main

Adobe admits PDF exploit, posts workaround

Daniel Fleshbourne   on 09 October 2007 - 09:31 · 7 comments & 4917 views

Advertisement (Why?)
Adobe Systems Inc. has confirmed that there's a critical bug in its most popular programs, but it doesn't yet have a patch that protects Windows XP users against attacks arriving as PDF files. In an advisory posted Friday, Adobe admitted that the flaw first disclosed by Petko Petkov, a U.K.-based security researcher, was real. The San Jose-based company also provided a multiple-step work-around in lieu of a permanent fix to its Adobe Acrobat software and its free Adobe Reader application.

Last month, Petkov claimed in a blog posting that he had found a critical vulnerability that could be leveraged using PDF files, Adobe's popular document format. "Adobe Acrobat/Reader PDF documents can be used to compromise your Windows box," Petkov said Sept. 21 "Completely!!! Invisibly and unwillingly!!! All it takes is to open a PDF document or stumble across a page [that] embeds one." At the time, Petkov declined to provide proof-of-concept code, telling users: "You have to take my word for it." He recommended steering clear of all PDFs until a fix was available.

View: The full story
News source: ComputerWorld

Post a comment · Send to friend Comments · There are 7 additional comments
#1 +Kushan on 09 Oct 2007 - 09:32
While they're at it, they should fix the stupidly slow loading times and bloatedness of the application.
*hugs foxit*
#2 cork1958 on 09 Oct 2007 - 10:21
There's an addon, or whatever you may want to call it, to make it load more quickly, which is pretty stupid, if you ask me.

Agree *hugs Foxit"
#3 El Sid on 09 Oct 2007 - 12:17
And on top of that, foxit is about a zillionth of the size of Adobe Reader! The magnitude of failure when a companys format reader gets spanked by a 3rd party reader for it's own format is beyond measurability!

*hugs Foxit*
#4 HawkMan on 09 Oct 2007 - 13:12
Foxit has problems with some PDF's though, causing them to e almost unreadable from aliasing.
#5 Croquant on 09 Oct 2007 - 15:05
Vulnerability only exists if you have IE7 installed. And I don't.
(1 reply) #6 night_stalker_z on 09 Oct 2007 - 18:33
If you guys use Foxit then why do you bother complaining?
#6.1 myrhymeandreason on 09 Oct 2007 - 18:40
Nott complaining, noticing how terrible applications are compared to 3rd party ones of the same type in many situations. A company like Adobe definitely has the ability, time, and funds to fix this issue; and a lot of times you see freeware options address security issues quicker.

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)