This application requires Javascript for optimal performance.

PDF.With.Launch.Action

Release Date

Apr 30, 2010

Severity

medium

Impact

Arbitrary command execution

Description

This indicates an attempt to download a PDF file with a launch action that provides a way to launch a command and may ultimately run an executable.

Affected Products

Adobe Reader
Foxit Reader

Recommended Actions

Apply the patch from the vendor:
http://www.adobe.com/support/security/bulletins/apsb10-15.html

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-0837
CVE-2010-1240

Reference/s

http://www.adobe.com/support/security/bulletins/apsb10-15.html
http://blog.didierstevens.com/2010/03/29/escape-from-pdf/
http://www.securityfocus.com/bid/34035 (BugTraq)

Reference: VID-20817