PdfÔĶÁÆ÷Êý×ÖÊðÃûαÔì·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-03-01

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


ÊÜÓ°ÏìÈí¼þÒÔ¼°°æ±¾£º 


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



·ì϶¸ÅÊö


µÂ¹ú²¨ºè³¶û´óѧµÄѧÕß×êÑз¢ÏÖ £¬ÔÚ22¸öPDFÔĶÁÆ÷ÀûÓ÷¨Ê½ºÍ7¸öÔÚÏßÑéÖ¤·þÎñÖдæÔÚPDFÊðÃûαÔì·ì϶ £¬ÕâЩ·ì϶¿É±»ÀûÓÃÀ´¶ÔPDFÎĵµµÄÊý×ÖÊðÃû½øÐÐδ¾­ÊÚȨµÄ¸ü¸Ä £¬µ«²»»áʹÆäÎÞЧ¡£


´øÊý×ÖÊðÃûµÄPDFÎļþÔÚÆóÒµºÍµ±¾Ö×éÖ¯Öб»×÷ΪӵÓÐ˾·¨Ð§Ó¦µÄÕýʽÎļþ¿í·ºÊ¹Óà £¬ÆäÖÐ £¬Êý×ÖÊðÃûÊÇ·Ö±æÎļþÕæÊµÐԵijÁÒª»·½Ú £¬ÊðÃûαÔì·ì϶һµ©±»¶ñÒâÀûÓà £¬Ôò¿ÉÄܸøÆóÒµºÍµ±¾Ö´øÀ´Ã³Ò×»úÃÜ»ò¾­¼ÃÉϵÄËðʧ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ò×ÊÜÕâЩ¹¥»÷µÄÈí¼þÁбíÖÐÔ̺¬¶à¿î½ÏΪʢÐеÄPDFÎĵµÔĶÁÆ÷Èí¼þ £¬ÈçAdobe Reader £¬Foxit Reader £¬LibreOffice £¬Nitro Reader £¬PDF-XChangeºÍSoda PDFµÈ¡£³öȱµãµÄÑéÖ¤·þÎñÔ̺¬DocuSign £¬eTRÑéÖ¤·þÎñ £¬DSSÑÝʾWebApp £¬EvotrustºÍVEP.siµÈ¡£


Ŀǰ £¬ËùÓÐÌṩPDFÔĶÁÆ÷ÀûÓ÷¨Ê½µÄ¹«Ë¾¶¼ÒѰ䲼°²È«²¹¶¡À´½â¾öÕâ¸öÎÊÌâ £¬¶øÒ»Ð©ÔÚÏß·þÎñÉÐδ½â¾öÕâЩÎÊÌâ¡£


ѧÕßÉè¼ÆÁËÈýÖÖPDFÊðÃûºýŪ¹¥»÷¼¼Êõ £¬²¢±ðÀ붨ÃûΪͨÓÃÊðÃûαÔ죨USF£© £¬ÔöÁ¿±£Áô¹¥»÷£¨ISA£©ºÍÊðÃû°ü×°¹¥»÷£¨SWA£©¡£


ÔÚUSF£¨Universal Signature Forgery£©¹¥»÷ÖÐ £¬¹¥»÷ÕßÄܹ»°Ñ³ÖÊðÃûÖеÄÔªÐÅÏ¢ £¬ÕâÑùPDFÔĶÁÆ÷ÔÚÑéÖ¤ÊðÃûʱ¾ÍÎÞ·¨½Ó¼ûÑéÖ¤ËùÐèµÄÊý¾Ý £¬È´Ê¼ÖÕÒÔΪÊðÃûÓÐЧ £¬ÀýÈçAcrobat Reader DCºÍReader XI¡£


ISA£¨Incremental Saving Attack£©¹¥»÷ÀûÓÃPDF¹æ·¶ÖеĺϷ¨Ö°ÄÜ £¬ÔÊÐíͨ¹ý¸½¼Ó¸ü¸ÄÀ´¸üÐÂÎļþ £¬ÀýÈç±£Áô×¢½â»òÏòÎĵµÔö³¤ÐÂÒ³Ãæ¡£¸Ã¹¥»÷¹æ»®Í¨¹ý¸ü¸Ä²»ÊôÓÚÊðÃûÆëÈ«ÐÔ±£»¤µÄÔªËØÀ´Åú¸ÄÎĵµ¡£


SWA£¨Signature Wrapping Attack£©¹¥»÷Ç¿ÔìÊðÃûÑéÖ¤Âß¼­·ÖÎöÓëԭʼÎĵµ·ÖÆçµÄÎĵµ²¿ÃÅ¡£ÕâÊÇͨ¹ý¡°½«Ô­Ê¼ÊðÃûµÄÄÚÈݳÁж¨Î»µ½ÎĵµÖÐµÄ·ÖÆçµØÎ»²¢ÔÚ·ÖÅäµÄµØÎ»²åÈëÐÂÄÚÈÝÀ´ÊµÏֵġ£¡±SWA Ó°ÏìÁ˺ܶàPDFÔĶÁÆ÷ºÍһЩÔÚÏßÑéÖ¤·þÎñ¡£


½¨¸´½¨Òé


¾¡¿ì¸üй¤×÷É豸ËùʹÓõÄPDFÔĶÁÆ÷ÀûÓ÷¨Ê½ÖÁ¹Ù·½×îаæ¡£


²Î¿¼Á´½Ó


https://www.nds.ruhr-uni-bochum.de/media/ei/veroeffentlichungen/2019/02/12/report.pdf