Content Management - PDFzone
PDFZone Ziff-Davis Enterprise
Authoring | Utilities | Content Management | Document Management | Mobile | DRM | Other Formats | Tips
Home arrow Content Management arrow Adobe Issues Fix for Reader, Acrobat Flaw
Adobe Issues Fix for Reader, Acrobat Flaw
By Ryan Naraine

Rate This Article:
Add This Article To:
Adobe quietly releases versions 7.0.1 of its freely distributed programs to patch a local file detection vulnerability.

Users of the ubiquitous Adobe Reader and Adobe Acrobat programs are at risk of a local file detection flaw, according to an alert from a private security research outfit.

Adobe Systems Inc. earlier this month sneaked out a fix for the vulnerability and recommended that users upgrade to versions 7.0.1 of the freely available programs.

ADVERTISEMENT

Hyperdose Security, the company credited with finding and reporting the bug, said an attacker could target the "Safe for Scripting" method in the Adobe programs to direct unsuspecting users to a malicious Web site.

Once the user lands on the malicious site, the attacker can use the "LoadFile" method to send a local file name on the victim's computer. Using this method, the attacker is able to determine file existence on their victim's machine, said Robert Fly, a researcher at Hyperdose Security.

Although the risk is considered low, Fly said the attack would be useful as a stepping stone to further attacks. "Knowing the existence of a local file an attacker can gain knowledge as to the software and likely versions of software the individual is using," he said.

In an advisory confirming Fly's findings, Adobe said the bug affects users running Microsoft Corp.'s Internet Explorer on Windows. "One of the methods exposed by ActiveX in Internet Explorer can be used to trigger a flaw in the Adobe browser control. An attacker would be able to determine what specifically queried files exist on the user's system, although the contents of the file are not accessible," the company said.

However, Adobe said that the impact is minimized due to the fact that the existence of local files can only be discovered if the complete file names and paths are known in advance by the attacker and the recipient is running Internet Explorer.




Discuss Adobe Issues Fix for Reader, Acrobat Flaw
 
>>> Be the FIRST to comment on this article!
 

 
 
>>> More Content Management Articles          >>> More By Ryan Naraine
 



FREE ZIFF DAVIS ENTERPRISE ESEMINARS AT ESEMINARSLIVE.COM
  • Dec 5, 2 p.m. ET
    Case Studies in MSP Profitability: 10 Processes to Automate to Achieve 2008 Goals
    with Michael Krieger. Sponsored by Autotask
  • Dec 6, 12:30 p.m. ET
    The State of the Great Windows Vista Migration
    with Aaron Goldberg. Sponsored by Dell & Microsoft
  • Dec 6, 2 p.m. ET
    Three Best Practices for Securing Microsoft Exchange
    with Michael Krieger. Sponsored by Entrust
  • Dec 6, 3 p.m. ET
    Simplify Your World, part 2: A Virtual Desktops Case Study
    with Joel Shore. Sponsored by EqualLogic
  • 12-19 VTS LOGO for BotMod
    Join us on Dec. 19 for Discovering Value in Stored Data & Reducing Business Risk. Join this interactive day-long event to learn how your enterprise can cost-effectively manage stored data while keeping it secure, compliant and accessible. Disorganized storage can prevent your enterprise from extracting the maximum value from information assets. Learn how to organize enterprise data so vital information assets can help your business thrive. Explore policies, strategies and tactics from creation through deletion. Attend live or on-demand with complimentary registration!
    FEATURED CONTENT

    Sponsored by Ziff Davis Enterprise Group


    DOWNLOADABLE ROI CALCULATORS & TOOLS FROM BASELINE
      Calculate Cost and ROI of Spam, VOIP, RFID, Sarbanes-Oxley and more...


    Featured Calculators:

     



    See More Tools!
    By Category| Planners |Calculators | Quizzes

     

    Special Report


    PDFzone Special Report: Making the Perfect PDF
    The Perfect PDF
    PDFzone shows you how to shine and polish your PDF by adding the reader-friendly touches your audience desires.

    Special Report


    PDFzone Special Report: Microsoft's PDF Play
    Microsoft's PDF Play
    Microsoft planned to offer a "Save to PDF" function in Office 2007, but the threat of legal action from Adobe may have them reconsidering.

    Special Report


    PDF conversion
    PDF Conversion Central
    Convert anything and everything to PDf and back again. Word docs, RSS, AutoCAD and more.
    ADVERTISEMENT