• On ZDNet: Free Internet: Gone in 5 years
January 3, 2007 4:51 PM PST

Multiple flaws found in Adobe Reader

by Robert Vamosi

A feature called Open Parameters within older versions of the Adobe Reader browser plug-in can be corrupted with malicious content, two researchers say.

In a conference paper titled "Subverting Ajax", security researchers Stafano Di Paola and Giorgio Fedon identified multiple cross-site scripting (XSS) vulnerabilities. One flaw in particular, the open parameters vulnerability, is quite easy to execute on vulnerable versions of Adobe Reader, they said.

For example, a malicious attack can be carried out by referencing any Web-based PDF file and supplying potentially malicious JavaScript code as an open parameter to any Web-based PDF file--for example, http://www.(domain name).com/file.pdf#whatever_name_you_want=javascript:your_code_here

The researchers said they contacted Adobe Systems in October with their findings and only recently made their work public.

Adobe has since released version 8 of Adobe Reader which no longer allows appended JavaScript within site URLs. However, many users continue to use older versions of the Adobe Reader plug-in and should update this as soon as possible.

Quick facts:

Name: Adobe Reader Open Parameters XSS
Date first reported: 1/3/07
Vulnerable software: Adobe Reader plug-in versions 6 and 7 for Mozilla Firefox, Opera and Microsoft Internet Explorer.
What it does: Could allow denial of service (crash), remote access and execution of malicious code.
Recommendations: Upgrade to Adobe Reader 8
Exploit code available: Yes
Vendor patch available: Yes
Advisory: Wise Security

Robert Vamosi writes for CNET Reviews.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from News Blog
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
Was InfoWorld's CTO of the Year award a year late?
VMWare VI4 renamed to vSphere
Add a Comment (Log in or register)
Adobe Reader 8.0
by zebradoubleu June 15, 2007 11:25 AM PDT
I just updated my Adobe Reader 7.0, which was working flawlessly, to the new 8.0. I've dowloaded it twice, uninstalled it and installed it twice and still can't use it.

The licensing page that opens up initially so the user can "accept" the terms and conditions is BLANK. When that page is closed, the program closes since the licensing agreement wasn't accepted.

Now I can't view any pdf documents until this issue is resolved. Any ideas?

Windows XP Home Edition

Thanks.
Reply to this comment
advertisement

Making sense of Windows 7 upgrades

faq The basics and the fine print on Microsoft's options for those eyeing the next operating system from Redmond.
• Full Windows 7 coverage

Road Trip 2009: Big Sky Country

CNET News reporter Daniel Terdiman takes his car full of gadgets to the Rockies and the Great Plains in search of tech, science, nature, and more.
• America's Fortress: Cheyenne Mountain

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right