User: Pass: Forget password? / Register New User 
Current issue Current issue | Forum and Community Forum & Community | Onekit's Software OneKit's Software | Submit software (submit PAD file) Submit software
home | links | about / contact us
Games Graphics & Design MP3 & Audio Internet & Networks System & Utilities Home & Education Business WebDev SoftDev
Reviews & Articles :: Adobe To Issue Patches for Reader Vulnerability
Issue: January 2007 > System & Utilities > Article "Adobe To Issue Patches for Reader Vulnerability"

Adobe To Issue Patches for Reader Vulnerability (Adobe To Issue Patches for Reader Vulnerability)  Adobe To Issue Patches for Reader Vulnerability

System & Utilities
Advertisement on Onekit.com Software Magazine
Adobe encourages upgrading to Reader 8 and recommends disabling Acrobat and Reader plug-ins on Web browsers until patches are issued.

Adobe will issue patches next week for older versions of its Reader and Acrobat Reader software, which contain a dangerous vulnerability that could be used for phishing attacks or to remotely access files on a computer.

The problem affects versions 7.0.8 and earlier of the Acrobat and Reader programs. Adobe is telling users of those versions to disable the Acrobat and Reader plug-in in their Web browser until the patches are issued.

Since the problem became public, Adobe has also been encouraging customers to upgrade to Reader 8, the latest version of its program, which is not affected by the vulnerability.

Some users can't upgrade to the new version, however, so Adobe will issue the patches for those users next week, Meredith Mills, an Adobe spokeswoman, said via email.


PDFs Contain Phishing Attacks

Security experts warned that the cross-site scripting vulnerability could let an attacker run arbitrary JavaScript code on a targeted machine by linking to a PDF file on the machine.

In a phishing attack, for example, a hacker could add JavaScript to a URL (uniform resource locator) that links to a PDF document on a site. If the link is opened, the JavaScript would run, inserting a form soliciting the user's password at a banking site, with the information transferred back to the hacker.

Adobe is also warning users to exercise caution when clicking on untrusted links, since those links could be manipulated to run an exploit.

Security vendor Websense wrote on Thursday that an attacker could also gain access to files on a machine.

Exploits will apparently only work with certain combinations of Web browsers and Adobe software, but Adobe did not specify which combinations.

Symantec wrote in its blog that the vulnerability affects the Firefox Web browser. Further tests showed that users running a combination of Internet Explorer (IE) 6 and Adobe Reader 7 on Windows XP Service Pack 1, and Internet Explorer 6 and Adobe Reader 4 on Windows XP Service Pack 2, are also vulnerable, Symantec wrote.



Related Links:
January 7, 2007
Author: Jeremy Kirk
There are no users' comments | Post your comment
Copyright 2003-2008 - Software Magazine, onekit.com, Legal Notices

You can help improve OneKIT and boomerang will come back.
Advertisement Advertisement
Sponsored links: Shareware downloads | Hard Drive Recovery | Firevector