Adobe Acrobat JavaScript Execution Bug
QASec.com writes to mention that Stefano Di Paola and Giorgio Fedon discovered an unpatched vulnerability in Adobe Acrobat Reader that can allow an attacker to execute arbitrary JavaScript on any hosted PDF file. People are reporting different results based on browser and Acrobat versions. Most of the major sites discussed have already fixed the problem, but many smaller sites may still need to be patched.
I recently signed up for the "send your name to wherever" thing pointed out on slash (its in my comment history somewhere)
The PDF was formed with parameters linking to a second pdf base document.
From Firefox on Windows with internet explorer disabled the pdf opened inside acrobat then proceeded to display the resulting PDF file in internet explorer.
I haven't seen IE now for ages and that made me nervous as hell.
liqbase