[26150] in bugtraq
Vulnerability found: The Adobe eBook Library
daemon@ATHENA.MIT.EDU (Vladimir Katalov)
Fri Jul 12 15:20:13 2002
Date: Fri, 12 Jul 2002 15:56:03 +0400
From: Vladimir Katalov <info@elcomsoft.com>
Reply-To: Vladimir Katalov <info@elcomsoft.com>
Message-ID: <8485278525.20020712155603@elcomsoft.com>
To: bugtraq@securityfocus.com, vuln-dev@securityfocus.com
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----------A2117E533986C45"
------------A2117E533986C45
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
-----BEGIN PGP SIGNED MESSAGE-----
Hash: MD5
Find attached the detailed information about the bugs/vulnerabilities
we have found in The Adobe eBook Library.
- --
Sincerely yours,
Vladimir
Vladimir Katalov
Managing Director
ElcomSoft Co.Ltd.
Member of Russian Cryptology Association
mailto:info@elcomsoft.com
http://www.elcomsoft.com (Corporate site)
http://www.crackpassword.com (Password Recovery Software)
-----BEGIN PGP SIGNATURE-----
Version: 2.6
iQEVAwUAPS7D14avf/iY3ldlAQFtbQf/TAvucVkcbkK63KOg/bVUXRzg8I106UaT
kROzh9GoqJPxh9Gp5xFJASg5cGPrHaNeDq6kMksHBL4EBpsUtjheCaZGBk0w66GK
+Kj6A0X1QW28/vTo9GKcBlLB3TGkVQrrCod7ofluIJHe9Jcd+ca85s9BfiEm02B+
MplH5hkQGrE2G4M+UPRATpzXAgvyu1eW+IA5l3aNmDOQNrXsAZchR8mZm7KY3E2H
sjTS9rnDkH8CdjV04WB8C7D7d/yoWVdL/MG0ghRekw1TUeyFjtFEKv62EsU6zBMV
+1gNk56LXEWMJHKsMU81kPRrmCQNwtL7zM+ApHIu6sXqMQ+fsJEc4Q==
=iwne
-----END PGP SIGNATURE-----
------------A2117E533986C45
Content-Type: text/plain; name="vuln-adobe-library.txt"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="vuln-adobe-library.txt"
Q09OVEFDVCBJTkZPUk1BVElPTg0KPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQ0KDQogTmFtZQkJCTog
VmxhZGltaXIgS2F0YWxvdg0KIEUtbWFpbAkJCTogaW5mb0BlbGNvbXNvZnQuY29tDQogUGhvbmUg
LyBmYXgJCTogKzcgMDk1IDIxNi03OTM3DQogICAgICAgICAgICAgICAgICAgICAgICAgICsxIDg2
NiA0NDgtMjcwMyAoZmF4OyBVUywgdG9sbC1mcmVlKQ0KIEFmZmlsaWF0aW9uIGFuZCBhZGRyZXNz
OiAyLTE3MSBnZW5lcmFsYSBBbnRvbm92YSBzdC4NCiAgICAgICAgICAgICAgICAgICAgICAgICAg
TW9zY293IDExNzI3OQ0KICAgICAgICAgICAgICAgICAgICAgICAgICBSdXNzaWENCg0KDQpURUNI
TklDQUwgSU5GTw0KPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQ0KDQpEZXNjcmlwdGlvbg0KLS0tLS0t
LS0tLS0NCg0KICBBZG9iZSBTeXN0ZW1zIEluY29ycG9yYXRlZCAoaHR0cDovL3d3dy5hZG9iZS5j
