CVE-2012-0777
published 2012-04-10CVE-2012-0777: The JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 on Mac OS X and Linux allows attackers to execute arbitrary code or…
PriorityP337medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
7.15%
93.6th percentile
The JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 on Mac OS X and Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | >= 10.0 < 10.1.3 | 10.1.3 |
| adobe | acrobat | >= 9.0 < 9.5.1 | 9.5.1 |
| adobe | acrobat_reader | >= 10.0 < 10.1.3 | 10.1.3 |
| adobe | acrobat_reader | >= 9.0 < 9.5.1 | 9.5.1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jxrq-6cjh-p9vf: The JavaScript API in Adobe Reader and Acrobat 9
ghsa_unreviewed·2022-05-14
CVE-2012-0777 [HIGH] CWE-119 GHSA-jxrq-6cjh-p9vf: The JavaScript API in Adobe Reader and Acrobat 9
The JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 on Mac OS X and Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Red Hat
condor: lock directories created mode 0777 allow for FS-based authentication challenge bypass
vendor_redhat·2012-09-19·CVSS 6.4
CVE-2012-3492 [MEDIUM] condor: lock directories created mode 0777 allow for FS-based authentication challenge bypass
condor: lock directories created mode 0777 allow for FS-based authentication challenge bypass
The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories even when they have weak permissions, which allows remote attackers to impersonate users by renaming a user's authentication directory.
Red Hat
acroread: multiple unspecified flaws (APSB12-08, APSB12-01)
vendor_redhat·2012-04-05·CVSS 6.8
CVE-2012-0777 [MEDIUM] acroread: multiple unspecified flaws (APSB12-08, APSB12-01)
acroread: multiple unspecified flaws (APSB12-08, APSB12-01)
The JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 on Mac OS X and Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Red Hat
CLI: world-writable root directory
vendor_redhat·2012-03-20·CVSS 3.7
CVE-2012-0032 [LOW] CLI: world-writable root directory
CLI: world-writable root directory
Red Hat JBoss Operations Network (JON) before 3.0.1 uses 0777 permissions for the root directory when installing a remote client, which allows local users to read or modify subdirectories and files within the root directory, as demonstrated by obtaining JON credentials.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3492 condor: lock directories created mode 0777 allow for FS-based authentication challenge bypass
bugzilla·2012-08-14·CVSS 6.4
CVE-2012-3492 [MEDIUM] CVE-2012-3492 condor: lock directories created mode 0777 allow for FS-based authentication challenge bypass
CVE-2012-3492 condor: lock directories created mode 0777 allow for FS-based authentication challenge bypass
Florian Weimer of the Red Hat Product Security Team discovered that Condor's file system authentication challenge accepted directories with weak permissions (for example, world readable, writable and executable permissions). If a user created a directory with such permissions, a local attacker could rename it, allowing them to execute jobs with the privileges of the victim user.
Discussion:
Acknowledgements:
This issue was discovered by Florian Weimer of the Red Hat Product Security Team.
---
This issue has been addressed in following products:
MRG for RHEL-5 v. 2
Via RHSA-2012:1278 https://rhn.redhat.com/errata/RHSA-2012-1278.html
---
This issue has been addressed in follo
Bugzilla
CVE-2011-4370 CVE-2011-4371 CVE-2011-4372 CVE-2011-4373 CVE-2012-0774 CVE-2012-0775 CVE-2012-0777 acroread: multiple unspecified flaws (APSB12-08, APSB12-01)
bugzilla·2012-04-05·CVSS 7.5
CVE-2011-4370 [HIGH] CVE-2011-4370 CVE-2011-4371 CVE-2011-4372 CVE-2011-4373 CVE-2012-0774 CVE-2012-0775 CVE-2012-0777 acroread: multiple unspecified flaws (APSB12-08, APSB12-01)
CVE-2011-4370 CVE-2011-4371 CVE-2011-4372 CVE-2011-4373 CVE-2012-0774 CVE-2012-0775 CVE-2012-0777 acroread: multiple unspecified flaws (APSB12-08, APSB12-01)
Adobe has released a prenotification of APSB12-08 indicated that it will release updates for Adobe Reader 9.x for Linux. No details have been noted other than that they fix critical vulnerabilities in the software.
External References:
http://www.adobe.com/support/security/bulletins/apsb12-08.html
Discussion:
Further details from the bulletin, updated today:
These updates resolve an integer overflow in the True Type Font (TTF) handling that could lead to code execution (CVE-2012-0774).
These updates resolve a memory corruption in the JavaScript handling that could lead to code execution (CVE-2012-0775).
These updates resolve a
Bugzilla
CVE-2012-0032 JON CLI: world-writable root directory
bugzilla·2012-01-09·CVSS 3.7
CVE-2012-0032 [LOW] CVE-2012-0032 JON CLI: world-writable root directory
CVE-2012-0032 JON CLI: world-writable root directory
After installing the remote client from JON 3.0, the extracted root directory is world readable/writeable/executable (0777). Although the child directories are not world writeable, by the parent directory being left in a world writeable state, it is possible to modify directory and file attributes on the child contents to trick the user into executing malicious scripts or code. A local attacker could use this flaw to compromise a remote JON server, using the credentials stolen from a privileged JON user who is using the remote client CLI from a system the local attacker has access to.
Discussion:
This issue has been addressed in following products:
JBoss Operations Network 3.0.1
Via RHSA-2012:0406 https://rhn.redhat.com/errata/RHSA-
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00017.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0469.htmlhttp://secunia.com/advisories/48756http://secunia.com/advisories/48846http://www.adobe.com/support/security/bulletins/apsb12-08.htmlhttp://www.securityfocus.com/bid/52950http://www.securitytracker.com/id?1026908http://www.us-cert.gov/cas/techalerts/TA12-101B.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/74735http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-04/msg00017.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0469.htmlhttp://secunia.com/advisories/48756http://secunia.com/advisories/48846http://www.adobe.com/support/security/bulletins/apsb12-08.htmlhttp://www.securityfocus.com/bid/52950http://www.securitytracker.com/id?1026908http://www.us-cert.gov/cas/techalerts/TA12-101B.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/74735
2012-04-10
Published