VWE-2016-2706 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2016-2706
This page is a chapter in Info Known Vulnerabilities

This page has been seen 144,848 times.

    • Created by on
      Last updated by on
Common NameSuspect PDF Vulnerability
VWE-IDVWE-2016-2706
Related ReportNone
SeverityMINOR
Exploit DifficultyEASY
PlatformAffects all platforms supported by the vulnerable versions.
DescriptionSample PDF included in the ZIP triggers off anti-virus/malware response. Does not affect Lite versions.
DiscoveredMay 30, 2016
ResolvedJuly 5, 2016
Due to lack of information from Adobe, it is unclear whether the PDF is actually dangerous, or if the response is a false-positive. As of July 15, 2016, Adobe continues to distribute the flawed PDF on their own web site. Nevertheless, these patches replace the suspect file with an updated PDF that does not trigger anti-virus response.
Patches Available4.0.12 Patch Level 1
4.0.11 Patch Level 1
4.0.10 Patch Level 2
4.0.9 Patch Level 2
4.0.8 Patch Level 4
4.0.7 Patch Level 5
4.0.6 Patch Level 8
WorkaroundManually remove /vault/model/image/test.pdf from the ZIP.
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.