main
Report a problem

Attack code targets unpatched Adobe Reader flaw

Daniel Fleshbourne   on 17 October 2007 - 12:26 · 10 comments & 6669 views

Advertisement (Why?)
A security researcher has published a proof-of-concept exploit for a known vulnerability in Adobe Reader. The researcher, known only as 'Cyanid-E', unveiled his creation in a posting to the Full Disclosure security mailing list on Tuesday.

The vulnerability has been confirmed on a fully patched Windows XP system running Adobe's Acrobat Reader 8.1 and Internet Explorer 7. Details about the vulnerability were published in late September on the GNU Citizen blog.

View: the full story
News source: vnunet

Post a comment · Send to friend Comments · There are 10 additional comments
(1 reply) #1 GreyWolfSC on 17 Oct 2007 - 14:03
Are they going to fix this or not? The "workaround" is a complicated RegEdit procedure that your average mom and pop aren't going to do.
#1.1 P1R4T3 on 17 Oct 2007 - 15:01
... unless the geek son install foxit on pop's pc and uninstall the adobe crap.
(1 reply) #2 hapbt on 17 Oct 2007 - 17:25
adobe sux
why is adobe reader like 20mb and foxit is like 2 yet they do the exact same thing
i bet foxit could patch any hole in their software in like a day
#2.1 RAID 0 on 17 Oct 2007 - 23:05
...because Adobe sucks a dong?
#3 IntelliMoo on 18 Oct 2007 - 04:31
Unfortately foxit doesn't work in HTML Help that hosts pdf.
(2 replies) #4 goatsniffer on 18 Oct 2007 - 05:45
LOLed @ Dong
#4.1 vetmarkjensen on 18 Oct 2007 - 06:32
These guys thought the word "dong" was funny, too...
http://neowin.files.googlepages.com/small-bnb.gif
#4.2 RAID 0 on 18 Oct 2007 - 16:32
Quote - (markjensen said @ #4.1)
These guys thought the word "dong" was funny, too...
http://neowin.files.googlepages.com/small-bnb.gif


Number one, I order you to take a number two.

yeah yeah eeh ehehehh
#5 PsiMoon314 on 18 Oct 2007 - 06:39
Hi,

The information in the Adobe "workaround" article is incorrect if you are using Windows XP, IE7 and Acrobat Reader 7 as the URL mentioned in the article does not exist for that version of AR.

The correct URL for AR7 is:
HKEY_LOCAL_MACHINESOFTWAREAdobeAcrobatReader7.0FeatureLockdowncDefaultLaunchURLPerms


Modify the relevant item in this key (from 0x32 to 0x33) to disable the mailto: functionality.

Kind Regards

Simon
#6 whocares78 on 18 Oct 2007 - 06:47
this new is like 2 weeks old

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)