Technology news and Jobs
Information Technology News
Researcher reveals Reader flaw
Information Technology News
Researcher reveals Reader flaw | Researcher reveals Reader flaw |
|
| by Stephen Withers | |
| Monday, 24 September 2007 | |
A security researcher has revealed a vulnerability in recent versions of Adobe Reader for Windows that can be exploited to take control of a computer.Featured Whitepaper
5 Best Practices for Smartphone Support
"The issues was verified on Windows XP SP2 with the latest Adobe Reader 8.1, although previous versions [including 7 and 8.0] are also affected," he added. "Windows Vista users are not affected." It is possible that other programs used to display PDF files are open to similar exploits. Petkov has not released his proof of concept, citing the widespread use of PDF files and the possibility that "it may take a while for Adobe to fix their closed source product". While some see this as responsible behaviour, other people have criticised him for failing to suggest any mitigation beyond 'don't open any PDFs' or to give sufficient information to allow verification by other researchers. However, Petkov asserts that the bug has been confirmed by "several friends and well known security researchers". Adobe is known to be aware of the issue, but has yet to issue an update or even an advisory about the problem. The recent QuickTime/Firefox vulnerability was also found by Petkov. |
| < Next story in category | Previous story in the category > |
|---|





Tags





