RSS RSS Twitter Twitter
macnn

06/25/2008, 2:25am, EDT

Wednesday, June 25th

Adobe fixes critical Acrobat security flaw

Adobe on Monday released patches for Acrobat and its free Reader equivalent to fix a security hole that could leave Mac and Windows computers susceptible to control at the hands of a malicious remote user. Computerworld writes that the "critical" vulnerability has existed in several incarnations of the v8.x.x Acrobat software, but does not apply to users of Acrobat 7.1.0. The patch comes after criticism over Adobe's vague mention of vulnerability fixes in a recent update, as several past JavaScript bugs resurfaced, leaving many users affected.

"Adobe has an epidemic with regards to JavaScript," noted Andrew Storms, director of security operations at nCircle Network Security. "With this many JavaScript bugs in Acrobat, one begins to ask questions. Why would a full, thick application like Acrobat need to be using JavaScript, especially when JavaScript in the browser has historically been a target for hackers? And since JavaScript has been a target for so many years, why hasn't Adobe flushed out these vulnerabilities already?"


Filed under: security, software
Other story tags: Windows, Adobe, Mac, Acrobat

, , 7comments, del.icio.us, slashdot, digg, buzz , Twitter



7 comments
Reader Reactions (Please use <i></i> for italic text)

subscribe to comments
for this article




Expand All   Global Settings

what's stupid is...

3
06/25, 3:02am, EDT

that Acrobat Reader is now over 100 Mb. Just to "read" PDFs. It used to be that it was decent, but now it's complete bloatware.

yeah!

-2
06/25, 8:06am, EDT

The patch comes after criticism over Adobe's vague mention of vulnerability fixes in a recent update, as several past JavaScript bugs resurfaced, leaving many users affected.

They should take lessons from Apple and learn how to document their fixes!

And I didn't even know Adobe had support for javascript, nor any idea what in the world one would need it for. Is this like one of those lame-ass ideas from the 90's where email software makers added javascript support to email content because it would be 'cool'?

Fresh-Faced Recruit
Joined Aug 2001
User is offline

Alternatives

3
06/25, 8:53am, EDT

There's always Preview for basic PDF viewing, or another free alternative is Skim. (http://www.macupdate.com/info.php/id/24590/skim)

Grizzled Veteran
Joined Aug 2007
User is offline

Alternatives

-1
06/25, 8:53am, EDT

There's always Preview for basic PDF viewing, or another free alternative is [url="http://www.macupdate.com/info.php/id/24590/skim"]Skim[/url]

(http://www.macupdate.com/info.php/id/24590/skim)

Grizzled Veteran
Joined Aug 2007
User is offline

Nevermind

1
06/25, 8:53am, EDT

I have horrible button clicking skills it seems.

Grizzled Veteran
Joined Aug 2007
User is offline

What, no LINK?

2
06/25, 9:35am, EDT

An article about a "critical vulnerability" and NO LINK for the patch.

How useful.

Fresh-Faced Recruit
Joined Oct 1999
User is offline

re: Yeah (@ testudo)

1
06/25, 12:34pm, EDT

Adobe has Javascript support in all their applications. It was their solution to cross-platform application scripting and automation. In fact they use ECMA-262 which is a superset of Javascript.

Adobe uses the Qt development platform for building cross-platform applications (well probably until recently), and Qt comes with a pre-built Javascript compiler and stack for automation and application scripting. So they probably just incorporated that engine.

And Javascript is not as bad as it's made out to be. It's a very powerful language, and if implemented correctly, quite secure. Without Javascript, the web wouldn't exist.

Fresh-Faced Recruit
Joined Apr 2008
User is offline
Your Comments

In order to post comments: If you are a registered member, please login with your MacNN Forums username and password otherwise please uncheck the checkbox below.


Registered Member?
macnn forums login:

macnn forums password:

Not a member of the MacNN forums? Register now for free.

RSS Feeds

Have the latest content delivered to your desktop via RSS. Use the links below to get access to a specific blog, news, or reviews feed.



  MacNN -all

  MacNN Reviews

  MacNN Podcasts

  iPodNN

  Electronista

  Left Lane News
Want To Sell Your Laptop? Any Condition - receive Top Cash. Get an instant quote. Free shipping www.CashForLaptops.com

Internet Marketing School - 100% Online: Master SEO, SEM, E Commerce, Media & More with a U of San Francisco Certificate.

Autodesk Inventor For Digital Prototypes: Use Inventor To Virtually Model, Test, and Iterate in 3D & Get To Market Faster!

Buy from The Apple Store, iTunes.com, Amazon.com, TechDepot, OfficeDepot, Computers4Sure, or donate.