Vulnerability Description
libCoolType library as used in Adobe Acrobat (acroread) on Linux creates the AdobeFnt.lst file with world-writable permissions, which allows local users to modify the file and possibly modify acroread's behavior.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Acrobat Reader | 4.0.5 |
References
- http://lists.debian.org/debian-security/2001/debian-security-200101/msg00085.htmVendor Advisory
- http://marc.info/?l=bugtraq&m=99849121502399&w=2
- http://www.securityfocus.com/bid/3225PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7024
- http://lists.debian.org/debian-security/2001/debian-security-200101/msg00085.htmVendor Advisory
- http://marc.info/?l=bugtraq&m=99849121502399&w=2
- http://www.securityfocus.com/bid/3225PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7024
FAQ
What is CVE-2001-1069?
CVE-2001-1069 is a vulnerability with a CVSS score of 7.2 (HIGH). libCoolType library as used in Adobe Acrobat (acroread) on Linux creates the AdobeFnt.lst file with world-writable permissions, which allows local users to modify the file and possibly modify acroread...
How severe is CVE-2001-1069?
CVE-2001-1069 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-1069?
Check the references section above for vendor advisories and patch information. Affected products include: Adobe Acrobat Reader.