Il faut passer en 7.0.1
The vulnerability is within the Adobe Reader control; if the control is placed on a web page, it is possible to discover the existence of local files by calling the .LoadFile(filename) method and monitoring its behaviour.
An attacker could then use the information gathered to help prepare for a more serious attack.
However the impact is minimised due to the fact that the existence of local files can only be discovered if the complete filenames and paths are known in advance by the attacker.
# Faille de sécurité
Posté par Gauthier (Mastodon) . En réponse à la dépêche Retour d'Adobe sur les plates-formes Linux ?. Évalué à 4.
The vulnerability is within the Adobe Reader control; if the control is placed on a web page, it is possible to discover the existence of local files by calling the .LoadFile(filename) method and monitoring its behaviour.
An attacker could then use the information gathered to help prepare for a more serious attack.
However the impact is minimised due to the fact that the existence of local files can only be discovered if the complete filenames and paths are known in advance by the attacker.