http://www.pcworld.com/article/159895/adob...tml?tk=rss_news
Read complete article in link above.
Adobe Flaw Heightens Risk of Encountering Malicious PDFs
Jeremy Kirk, IDG News Service
...The flaw affects version 9 of Reader and Acrobat as well as earlier versions, according to Adobe's advisory. A buffer overflow condition can be triggered by opening a specially-crafted PDF, which gives the attackers control of the computer. Shadowserver wrote that the flaw could be exploited on systems running Microsoft's Windows XP SP3.
Adobe called the flaw "critical," it's most severe rating, and said it will release a patch for Reader 9 and Acrobat 9 by March 11. The company said patches for version 8 of Reader and Acrobat will follow, then finally for version 7 of Reader and Acrobat.....
...There are a couple of defenses PC users can employ until the patch arrives. Users should not open PDFs from untrusted sources, Symantec said. Also, since the attack relies on JavaScript, users can disable that function in Acrobat and Reader, Shadowserver advised....
To disable JavaScript in Adobe Reader:
Open Adobe Reader
Click on Edit
Click on Preferences
Click on Java Script in Sidebar
Uncheck "Enable Acrobat Java Script"
Click OK
Read complete article in link above.
Adobe Flaw Heightens Risk of Encountering Malicious PDFs
Jeremy Kirk, IDG News Service
...The flaw affects version 9 of Reader and Acrobat as well as earlier versions, according to Adobe's advisory. A buffer overflow condition can be triggered by opening a specially-crafted PDF, which gives the attackers control of the computer. Shadowserver wrote that the flaw could be exploited on systems running Microsoft's Windows XP SP3.
Adobe called the flaw "critical," it's most severe rating, and said it will release a patch for Reader 9 and Acrobat 9 by March 11. The company said patches for version 8 of Reader and Acrobat will follow, then finally for version 7 of Reader and Acrobat.....
...There are a couple of defenses PC users can employ until the patch arrives. Users should not open PDFs from untrusted sources, Symantec said. Also, since the attack relies on JavaScript, users can disable that function in Acrobat and Reader, Shadowserver advised....
To disable JavaScript in Adobe Reader:
Open Adobe Reader
Click on Edit
Click on Preferences
Click on Java Script in Sidebar
Uncheck "Enable Acrobat Java Script"
Click OK
This post has been edited by buddy215: 20 February 2009 - 10:59 AM

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Back to top










