With regards to the Adobe Acrobat Reader advisory (#NISR03022004)

"NGSSoftware Insight Security Research" <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.announce,gmane.comp.security.bugtraq,gmane.comp.security.ntbugtraq
Message-ID <007801c406d3$74317180$61d5389d@GLADIUS>
Hello all,
I've been inundated with e-mails asking whether operating systems other than 
Windows are affected by XFDF overflow. Whilst I did not state that Windows 
is the only OS affected, and I should have done, I thought it was clear, 
incorrectly, that Adobe Acrobat Reader for Windows was indeed the only one 
and not Mac, *nix, etc.

From the original advisory:

When the xfdf file is parsed an unsafe call to sprintf is made in
preparation for outputting a debug message using OutputDebugString.

OutputDebugString is a Win32 API function, exported by kernel32.dll. 
Conseqently, the vulnerable code path will exist only in the Windows version 
of Adobe Acrobat Reader.

I hope this clears up any confusion.

Cheers,
David Litchfield
NGSSoftware/NGSConsulting
http://www.nextgenss.com/
+44(0)208 401 0070
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.