Feeds

Critical jailbreak hole plugged in Foxit Reader

Adobe Reader unaffected

Choosing a cloud hosting partner with confidence

The Foxit document reader has been updated to fix the same critical bug that currently leaves iPhones, iPads, and iPod touches wide open to malware attacks.

Foxit Reader version 4.1.1.0805 “fixes the crash issue caused by the new iPhone/iPad jailbreak program which can be exploited to inject arbitrary code into a system and execute it there,” Foxit officials said. They recommend that users install the update to protect themselves.

There are actually two underlying vulnerabilities involved in the Jailbreakme hack, and at time of writing they still made it possible to jailbreak iPhones, iPads, and iPod touches simply by visiting a site with one of the fully patched devices. While the hack isn't malicious, security watchers have warned that it's possible to exploit the same vulnerabilities to do much more nefarious things, such as install password-sniffing malware. Apple confirmed last week that a PDF reader built into iOS is vulnerable, and Foxit's advisory now makes clear their PDF reader is also susceptible.

Foxit suffered from only one of the vulnerabilities exploited by Jailbreakme.com. Interestingly, Adobe's senior director of product security and privacy Brad Arkin has said that Adobe Reader does not suffer from this vulnerability.

Adobe critics frequently hold up Foxit as an example of a PDF reader that's a safer alternative to Adobe Reader. We're not so sure. Without a doubt, it's less targeted by malicious hackers. But we're not aware of any data showing that's because there are fewer holes to exploit in the alternate reader. As the Jailbreakme bug shows, sometimes Adobe Reader is free of risks that confront its competitors. ®

This article was updated to make it clear there was only one vulnerability in Foxit.

Beginner's guide to SSL certificates

More from The Register

next story
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
FYI: OS X Yosemite's Spotlight tells Apple EVERYTHING you're looking for
It's on by default – didn't you read the small print?
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.