Check Point Reference: | CPAI-2015-0060 |
Date Published: | 19 Jan 2015 |
Severity: | High |
Last Updated: | Wednesday 21 January, 2015 |
Source: | |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | PDF Readers |
Vulnerability Description | PDF files are susceptible to various remote code execution vulnerabilities. Although various security products provide coverage against many such vulnerabilities, attackers could potentially bypass security products inspection by using PDF files that contain a suspicious File Info Fields. |
This protection will detect and block PDF containing suspicious File Info Fields.
In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, click on Protection tab and select the version of your choice.
This protection's log will contain the following information:
Attack Name: Adobe Products Violation.
Attack Information: PDF Containing Suspicious File Info Fields