Advertisement
Promo

Security threats Toolkit

Adobe Acrobat security hole discovered

Will Knight ZDNet.co.uk

Published: 08 Aug 2000 10:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A security hole in Adobe Acrobat has been discovered that could allow malicious hackers to take over other computers, Adobe confirmed Monday.

Adobe has issued a patch for the vulnerability at its Web site and says that to its knowledge no users have been targeted using the exploit.

The security bug means that a specially created Acrobat PDF file could be used to crash Acrobat running on Windows and then run arbitrary code, potentially giving an outsider direct access to the machine.

Adobe was alerted to the problem by a security outfit called Shadow Penguin Security. Andrew Cormack, head of the Computer Emergency Response Team (Cert) within the Janet (Joint Academic Network) Security Department, says that the development is a concern just because of the popularity of exchanging PDF files using email.

"Potentially you could lose control of your machine and that's worrying," he says. "It is yet another way for people to trip themselves up."

Cormack believes, however, that the vulnerability may not immediately inspire a barrage of new viruses or Trojan horse programs disguised as regular PDFs, because it is considerably more difficult to write a PDF file than, for example, a Visual Basic program or a Macro.

Anti-virus vendors recommend that computer users download Adobe's bug fix in order to guarantee that they are not left vulnerable. This is the latest in a row of vulnerabilities that pose a threat to PC security.

Popular email application Microsoft Outlook was the subject of scrutiny last month when a similar bug was uncovered. This could allow a computer virus or similar malicious application to activate upon arrival at a user's computer.

Take me to the Virus Workshop

Take me to the Summer of Hacking Special

Take me to Hackers

What do you think? Tell the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
32 out of 95 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters