Adobe Reader Patch Fixes Remote-Control Vulnerability
November 5th, 2008
Adobe Systems has released a security
fix to address eight major vulnerabilities in version 8.12 of its free Adobe Reader application. The flaw was first reported to Adobe five months ago.Core Security Technologies on Tuesday issued an advisory disclosing the vulnerability, which could affect millions of individuals and businesses that use the popular PDF file-viewing software. Specifically, CoreLabs engineers discovered attackers could exploit Adobe Reader to gain access to vulnerable systems by using a specially crafted PDF file with malicious JavaScript content.
“As with many of today’s ubiquitous client-side applications, the sheer complexity of Adobe Reader creates a broad surface for potential vulnerabilities and, in this case, Adobe’s inclusion of a fully fledged JavaScript engine introduces the same types of implementation bugs commonly found in such sophisticated client-side programs,” said Ivan Arce, Core’s CTO.
Click here to read the rest of my story on NewsFactor.
Entry Filed under: Hot off the Press






Leave a Comment
Some HTML allowed:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>
Trackback this post | Subscribe to the comments via RSS Feed