Adobe eBook Reader 2.2 - File Restoration Privilege Escalation

EDB-ID:

21629




Platform:

Windows

Date:

2002-07-19


source: https://www.securityfocus.com/bid/5273/info

Adobe eBook Reader is a client side application which is able to view Adobe eBooks, available for Microsoft Windows and Macintosh OS 9. eBooks are electronic books which provide some protection for content. Users may be able to view a book, but have limited publisher defined privileges to copy content.

It is possible to bypass some quota restrictions. Non-zero quotas on copying and printing content may be bypassed by repeatedly restoring certain files used to maintain state from backups.

This vulnerability has been reported in versions of eBook Reader for Microsoft Windows. It may, however, exist on other platforms.

Data\Vouchers\*.*
Data\GB.dbd
Data\Category.etb
Data\Library*.etb
Data\Library*.vld