Researcher reveals Reader flaw E-mail
by Stephen Withers   
Monday, 24 September 2007
A security researcher has revealed a vulnerability in recent versions of Adobe Reader for Windows that can be exploited to take control of a computer.

According to Petko Petkov, "All it takes is to open a PDF document or stumble across a page which embeds one."

"The issues was verified on Windows XP SP2 with the latest Adobe Reader 8.1, although previous versions [including 7 and 8.0] are also affected," he added. "Windows Vista users are not affected." It is possible that other programs used to display PDF files are open to similar exploits.

Petkov has not released his proof of concept, citing the widespread use of PDF files and the possibility that "it may take a while for Adobe to fix their closed source product". While some see this as responsible behaviour, other people have criticised him for failing to suggest any mitigation beyond 'don't open any PDFs' or to give sufficient information to allow verification by other researchers.

However, Petkov asserts that the bug has been confirmed by "several friends and well known security researchers".

Adobe is known to be aware of the issue, but has yet to issue an update or even an advisory about the problem.

The recent QuickTime/Firefox vulnerability was also found by Petkov.

Powered By Joomla Tags

Please enable JavaScript in your browser to post your comment!

 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
694,279
Subscribers 15,210
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff

- Advertisement -

Featured Whitepapers

Follow iTWire on Twitter

About iTWire

iTWire is all about technology news, information, jobs and community for the IT and telecommunications industry professional. Subscribe to our free ICT daily newsletter