Author Topic: Adobe pdf exploits  (Read 3508 times)

0 Members and 1 Guest are viewing this topic.

May 09, 2010, 12:47:18 pm
Read 3508 times

notforprophet

  • Newbie

  • Offline
  • *

  • 1
Malware links:

onufriy.3utilities.com/index.php, onufriy.3utilities.com/pdf.php?spl=ie


Analyses by Wepawet: http://wepawet.iseclab.org/view.php?hash=05c0d67898eb373bd851117119ee5558&t=1273408709&type=js
                              http://wepawet.cs.ucsb.edu/view.php?type=js&hash=2f01c7a0deda94b2bc2798f527e97804&t=1273259899

Exploits listed:
Adobe Collab overflow   Multiple Adobe Reader and Acrobat buffer overflows   CVE-2007-5659
Adobe util.printf overflow   Stack-based buffer overflow in Adobe Acrobat and Reader via crafted format string argument in util.printf   CVE-2008-2992
Adobe getIcon   Stack-based buffer overflow in Adobe Reader and Acrobat via the getIcon method of a Collab object   CVE-2009-0927
doc.media.newPlayer   Use-after-free vulnerability in the Doc.media.newPlayer method in Adobe Reader and Acrobat 8.0 through 9.2   CVE-2009-4324

Additional (potential) malware:

http://onufriy.3utilities.com/loading.php?spl=pdf_email_       

http://onufriy.3utilities.com/loading.php?spl=pdf_geticon_       

http://onufriy.3utilities.com/loading.php?spl=pdf_mediapl_       

http://onufriy.3utilities.com/loading.php?spl=pdf_printf_