Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 04-01-2007, 05:48 PM   #1 (permalink)
a_g = JPKN
 
s18000rpm's Avatar
 
Join Date: Mar 2006
Posts: 5,170
Exclamation Adobe Reader Flaw -Uncovered by Researchers


Security researchers have discovered a cross-site scripting (XSS) vulnerability affecting the widely used Adobe Acrobat Reader software that could make it easy for attackers to launch malicious code.

The flaw, revealed by security researchers Stefano Di Paola and Giorgio Fedon last week at the Chaos Communications Congress hacker convention in Berlin, could allow attackers to manipulate the Adobe Reader browser plug-in to execute arbitrary JavaScript on the client side simply by adding code to the URL of an online PDF file and getting users to click on the link.

The XSS vulnerability is made possible by the Open Parameters feature in Adobe Reader, which makes it possible to open a PDF file using a URL and specify which content to show and how to display it.

In a Wednesday advisory sent to its Deepsight threat management customers, Symantec warned that because Open Parameters exists in most Adobe Reader applications and browser plug-ins, the flaw could lead to a wave of XSS attacks against client-side targets.

"We may be seeing one of the first significant developments where cross-site scripting attacks are delivered to the client side with extremely high target-to-compromise ratios," according to the Deepsight advisory.

Attackers also could leverage the XSS vulnerability to steal cookie-based authentication credentials and launch additional attacks, Symantec noted.

The flaw is easy to exploit because attackers don't need write access to a PDF document and can add malicious JavaScript to any PDF file link found online, according to a post on the SANS Internet Storm Center blog.

Adobe Systems couldn't be reached for comment.

The vulnerability affects Adobe Reader version 6.0.1 for Windows using Internet Explorer 6 and version 7.0.8 for Windows using Firefox 2.0.0.1, but Adobe has fixed the problem in version 8 of the Reader software.

Security firm Secunia, which recommended upgrading to Adobe Reader 8.0 to fix the problem, didn't see the threat as serious, giving it a rating of "less critical," or 2 on a 5-point scale. Symantec Deepsight rated the severity of the flaw as 6.1 on a 10-point scale.

Source: CRN NEWS
__________________
★-----------�-----------★
ASUS K53SV SX520D + BF3
★-----------�-----------★
s18000rpm is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 04-01-2007, 06:21 PM   #2 (permalink)
gooby pls
 
Third Eye's Avatar
 
Join Date: Apr 2006
Location: Not very far from you
Posts: 4,293
Default Re: Adobe Reader Flaw -Uncovered by Researchers

Thanks for the info.......
__________________
:|
Third Eye is offline  
Old 05-01-2007, 01:35 PM   #3 (permalink)
Wandering in time...
 
Ankur Gupta's Avatar
 
Join Date: Nov 2004
Location: Delhi,India
Posts: 1,293
Default Re: Adobe Reader Flaw -Uncovered by Researchers

Yeah read that news in the newspapers today..
thanx for the details..
__________________
Integrate Yourself With The Latest Happenings.....
www.ankur-gupta.com/blog
Ankur Gupta is offline  
Old 05-01-2007, 02:18 PM   #4 (permalink)
OSS Enthusiast!
 
nitish_mythology's Avatar
 
Join Date: Sep 2005
Location: Hills of Kumaoun
Posts: 664
Default Re: Adobe Reader Flaw -Uncovered by Researchers

Newspaper discussing Adobe flaw!
May I know the name?
__________________
Do you know, Shinigamis only eat apples???
nitish_mythology is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by Tenida
- by clinton
- by Anorion
- by Niilesh

Advertisement




All times are GMT +5.5. The time now is 03:04 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2