Advertisement
Promo

Security threats Toolkit

Adobe Reader JavaScript security flaw emerges

Elinor Mills CNET News

Published: 29 Apr 2009 08:53 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security experts are recommending that people disable JavaScript in Adobe Reader following reports of a vulnerability in the popular portable document format reader on Tuesday.

The vulnerability appears to be due to an error in the 'getAnnots()' JavaScript function and exploiting it could allow someone to remotely execute code on the machine, according to an advisory from the US-Cert.

"US-Cert encourages users and administrators to disable JavaScript in Adobe Reader to help mitigate the risk," the post said. "To disable JavaScript in Adobe Reader, open the General Preferences dialog box. From the Edit-Preferences-JavaScript menu, uncheck 'Enable Acrobat JavaScript'."

All currently supported shipping versions of Adobe Reader (8.1.4, 9.1 and 7.1.1 and earlier) are vulnerable and Windows, Macintosh and Unix platforms are affected, Adobe said in an advisory.

The company said it would release updates for all the platforms but did not yet have a timeframe for that. "We are currently not aware of any reports of exploits in the wild for this issue," the advisory said.

At the RSA security conference last week, F-Secure chief research officer Mikko Hypponen said internet users should switch to using an alternative PDF reader because of the security issues with Adobe Reader. A list of them is available on the PDFReaders.org website.

Of the targeted attacks so far this year, more than 47 percent exploit holes in Acrobat Reader, while six vulnerabilities have been discovered that target the program, he said.

Just last month, Adobe issued a fix for an Acrobat Reader hole that attackers had been exploiting for months, after issuing a patch for a critical vulnerability in Flash player the month before.

Credit: Another Adobe Reader security hole emerges from CNET News

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
7 out of 7 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

South Korea plans to fingerprint visit...

The South Korean authorities could fingerprint and photograph foreign visitors from 2012, the Korea Times reported on Tuesday. Barring diplomats and government operatives, all visitors... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters