• On The Insider: Miley Cyrus in Sex and the City 2
January 3, 2007 4:51 PM PST

Multiple flaws found in Adobe Reader

by Robert Vamosi
  • Font size
  • Print
  • 1 comment
Share

A feature called Open Parameters within older versions of the Adobe Reader browser plug-in can be corrupted with malicious content, two researchers say.

In a conference paper titled "Subverting Ajax", security researchers Stafano Di Paola and Giorgio Fedon identified multiple cross-site scripting (XSS) vulnerabilities. One flaw in particular, the open parameters vulnerability, is quite easy to execute on vulnerable versions of Adobe Reader, they said.

For example, a malicious attack can be carried out by referencing any Web-based PDF file and supplying potentially malicious JavaScript code as an open parameter to any Web-based PDF file--for example, http://www.(domain name).com/file.pdf#whatever_name_you_want=javascript:your_code_here

The researchers said they contacted Adobe Systems in October with their findings and only recently made their work public.

Adobe has since released version 8 of Adobe Reader which no longer allows appended JavaScript within site URLs. However, many users continue to use older versions of the Adobe Reader plug-in and should update this as soon as possible.

Quick facts:

Name: Adobe Reader Open Parameters XSS
Date first reported: 1/3/07
Vulnerable software: Adobe Reader plug-in versions 6 and 7 for Mozilla Firefox, Opera and Microsoft Internet Explorer.
What it does: Could allow denial of service (crash), remote access and execution of malicious code.
Recommendations: Upgrade to Adobe Reader 8
Exploit code available: Yes
Vendor patch available: Yes
Advisory: Wise Security

Robert Vamosi writes for CNET Reviews.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from News Blog
Nvidia puts NForce chipset development on hold
Opera 10 browser is here
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
Add a Comment (Log in or register)
Adobe Reader 8.0
by zebradoubleu June 15, 2007 11:25 AM PDT
I just updated my Adobe Reader 7.0, which was working flawlessly, to the new 8.0. I've dowloaded it twice, uninstalled it and installed it twice and still can't use it.

The licensing page that opens up initially so the user can "accept" the terms and conditions is BLANK. When that page is closed, the program closes since the licensing agreement wasn't accepted.

Now I can't view any pdf documents until this issue is resolved. Any ideas?

Windows XP Home Edition

Thanks.
Reply to this comment
advertisement

The yogurt makers of tech: Gadgets to avoid

Don't buy these one-trick ponies--unless you like gizmos that gather dust.

Google wants to unclog Net's DNS plumbing

The Net giant, ever eager for a faster Internet, debuts its Google Public DNS service. With it, Google could become even more central to the Net.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
Click Here
advertisement

Inside CNET News

Scroll Left Scroll Right