Re: xpdf and acrobat reader hole

Sam Halliday <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
James Iwanek wrote:
> Jochen Schroeder wrote:
> > There is a whole in acrobat reader and xpdf which let's you execute
> > any shell command from within a pdf-dokument. Nice thing if you
> > embed rm -rf$HOME/* within an pdf-file. Am still not quite sure if
> > this really is a hole or considered a feature ;-). Anyways here's
> > the relevant link:
> > http://lists.netsys.com/pipermail/full-disclosure/2003-June/010397.html
> any fool knows you have a more robust hack if you were to replace
> monkey with $USER ;-)

`rm -rf $HOME/$USER`

can't see that doing much :-/
(e.g. expanded=`rm -rf /home/samuel/samuel`)

however, a REAL fool would use the opportunity to plant a backdoor or
mail a secret GPG key back home... the simplicity of this exploit is
quite scary, i imagine that most applications/formats have similar
issues; especially with everything trying so hard to interoperate on a
point-and-click basis.

i wonder if large archives like arXiv.org are going to parse for this
kind of thing? they generate PDF files on demand (with some level of
caching) from the source .tex files. however, someone actually using
this kind of exploit with their name attached to it is enough to lose
them a career in research, but it is scary that such an exploit is
possible to begin with...

Sam... thinking about moving this to lfs-chat
-- 
Trespassers will be shot. Survivors will be SHOT AGAIN!
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)

iD8DBQE+7mn13qTuwoWzAjMRAu26AJoDpl0IBOZGTPLZayvdWoWJV2U6OACgqhgC
el3R8K3jClJ0Ji79jr6bLV8=
=NSVI
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.