b20pIHJlY2VudGx5IG9wZW5lZA0KICBhIHNwZWNpYWwgd2ViIHNpdGUgdG8gZGVtb25zdHJhdGUg
dGhlIG5ldyBsaWJyYXJ5IGZlYXR1cmVzIG9mDQogIEFkb2JlIENvbnRlbnQgU2VydmVyIDMuMCAo
aHR0cDovL3d3dy5hZG9iZS5jb20vcHJvZHVjdHMvY29udGVudHNlcnZlcikuDQogIEFjY29yZGlu
ZyB0byBBZG9iZSBkZXNjcmlwdGlvbiwgIlRoZSBBZG9iZSBlQm9vayBMaWJyYXJ5IHVzZXMgQWRv
YmUNCiAgQ29udGVudCBTZXJ2ZXIgYXMgYSBzZWN1cmUgcmVwb3NpdG9yeSBmb3IgdGhlIGVCb29r
cyIuIFRoZSBsaWJyYXJ5DQogIGlzIGxvY2F0ZWQgYXQ6DQoNCiAgaHR0cDovL2xpYnJhcnlkZW1v
LmFkb2JlLmNvbS9saWJyYXJ5Lw0KDQogIFRoZXJlIGFyZSBhIGZldyBib29rcyBhdmFpbGFibGUg
LS0gNSBjb3BpZXMgb2YgZWFjaC4gVGhlIGN1c3RvbWVyDQogIGNhbiBib3Jyb3cgYW55IGJvb2sg
Zm9yIGEgZml4ZWQgcGVyaW9kIG9mIHRpbWUgKG9uZSBvciB0aHJlZSBkYXlzKTsNCiAgd2hlbiBv
bmUgY3VzdG9tZXIgZ2V0cyBhIGJvb2ssIHRoZSBjb3VudGVyICgibnVtYmVyIG9mIGJvb2tzDQog
IGF2YWlsYWJsZSIpIGlzIGRlY3JlYXNlZCwgYW5kIHdoZW4gaXQgcmVhY2hlcyB6ZXJvLCB0aGlz
IGJvb2sNCiAgYmVjb21lcyBub3QgYXZhaWxhYmxlIHVudGlsIGF0IGxlYXN0IG9uZSBvdGhlciBj
dXN0b21lciB3aWxsIHJldHVybg0KICBpdCB0byB0aGUgbGlicmFyeSwgb3IgbG9hbiBwZXJpb2Qg
d2lsbCBleHBpcmUuIEhvd2V2ZXIsIHRoZXJlIGFyZSB0aHJlZQ0KICBidWdzL3Z1bG5lcmFiaWxp
dGllcyB0aGVyZToNCg0KICAxLiBJdCBpcyBwb3NzaWJsZSB0byBnZXQgYWxsIGF2YWlsYWJsZSBj
b3BpZXMgb2YgYW55IGJvb2sgLS0NCiAgICAgQWRvYmUgQWNyb2JhdCBlQm9vayBSZWFkZXIgZG9l
c24ndCBjaGVjayBpZiB5b3UgaGF2ZSBib3Jyb3dlZCB0aGUNCiAgICAgZ2l2ZW4gYm9vayBhbHJl
YWR5LiANCg0KICAyLiBUaGUgbG9hbiBwZXJpb2QgKG9uZSBvciB0aHJlZSBkYXlzKSBpcyBub3Qg
dmVyaWZpZWQuIEl0IGlzIGltcGxlbWVudGVkDQogICAgIGluIHRoZSBzY3JpcHQgdXNpbmcgdGhl
IGZvbGxvd2luZw0KDQogICAgIDxGT1JNIGlkPWZvcm0yIG5hbWU9ImZvcm0yIiBBQ1RJT049Imh0
dHA6Ly9saWJyYXJ5ZGVtby5hZG9iZS5jb20vbGlicmFyeS9kb3dubG9hZC5hc3AiIE1FVEhPRD0i
UE9TVCI+DQogICAgICAgPElOUFVUIHR5cGU9aGlkZGVuIHZhbHVlPTEzMyBuYW1lPWJvb2tpZD4g
DQogICAgICAgPElOUFVUIHR5cGU9cmFkaW8gQ0hFQ0tFRCB2YWx1ZT0xNDQwIG5hbWU9bG9hbk1p
bj4gQm9ycm93IGZvciAxIGRheTxCUj4NCiAgICAgICA8SU5QVVQgdHlwZT1yYWRpbyB2YWx1ZT00
MzIwIG5hbWU9bG9hbk1pbj4gQm9ycm93IGZvciAzIGRheXM8QlI+DQogICAgICAgLi4uDQoNCiAg
ICAgVGhlIHZhbHVlIG9mIGxvYW5NaW4gaXMgdGhlIGxvYW4gcGVyaW9kIGluIG1pbnV0ZXMgKDE0
NDAgZm9yIG9uZQ0KICAgICBkYXksIGFuZCA0MzIwIGZvciB0aHJlZSBkYXlzKS4gSXQgaXMgcG9z
c2libGUgdG8gc2F2ZSB0aGUgZm9ybSB0bw0KICAgICB0aGUgbG9jYWwgZGlzaywgY2hhbmdlIG9u
