PdfÔĶÁÆ÷Êý×ÖÊðÃûαÔìÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-03-01

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì¹æÄ£


ÊÜÓ°ÏìÈí¼þÒÔ¼°°æ±¾£º 


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!



Îó²î¸ÅÊö


µÂ¹ú²¨ºè³¶û´óѧµÄѧÕßÑо¿·¢Ã÷ £¬ÔÚ22¸öPDFÔĶÁÆ÷Ó¦ÓóÌÐòºÍ7¸öÔÚÏßÑéÖ¤·þÎñÖб£´æPDFÊðÃûαÔìÎó²î £¬ÕâЩÎó²î¿É±»Ê¹ÓÃÀ´¶ÔPDFÎĵµµÄÊý×ÖÊðÃû¾ÙÐÐδ¾­ÊÚȨµÄ¸ü¸Ä £¬µ«²»»áʹÆäÎÞЧ¡£


´øÊý×ÖÊðÃûµÄPDFÎļþÔÚÆóÒµºÍÕþ¸®×éÖ¯Öб»×÷Ϊ¾ßÓÐÖ´·¨Ð§Ó¦µÄÕýʽÎļþÆÕ±éʹÓà £¬ÆäÖÐ £¬Êý×ÖÊðÃûÊÇÇø·ÖÎļþÕæÊµÐÔµÄÖ÷Òª»·½Ú £¬ÊðÃûαÔìÎó²îÒ»µ©±»¶ñÒâʹÓà £¬Ôò¿ÉÄܸøÆóÒµºÍÕþ¸®´øÀ´ÉÌÒµÉñÃØ»ò¾­¼ÃÉϵÄËðʧ¡£


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


Ò×ÊÜÕâЩ¹¥»÷µÄÈí¼þÁбíÖаüÀ¨¶à¿î½ÏΪʢÐеÄPDFÎĵµÔĶÁÆ÷Èí¼þ £¬ÈçAdobe Reader £¬Foxit Reader £¬LibreOffice £¬Nitro Reader £¬PDF-XChangeºÍSoda PDFµÈ¡£ÓÐȱÏݵÄÑéÖ¤·þÎñ°üÀ¨DocuSign £¬eTRÑéÖ¤·þÎñ £¬DSSÑÝʾWebApp £¬EvotrustºÍVEP.siµÈ¡£


ÏÖÔÚ £¬ËùÓÐÌṩPDFÔĶÁÆ÷Ó¦ÓóÌÐòµÄ¹«Ë¾¶¼ÒÑÐû²¼Çå¾²²¹¶¡À´½â¾öÕâ¸öÎÊÌâ £¬¶øÒ»Ð©ÔÚÏß·þÎñÉÐδ½â¾öÕâЩÎÊÌâ¡£


ѧÕßÉè¼ÆÁËÈýÖÖPDFÊðÃûÓÕÆ­¹¥»÷ÊÖÒÕ £¬²¢»®·ÖÃüÃûΪͨÓÃÊðÃûαÔ죨USF£© £¬ÔöÁ¿ÉúÑĹ¥»÷£¨ISA£©ºÍÊðÃû°ü×°¹¥»÷£¨SWA£©¡£


ÔÚUSF£¨Universal Signature Forgery£©¹¥»÷ÖÐ £¬¹¥»÷Õß¿ÉÒÔʹÓÃÊðÃûÖеÄÔªÐÅÏ¢ £¬ÕâÑùPDFÔĶÁÆ÷ÔÚÑéÖ¤ÊðÃûʱ¾ÍÎÞ·¨»á¼ûÑéÖ¤ËùÐèµÄÊý¾Ý £¬È´Ê¼ÖÕÒÔΪÊðÃûÓÐÓà £¬ÀýÈçAcrobat Reader DCºÍReader XI¡£


ISA£¨Incremental Saving Attack£©¹¥»÷ʹÓÃPDF¹æ·¶ÖеÄÕýµ±¹¦Ð§ £¬ÔÊÐíͨ¹ý¸½¼Ó¸ü¸ÄÀ´¸üÐÂÎļþ £¬ÀýÈçÉúÑÄ×¢ÊÍ»òÏòÎĵµÌí¼ÓÐÂÒ³Ãæ¡£¸Ã¹¥»÷¼Æ»®Í¨¹ý¸ü¸Ä²»ÊôÓÚÊðÃûÍêÕûÐÔ± £»¤µÄÔªÏòÀ´ÐÞ¸ÄÎĵµ¡£


SWA£¨Signature Wrapping Attack£©¹¥»÷Ç¿ÖÆÊðÃûÑéÖ¤Âß¼­ÆÊÎöÓëԭʼÎĵµ²î±ðµÄÎĵµ²¿·Ö¡£ÕâÊÇͨ¹ý¡°½«Ô­Ê¼ÊðÃûµÄÄÚÈÝÖØÐ¶¨Î»µ½ÎĵµÖеIJî±ðλÖò¢ÔÚ·ÖÅɵÄλÖòåÈëÐÂÄÚÈÝÀ´Íê³ÉµÄ¡£¡±SWA Ó°ÏìÁËÐí¶àPDFÔĶÁÆ÷ºÍһЩÔÚÏßÑéÖ¤·þÎñ¡£


ÐÞ¸´½¨Òé


¾¡¿ì¸üÐÂÊÂÇé×°±¸ËùʹÓõÄPDFÔĶÁÆ÷Ó¦ÓóÌÐòÖÁ¹Ù·½×îаæ¡£


²Î¿¼Á´½Ó


https://www.nds.ruhr-uni-bochum.de/media/ei/veroeffentlichungen/2019/02/12/report.pdf