The digital signature mechanism for the Adobe Acrobat PDF viewer only verifies the PE header of executable code for a plug-in, which can allow attackers to execute arbitrary code in certified mode by making the plug-in appear to be signed by Adobe.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Acrobat | Adobe | 4.0 (including) | 4.0 (including) |
Acrobat | Adobe | 4.0.5 (including) | 4.0.5 (including) |
Acrobat | Adobe | 4.0.5a (including) | 4.0.5a (including) |
Acrobat | Adobe | 4.0.5c (including) | 4.0.5c (including) |
Acrobat | Adobe | 5.0 (including) | 5.0 (including) |
Acrobat | Adobe | 5.0.5 (including) | 5.0.5 (including) |
Acrobat_reader | Adobe | 4.0 (including) | 4.0 (including) |
Acrobat_reader | Adobe | 4.0.5 (including) | 4.0.5 (including) |
Acrobat_reader | Adobe | 4.0.5a (including) | 4.0.5a (including) |
Acrobat_reader | Adobe | 4.0.5c (including) | 4.0.5c (including) |
Acrobat_reader | Adobe | 5.0 (including) | 5.0 (including) |
Acrobat_reader | Adobe | 5.0.5 (including) | 5.0.5 (including) |