ZSBvZiB0aGUgdmFsdWVzIHRvIHRoZSBvbmUgeW91IG5lZWQgKGkuZS4NCiAgICAgNTI1NjAwIGZv
ciBvbmUgeWVhciksIGxvYWQgdGhlIHVwZGF0ZWQgZm9ybSBpbnRvIHRoZSBicm93c2VyLCBhbmQN
CiAgICAgYnkgcHJlc3NpbmcgdGhlICJBZGQgdG8gIGJvb2tiYWciIGJ1dHRvbiBib3Jyb3cgdGhp
cyBib29rIGZvciB0aGUNCiAgICAgc2VsZWN0ZWQgKCJmYWtlIikgcGVyaW9kLiANCg0KICAzLiBX
aGVuIHRoZSBib29rIGNvdW50ZXIgcmVhY2hlcyB6ZXJvLCB0aGUgdXNlciBjYW4gc2VlIGEgbm90
ZSBuZWFyIHRoZQ0KICAgICBib29rIGRlc2NyaXB0aW9uOiANCg0KICAgICBUaGVyZSBhcmUgY3Vy
cmVudGx5IG5vbmUgYXZhaWxhYmxlLg0KICAgICBQbGVhc2UgY2hlY2sgYmFjayBsYXRlci4gDQoN
CiAgICAgSG93ZXZlciwgdGhlICJBZGQgdG8gIGJvb2tiYWciIGJ1dHRvbiBpcyBzdGlsbCBhdmFp
bGFibGUgYW5kIHdvcmtpbmcNCiAgICAganVzdCBmaW5lLCBpLmUuIGl0IGlzIHN0aWxsIHBvc3Np
YmxlIHRvIGdldCBhbm90aGVyIGNvcHkgKGNvcGllcykgb2YNCiAgICAgdGhlIGJvb2suIEFuZCB0
aGUgIk51bWJlciBvZiBCb29rcyIgY291bnRlciAob24gdGhlIGxpYnJhcnkgcGFnZSkNCiAgICAg
YmVjb21lcyBuZWdhdGl2ZS4NCg0KVGhlIGltcGFjdA0KLS0tLS0tLS0tLQ0KDQogIEJ5IGNvbWJp
bmluZyBidWdzIFsxXSBhbmQgWzJdLCBpdCBpcyB2ZXJ5IGVhc3kgdG8gaW1wbGVtZW50IHNvbWV0
aGluZw0KICBsaWtlICJEZW5pYWwtb2Ytc2VydmljZSIgYXR0YWNrIGZvciB0aGUgbGlicmFyeTog
anVzdCBnZXQgYWxsIGNvcGllcyBvZg0KICBhbGwgYm9va3MgZnJvbSB0aGUgbGlicmFyeSAoZm9y
IHZlcnkgbGFyZ2UgcGVyaW9kIG9mIHRpbWUgLS0gZS5nLiBhIGZldw0KICB5ZWFycykuIFNvIG5v
IGJvb2tzIHdpbGwgYmUgYXZhaWxhYmxlIHRvIGFueWJvZHkgZWxzZS4NCg0KICBCZXNpZGVzLCB0
aGVyZSBpcyBhYmlsaXR5IHRvIGJvcnJvdyB0aGUgYm9va3MgZm9yIHVubGltaXRlZCB0aW1lLg0K
DQpQb3NzaWJsZSB3b3JrYXJvdW5kL2ZpeGVzDQotLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tDQoN
CiAgVGhlIHNjcmlwdCBzaG91bGQgdmVyaWZ5ICdsb2FuTWluJyBpbnB1dCB2YWx1ZSwgYW5kIHNo
b3VsZA0KICBub3QgYWxsb3cgdG8gYm9ycm93IHRoZSBib29rIGlmIGl0IGRvZXMgbm90IG1hdGNo
IHByZS1kZWZpbmVkDQogIHZhbHVlcywgb3IgaWYgbnVtYmVyIG9mIGJvb2tzIGF2YWlsYWJsZSBp
cyBhbHJlYWR5IHplcm8uDQoNCg0KT1RIRVIgSU5GT1JNQVRJT04NCj09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PQ0KDQogIFNvbWUgdGltZSBhZ28gd2UgaGF2ZSBmb3VuZCBtdWNoIG1vcmUgc2VyaW91cyBwcm9i
bGVtIHdpdGggYW5vdGhlcg0KICBBZG9iZSBzb2Z0d2FyZSBhbmQgcmVwb3J0ZWQgaXQgdG8gdGhl
IHZlbmRvcjsgaG93ZXZlciwgdGhlcmUgd2FzIG5vDQogIHJlc3BvbnNlIGF0IGFsbCwgYW5kIHNv
IHdlIGRlY2lkZWQgbm90IHRvIHdhc3RlIG91ciB0aW1lIHJlcG9ydGluZw0KICB0aGlzIG9uZSAo
YWJvdXQgdGhlIGxpYnJhcnkpIHRvIEFkb2JlLg0K
------------A2117E533986C45--