Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against Adobe Reader Plugin Cross-site Scripting Vulnerability (APSB07-01)

Subscribe

Check Point Reference: CPAI-2010-011
Date Published:
Severity:
Source: Adobe Security Bulletin - APSB07-01
Industry Reference(s): CVE-2007-0045
CVE-2007-0048
Protection Provided by: Security Gateway
  • R70
VPN-1
  • NGX R65
VSX
  • NGX R65
Who is Vulnerable?
Adobe Reader 7.0.8 and earlier versions
Adobe Acrobat Standard, Professional and Elements 7.0.8 and earlier versions
Adobe Acrobat 3D
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities have been discovered in Adobe Reader and Acrobat Plugin when used with various Web browsers. Cross-site scripting occurs when a Web-based application fails to validate user input before returning it to the client's browser. This enables attackers to inject malicious content into Web pages to be executed in the context of the user's browser. A remote attacker could exploit these issues to execute a cross-site scripting attack or cause a denial of service condition.
Update/Patch Available
Apply patches:
Adobe Security Bulletin - APSB07-01
Vulnerability Details
The vulnerabilities are due to an error in the Adobe Acrobat Reader Plugin.

CVE-2007-0045: Successful exploitation of this issue allows remote attackers to inject arbitrary JavaScript and conduct other attacks via a malformed PDF URL.

CVE-2007-0048: Successful exploitation of this issue allows remote attackers to cause a denial of service condition via a long sequence of hash characters appended to a PDF URL.

Protection Overview
This protection will detect and block attempts to exploit this vulnerability.

In order for the protection to be activated, update your Security Gateway/VPN-1 product to the latest IPS/SmartDefense update. For information on how to update IPS/SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.

To configure the defense, select your product from the list below and follow the related protection steps.

Security Gateway R70

How Can I Protect My Network?
1. In the IPS tab, click Protections > By Protocol > Application Intelligence > Content Protection > Adobe Reader and Acrobat.
2. In the right pane, double-click the Adobe Reader Plugin Malformed URL Cross-Site Scripting (APSB07-01) protection.
3. In the Protection Details window, click on Edit. Choose the protection's Action (Override IPS Policy with: Prevent/Detect), and apply Additional Settings.
4. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Adobe Reader Violation
Attack Information: Adobe Reader plugin malformed URL cross-site scripting (APSB07-01)

VPN-1 NGX R65 & VPN-1 VSX NGX R65

How Can I Protect My Network?
1. In the SmartDefense tab, click Application Intelligence > Content Protection.
2. Select the following protection:

Adobe Reader Plugin Malformed URL Cross-Site Scripting (APSB07-01)

3. In the configuration pane, under Settings > Mode, check Active.
4. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Adobe Reader Violation
Attack Information: Adobe Reader plugin malformed URL cross-site scripting (APSB07-01)