NEWS /

Flaw Found in Adobe's Acrobat PDF Format

04 Jan, 2007, 12:14 pm IST | by AP |

Computer security researchers said Wednesday they have discovered a vulnerability in Adobe Systems Inc.'s ubiquitous Acrobat Reader software that allows cyber-intruders to attack personal computers through trusted Web links.


Virtually any Web site hosting Portable Document Format, or PDF, files are vulnerable to attack, according to researchers from Symantec Corp. and VeriSign Inc.'s iDefense Intelligence.

The attacks could range from stealing cookies that track a user's Web browsing history to the creation of harmful worms, the researchers said.

The flaw, first revealed at a hacker conference in Germany over the holidays, exists in a plug-in that enables Acrobat users to view PDF files within Web browsers.

By manipulating the Web links to those documents, hackers and online thieves are able to commandeer the Acrobat software and run malicious code when users attempt to open the files, according to Ken Dunham, director of the rapid response team at VeriSign's iDefense Intelligence.

Dunham gave this hypothetical scenario: an attacker finds a PDF file on a banking Web site. The attacker creates a hostile Web site that links to the bank's PDF file. Included is malicious JavaScript code that will run on the unsuspecting user's computer once the link is clicked.

''PDF is trusted and tried and true — everyone uses it,'' Dunham said. ''But instead of just viewing the file, you've initiated script that shouldn't be executed. All you have to do is click on the PDF and the ball starts rolling.''

Representatives from Adobe did not return a call from The Associated Press on Wednesday night.

The flaw appears to target Microsoft Corp.'s Internet Explorer 6.0 Web browser and earlier versions, and Mozilla's Firefox browser, the researchers said.

They recommended that users protect themselves by upgrading Internet Explorer or changing Firefox's user options so the browser does not use the Acrobat plug-in.

Researchers said it's unclear how pervasive or harmful any future attacks might be.

''Given that it is easy to exploit, I would expect that we will see this method used considerably in the coming days and weeks, until it is resolved,'' a Symantec researcher said in a posting on a company Web log.

Tags: Adobe , Acrobat , PDF , VeriSign

RELATED STORIES

Adobe Creative Cloud now available for purchase

Adobe Creative Cloud now available for purchase

Adobe Systems Incorporated has announced the immediate availability of Adobe Creative Suite 6 software.

Adobe releases new security update for Flash Player

Adobe updates Android Flash Player to 11.1, adds ICS support

Galaxy Nexus bug fix and Flash support coming this month

No Adobe Flash support for Android 4.0, yet

Adobe for Android gets an update

Adobe to get aggressive with HTML5, kill Flash for mobiles

Fotoshop by Adobé (Adobe)

10 Jan, 2012, 07:52 am IST

Fotoshop by Adobé (Adobe)

Adobe

23 Sep, 2010, 05:43 am IST

Adobe

Adobe Primetime Simulcast Demo.mp4

22 May, 2012, 09:32 am IST

Adobe Primetime Simulcast Demo.mp4

 

Leaked Images, Availability, Pricing,
Specs, Pre-order

Photos

High Court Order - Madras

High Court Order - Madras

17 May, 2012, 04:22 PM

2.3

Trials Evolution

Trials Evolution

12 May, 2012, 10:33 AM

Sniper Elite V2

Sniper Elite V2

09 May, 2012, 10:04 PM

3.3

MORE PHOTOS

OPINIONS

Padmini Harchandrai

The latest "should they-shouldn't they" event with Facebook is the lift of the minimu...

MORE OPINIONS

features

Portable Wi-Fi Drives for your smartphone

Portable Wi-Fi Drives for your smartphone

Fed up of the limited storage on your mobile device? Here are some devices

By Aaron Almeida

Top 5 potential Gmail alternatives

Top 5 potential Gmail alternatives

Google’s Gmail service is arguably the most advanced and feature-packed...

By Naina Khedekar

Five ways to beat the petrol hike

Five ways to beat the petrol hike

Petrol prices went up by a considerable amount post Wednesday, and this...

By Karan Shah

MORE FEATURES

On video: HTC One V

On video: HTC One V

18 May, 2012, 04:44 AM

4.5

On video: Cowon Z2 (16GB)

On video: Cowon Z2 (16GB)

15 May, 2012, 04:58 PM

2.3

On video: Samsung WB150F

On video: Samsung WB150F

08 May, 2012, 04:23 AM

5.0

MORE VIDEOS

776 views

1129 views

630 views

MORE WALLPAPERS