First published: Wed May 14 2003(Updated: )
Adobe Acrobat 5 does not properly validate JavaScript in PDF files, which allows remote attackers to write arbitrary files into the Plug-ins folder that spread to other PDF documents, as demonstrated by the W32.Yourde virus.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0284 has a high severity rating due to its potential to allow remote attackers to write arbitrary files.
To fix CVE-2003-0284, you should upgrade to a newer version of Adobe Acrobat that addresses this vulnerability.
The risks of CVE-2003-0284 include the potential for malware distribution and unauthorized file manipulation on affected systems.
CVE-2003-0284 specifically affects Adobe Acrobat 5.0.
CVE-2003-0284 is specific to Adobe Acrobat and does not affect other PDF readers directly, but similar vulnerabilities may exist in other software.