Adobe Reader 8 contains multiple input validation errors. According to Adobe these flaws could result in arbitrary code execution with the permissions of the user running Adobe Reader.
Public now via upstream security bulletin: http://www.adobe.com/support/security/bulletins/apsb08-19.html Additional details from iDefense advisory: http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=755 http://marc.info/?l=full-disclosure&m=122583271427154&w=4 The vulnerability specifically exists in code responsible for parsing Type 1 fonts. After allocating an area of memory, no bounds checking is performed. Subsequent access of this memory may result in modification of arbitrary memory, which in turn may result in arbitrary code execution.
This issue was addressed in: Red Hat Enterprise Linux Extras: http://rhn.redhat.com/errata/RHSA-2008-0974.html