advisories/32700http://secunia.com/advisories/32872http://www.adobe.com/support/security/bulletins/apsb08-19.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0974.htmlhttp://www.securityfocus.com/bid/32100http://www.securitytracker.com/id?1021140http://www.us-cert.gov/cas/techalerts/TA08-309A.htmlhttp://www.vupen.com/english/advisories/2008/3001http://www.vupen.com/english/advisories/2009/0098https://bugzilla.redhat.com/show_bug.cgi?id=469882https://exchange.xforce.ibmcloud.com/vulnerabilities/46335
2008-11-05
Published