Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Adobe Acrobat Plug-In Forged Digital Signature Vulnerability

Adobe Acrobat fails to check the validity of a plug-in beyond the portable executable headers. This could allow a plug-in with a valid digital signature to be modified and still seen as trusted by Acrobat. Additionally, a trusted plug-in could be modified to load another, untrusted plug-in and pass control to it.

** Reports indicate that a virus exists that exploits this vulnerability in order to propagate.







 

Privacy Statement
Copyright 2008, SecurityFocus