If geeks love it, we’re on it

PDF exploit not yet patched

PDF exploit not yet patched

Windows users are susceptible to an exploit that can arrive by opening a PDF file or viewing a webpage with a PDF embedded.

In an advisory posted Friday, Adobe admitted that the flaw first disclosed by Petko Petkov, a U.K.-based security researcher, was real. The San Jose-based company also provided a multiple-step work-around in lieu of a permanent fix to its Adobe Acrobat software and its free Adobe Reader application.

Petkov wouldn’t publicly release details, but recommends steering clear of public PDFs until it’s patched.

Comments

  1. GHoosdum
    GHoosdum Is this an Adobe-specific exploit, or will it exhibit in all PDF readers? I use FoxIt at home.
  2. Linc
    Linc
    GHoosdum wrote:
    Is this an Adobe-specific exploit, or will it exhibit in all PDF readers? I use FoxIt at home.
    It isn't clear from the article, but I would assume it's likely FoxIt would have the same vulnerability.

    Should also note this only pertains to XP users with IE7.
  3. Zuntar
    Zuntar Good, I don't use IE7.:p
  4. GHoosdum
  5. Linc
    Linc I don't think it's required that you actually use IE7, only that it is installed. The exploit is with how the protocol for a mailto: link in a PDF is handled (note that you don't have to click it, only open it).
  6. GHoosdum
    GHoosdum The article makes it seem like the burden lies with Adobe to fix this exploit, but it seems to me that logically it would require a patch to IE7 to solve it for all PDF readers, particularly since it doesn't occur when any other browser is installed.
  7. Linc
    Linc Adobe maintains/owns the PDF technical standard, so I think, logically, the responsibility does lie with them to fix an exploit in it... but I may not fully understand. The article doesn't clear up a lot of things.

Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!