Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

Adobe Issues Patch for Critical Reader Flaw

Critical vulnerability could be used to exploit JavaScript engine in popular Reader application

Nov 04, 2008 | 03:35 PM

By Kelly Jackson Higgins
DarkReading

Adobe today fixed a major security hole in Adobe Reader that lets an attacker take control of a user's machine when he or she opens or downloads a PDF file.

The overflow vulnerability exploits JavaScript features in Adobe Reader 8.1 and earlier versions. This isn't the first such critical bug found in Reader, says Ivan Arce, CTO of Core Security Technologies, which discovered the flaw, but it's a major one.

"JavaScript content may trigger the vulnerability and let an attacker control the system," Arce says.

Core researchers discovered the vulnerability while studying another similar flaw in a different PDF view application, Foxit Reader. Arce says the bug demonstrates just how multiple vendors can have similar flaws in their applications. Core reported its finding to Adobe in May after discovering the vulnerability.

Aside from the patch, Reader users can either disable JavaScript in the application or upgrade to the newest version of Reader, Version 9, which does not contain the vulnerability, Arce notes.


Subscribe to RSS










Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:suse linux
Published:2010-01-22
Severity:High
Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
Vulnerability:bind
Published:2010-01-22
Severity:Medium
Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)