Sponsored in part by... Freeverse Freeverse, Inc.'s SOUND STUDIO 3.5.5 - Sound Studio is for anyone
who needs to record or edit audio with a professional tool, but at
a consumer price. Perfect for Podcasts, Music, More! Now updated
for OS X 10.5 Leopard. <http://www.freeverse.com/soundstudio>

 [F] TidBITS  / TidBITS  / TidBITS Talk  /

Security Flaw In Acrobat Reader

[mmatty]mmatty (apparently) - 01:48pm Jan 5, 2007 PST
via email

Macs are vulnerable to this bug too:

<http://blog.washingtonpost.com/securityfix/2006/07/more_fun_with_adobe_updates_1.html>

Since I use Acrobat Pro 6 frequently to create and edit, and won't
upgrade until the upcoming universal binary version is released, it
will be a big PITA to have to constantly move between the reader,
which I will set as the default, and the full application.

Marilyn


Mark as Read
  OutlineAll MessagesOlder MessagesOldest MessagesNewest MessagesNewer Messages

Miles Libbey - Jan 9, 2007 7:02 pm (#1 Total: 1)  

Reply to this message
 

Photo of Author
Posts: 3
Re: Security Flaw In Acrobat Reader

BTW, that washington post article was from July 2006. There is a serious problem in Adobe Acrobat Reader right now (don't know if a patch has been released, but certainly many users will not have upgraded yet). All webmasters that worry about cross site scripting (ie, cookie/credential theft) should be treating PDF documents as unsafe-- changing the PDF mime type to avoid inline display; serving the document outside of the domain with the interesting cookies (or IP address); or something similar. http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051572.html Is that the issue you are thinking of?



  OutlineAll MessagesOlder MessagesOldest MessagesNewest MessagesNewer Messages


 [F] TidBITS  / TidBITS  / TidBITS Talk  / Security Flaw In Acrobat Reader




Add a message

To add a message to this discussion, you must be a registered user. Enter your email address below. If you have an account associated with the email address you enter, you will be prompted for your password. If not, you'll be able to create a new account with no fuss.

Enter your email address:

Submit