iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > Insider Reports > Insider > Adobe Reader Needs An Update
Search:
[ insider_reports_insider ]

Adobe Reader Needs An Update



David Utter
Staff Writer
2007-01-04

SecurityProNews: Insider Reports Insider Reports RSS Feed


Users of versions 6.x and 7.x of the Adobe Reader browser plug-in should go ahead and upgrade to version 8 to avoid a nasty little sanitization flaw.

Adobe Reader Needs An Update
Adobe Reader Needs An Update

Versions of the Adobe Reader used in conjunction with Internet Explorer and Firefox as plug-ins could pass code through to enable a cross-site scripting attack. The plug-in does not sanitize code passing through it, which could allow arbitrary code to be executed.

Secunia noted in its advisory about the issue that users could upgrade to version 8 of the Adobe Reader to avoid the problem.

Limited testing by CERT indicated the upgrade would work as recommended. CERT described the issue in its note about the problem:

The Adobe Acrobat Plug-In PDF Open Parameters feature allows users to specify actions to take on a PDF document via URI parameters. However, the Adobe Acrobat Plug-In fails to properly validate these URI parameters for scripting code. This allows user-supplied scripts to execute within the context of the web site hosting the PDF file causing a cross-site scripting vulnerability.

People who are unable to upgrade to the latest version of Adobe Reader do have workaround options available as listed in CERT's advisory. The ability to display PDF documents automatically in the browser can be disabled.

The usual cautions about not clicking on unfamiliar links from untrusted sources applies as usual. Our previous article on the serious threat from malicious JavaScript explains why that is a greater concern now.

---
Tag:

Add to Del.icio.us | Digg | Reddit | Furl

Get all the updates -





About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.

More insider_reports_insider Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds