Feeds

Security researchers fret over Adobe PDF flaw

Double danger

Top three mobile application threats

Adobe has warned that its Reader and Acrobat PDF software is vulnerable to an unpatched vulnerability.

A pair of flaws in the JavaScript functions of the PDF reading application are behind the problem, prompting Adobe to advise surfers to disable JavaScript as a workaround, pending the availability of a patch. Even after a patch becomes available, the problem may hang around for months. The vulnerability is a cross-platform flaw that affects Windows, Macs and Linux machines running Adobe's software.

The two security vulnerabilities in Adobe's software are particularly nasty, because they lend themselves to the planting of malicious code on vulnerable PCs. The flaws therefore potentially lend themselves to drive-by download attacks. There's no evidence of this happening as yet, even though proof of concept attack code has been developed.

Analysis on the response to the last such vulnerability from Adobe by security scanning firm Qualys, which dates back to February, shows that users were very slow at applying patches. Applying application security updates, as distinct from operating system patches, is becoming the most pressing problem in patching, according to Wolfgang Kandek, CTO at Qualys.

Security firms, such as Sophos and F-Secure (here), both advise surfers to consider the use of alternative PDF reader packages (list here), as a way of moving away from a monoculture of PDF readers, which is bad security practise. ®

Combat fraud and increase customer satisfaction

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.