Adobe Issues Patch for PDF-related Vulnerability

By Scott M. Fulton, III | Published October 22, 2007, 4:01 PM

It ended up not being Adobe's problem to begin with anyway: a vulnerability that enabled JavaScript code within a specifically crafted URL to run unchecked, and launch any executable code. When Petko D. Petkov of GNUCitizen.org discovered the problem, it appeared to have been directly triggered by Adobe Acrobat or Adobe Reader.

As it turned out, Windows XP and Internet Explorer 7 have a little difficulty with parsing filenames that contain percent signs (%). A maliciously crafted URL that points to a PDF file can have XP launch executable code after it launches the reader for the PDF file. While it wasn't Acrobat or Reader that triggered the launch, a fix from Adobe issued today purports to thwart the launch, keeping the system secure.

BetaNews downloaded and tested Adobe's 8.1.1 patch for Acrobat Professional, with a proof-of-concept URL that we had seen previously load the Windows Calculator as proof it could launch any code without security checks. Now the application instead pulls up a dialog box, which reads, "Acrobat does not allow connection to: mailto:test%../../../../../../../../windows/system32/calc.exe".cmd"

Today's updates work with version 8 of the reader software. In its advisory to users today, Adobe said a future update will be made available for version 7.

Comments

View comments by with a score of at least

at the risk of sounding like an ms hateboy, so it was MS fault after all.

Score: 0

|

'A pivot from war to peace:' The AMD + Intel armistice, in their own words

An extraordinary day in technology history is recognized by two long-time rivals that mutually decided it's futile to fight anyplace else except the marketplace.

PS3, Xbox to soon get Twitter, Facebook integration

Both Microsoft's Xbox 360 and Sony's PlayStation 3 will integrate with Facebook in the near future.

Windows Marketplace for Mobile now available in browser, iTunes' App Store still not

You can now check out what Windows Marketplace for Mobile has to offer without a Windows Phone.

Microsoft damage control after marketer claims Win7 inspired by Mac

Have you ever said anything you wish you could take back? Ever? No? Not even once? Well then, you won't sympathize with a mid-level Microsoft manager today.

Blockbuster's way down, but poised for a comeback

Though it took a serious beating in 2009, Blockbuster CEO Jim Keyes says the company can turn it around.

iTunes Preview deson't go far enough to create Web-based option for store

Apple has rolled out iTunes Preview, a Web interface for browsing iTunes.

PDC 2009 Preview: The move to Office 2010 and Visual Studio 2010

The major focus of Microsoft's conference next week will likely be explaining why two pillars of its software sales strategy deserve to remain where they are.

Dell's first smartphone aids the Android onslaught

Longtime PC leader Dell has finally announced its Android-based smarphone.

After the Intel + AMD armistice: Do we really want a level playing field?

Scott Fulton On Point: One by one, the reasons for us to continue suspending the course toward open and fair competition in IT, are dropping like flies.

FLO TV launches pocketable, smartphone-like TVs

Qualcomm's FLO TV Personal Television made by HTC launches in retail today.

Google acquires Gizmo5, builds IP telephony portfolio

Google Voice today confirmed rumors that it would acquire IP telephony company Gizmo5