Adobe patches Reader flaw
PDF flaw affects affect older, infirm package
Posted in Anti-Virus, 4th November 2008 13:58 GMT
Free whitepaper – Securing your Microsoft Internet Information Services (MS IIS) web server
Security watchers are warning of a critical flaw affecting older versions of Adobe Reader.
Hackers might be able to exploit the bug using specially crafted pdf files with JavaScript content, Core Security warns. Ivan Arce, CTO at Core Security, said the security bug was discovered while investigating a previously disclosed problem in Foxit, an alternative pdf viewer package.
Successful exploitation against the Adobe Reader flaw would involve tricking users into opening a laced pdf file. The flaw only affects users of Adobe Reader 8, which was replaced by Adobe Reader 9 in June 2008. Nonetheless Core argues that many users are still running older versions of the software and are therefore at risk of attack.
Adobe has issued a security patch to fix the flaw, which affects versions 8.1.2 and below of Adobe Reader. If applying the update isn't immediately possible then disabling Javascript functionality should suffice as a workaround. ®
Free whitepaper – Avoiding 7 common mistakes of IT security compliance


Airport insecurity: the case of lost laptops
Reducing messaging and web security costs with managed services
Avoiding 7 common mistakes of IT security compliance
Extended Validation SSL Certificates
Feds: Hospital hacker's 'massive' DDoS averted
Microsoft knew of nasty IE bug a year before attacks
BlockMaster SafeStick hardware-encrypted USB drive