PT-2005-2808 · Adobe · Reader
Published
2005-07-07
·
Updated
2008-09-05
·
CVE-2005-1841
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe Reader versions 5.0.9 through 5.0.10
Description
The issue allows local users to potentially read PDF documents of another user due to the control creating temporary files with permissions specified by the user's umask. This could lead to unauthorized access to sensitive information if the umask settings allow it.
Recommendations
For Adobe Reader versions 5.0.9 through 5.0.10, consider adjusting the umask settings to restrict access to temporary files created by the control, or apply specific permissions to limit readability of these files. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Reader