First published: Fri Aug 31 2001(Updated: )
libCoolType library as used in Adobe Acrobat (acroread) on Linux creates the AdobeFnt.lst file with world-writable permissions, which allows local users to modify the file and possibly modify acroread's behavior.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | =4.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1069 is considered a high severity vulnerability due to its potential to allow local users to modify critical system files.
To fix CVE-2001-1069, change the permissions of the AdobeFnt.lst file to restrict access to only the necessary users.
CVE-2001-1069 affects Adobe Acrobat Reader version 4.0.5 on Linux systems.
CVE-2001-1069 allows local users to modify the AdobeFnt.lst file, potentially altering the behavior of Acrobat Reader.
CVE-2001-1069 may still be relevant for systems using the outdated Adobe Acrobat Reader 4.0.5, especially in environments that require legacy software.