PdfÔĶÁÆ÷Êý×ÖÊðÃûαÔìÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-03-01Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì¹æÄ£
ÊÜÓ°ÏìÈí¼þÒÔ¼°°æ±¾£º
Îó²î¸ÅÊö
µÂ¹ú²¨ºè³¶û´óѧµÄѧÕßÑо¿·¢Ã÷£¬ÔÚ22¸öPDFÔĶÁÆ÷Ó¦ÓóÌÐòºÍ7¸öÔÚÏßÑéÖ¤·þÎñÖб£´æPDFÊðÃûαÔìÎó²î£¬ÕâЩÎó²î¿É±»Ê¹ÓÃÀ´¶ÔPDFÎĵµµÄÊý×ÖÊðÃû¾ÙÐÐδ¾ÊÚȨµÄ¸ü¸Ä£¬µ«²»»áʹÆäÎÞЧ¡£
´øÊý×ÖÊðÃûµÄPDFÎļþÔÚÆóÒµºÍÕþ¸®×éÖ¯Öб»×÷Ϊ¾ßÓÐÖ´·¨Ð§Ó¦µÄÕýʽÎļþÆÕ±éʹÓã¬ÆäÖУ¬Êý×ÖÊðÃûÊÇÇø·ÖÎļþÕæÊµÐÔµÄÖ÷Òª»·½Ú£¬ÊðÃûαÔìÎó²îÒ»µ©±»¶ñÒâʹÓã¬Ôò¿ÉÄܸøÆóÒµºÍÕþ¸®´øÀ´ÉÌÒµÉñÃØ»ò¾¼ÃÉϵÄËðʧ¡£
Ò×ÊÜÕâЩ¹¥»÷µÄÈí¼þÁбíÖаüÀ¨¶à¿î½ÏΪʢÐеÄPDFÎĵµÔĶÁÆ÷Èí¼þ£¬ÈçAdobe Reader£¬Foxit Reader£¬LibreOffice£¬Nitro Reader£¬PDF-XChangeºÍSoda PDFµÈ¡£ÓÐȱÏݵÄÑéÖ¤·þÎñ°üÀ¨DocuSign£¬eTRÑéÖ¤·þÎñ£¬DSSÑÝʾWebApp£¬EvotrustºÍVEP.siµÈ¡£
ÏÖÔÚ£¬ËùÓÐÌṩPDFÔĶÁÆ÷Ó¦ÓóÌÐòµÄ¹«Ë¾¶¼ÒÑÐû²¼Çå¾²²¹¶¡À´½â¾öÕâ¸öÎÊÌ⣬¶øÒ»Ð©ÔÚÏß·þÎñÉÐδ½â¾öÕâЩÎÊÌâ¡£
ѧÕßÉè¼ÆÁËÈýÖÖPDFÊðÃûÓÕÆ¹¥»÷ÊÖÒÕ£¬²¢»®·ÖÃüÃûΪͨÓÃÊðÃûαÔ죨USF£©£¬ÔöÁ¿ÉúÑĹ¥»÷£¨ISA£©ºÍÊðÃû°ü×°¹¥»÷£¨SWA£©¡£
ÔÚUSF£¨Universal Signature Forgery£©¹¥»÷ÖУ¬¹¥»÷Õß¿ÉÒÔʹÓÃÊðÃûÖеÄÔªÐÅÏ¢£¬ÕâÑùPDFÔĶÁÆ÷ÔÚÑéÖ¤ÊðÃûʱ¾ÍÎÞ·¨»á¼ûÑéÖ¤ËùÐèµÄÊý¾Ý£¬È´Ê¼ÖÕÒÔΪÊðÃûÓÐÓã¬ÀýÈçAcrobat Reader DCºÍReader XI¡£
ISA£¨Incremental Saving Attack£©¹¥»÷ʹÓÃPDF¹æ·¶ÖеÄÕýµ±¹¦Ð§£¬ÔÊÐíͨ¹ý¸½¼Ó¸ü¸ÄÀ´¸üÐÂÎļþ£¬ÀýÈçÉúÑÄ×¢ÊÍ»òÏòÎĵµÌí¼ÓÐÂÒ³Ãæ¡£¸Ã¹¥»÷¼Æ»®Í¨¹ý¸ü¸Ä²»ÊôÓÚÊðÃûÍêÕûÐÔ±£»¤µÄÔªÏòÀ´ÐÞ¸ÄÎĵµ¡£
SWA£¨Signature Wrapping Attack£©¹¥»÷Ç¿ÖÆÊðÃûÑéÖ¤Âß¼ÆÊÎöÓëÔʼÎĵµ²î±ðµÄÎĵµ²¿·Ö¡£ÕâÊÇͨ¹ý¡°½«ÔʼÊðÃûµÄÄÚÈÝÖØÐ¶¨Î»µ½ÎĵµÖеIJî±ðλÖò¢ÔÚ·ÖÅɵÄλÖòåÈëÐÂÄÚÈÝÀ´Íê³ÉµÄ¡£¡±SWA Ó°ÏìÁËÐí¶àPDFÔĶÁÆ÷ºÍһЩÔÚÏßÑéÖ¤·þÎñ¡£
ÐÞ¸´½¨Òé
¾¡¿ì¸üÐÂÊÂÇé×°±¸ËùʹÓõÄPDFÔĶÁÆ÷Ó¦ÓóÌÐòÖÁ¹Ù·½×îа档
²Î¿¼Á´½Ó
https://www.nds.ruhr-uni-bochum.de/media/ei/veroeffentlichungen/2019/02/12/report.pdf


¾©¹«Íø°²±¸11010802024551ºÅ