YOUR IT - Technology for you

No. 1 Story

Telstra adds one million mobile services, but Sensis plummets

Telstra has revealed the addition of almost one million new mobile services in the six months to December 2011, but Sensis revenues plummeted 24 percent in 12 months.

read more

Researcher reveals Reader flaw

Your IT - Home IT

A security researcher has revealed a vulnerability in recent versions of Adobe Reader for Windows that can be exploited to take control of a computer.

According to Petko Petkov, "All it takes is to open a PDF document or stumble across a page which embeds one."

"The issues was verified on Windows XP SP2 with the latest Adobe Reader 8.1, although previous versions [including 7 and 8.0] are also affected," he added. "Windows Vista users are not affected." It is possible that other programs used to display PDF files are open to similar exploits.

Petkov has not released his proof of concept, citing the widespread use of PDF files and the possibility that "it may take a while for Adobe to fix their closed source product". While some see this as responsible behaviour, other people have criticised him for failing to suggest any mitigation beyond 'don't open any PDFs' or to give sufficient information to allow verification by other researchers.

However, Petkov asserts that the bug has been confirmed by "several friends and well known security researchers".

Adobe is known to be aware of the issue, but has yet to issue an update or even an advisory about the problem.

The recent QuickTime/Firefox vulnerability was also found by Petkov.

Loading comments ...

- sponsored feature -

The Death of Traditional BI: What’s Next?

How to Make Business Discovery Work for Your Business IP PABX BUYING GUIDE

Business Discovery takes its cues from consumer apps. Like Google, it encourages us- ers to hunt for and explore data without worrying about or even noticing the underly- ing technology. Their entire experience is working within an intuitive interface to get real-time, self-service results with only minimal training. ...more