Adobe Chided For Insecure Acrobat Reader
The Register covers security firm Secunia calling out Adobe for its insecure distribution practices with regard to Adobe Reader. (Here is Secunia's note.) The accusation is that the way Adobe provides Reader extends the software's window of vulnerability once an exploit has begun to circulate. Version 9.1 of Reader, which is what you get when you visit the official download site, contains 10 vulnerabilities that were patched by later releases. "Adobe Systems has been taken to task for offering outdated software on its downloads page that contains dozens of security vulnerabilities, several of which are already being exploited in the wild... Visitors who obtain Adobe Reader from the company's official downloads page will find that it installs version 9.1 of the program on their computers, even though the most recent version was 9.1.2 at time of writing. That could put users at considerable peril given the number of vulnerabilities fixed in the two iterations that have come since 9.1, complains Secunia..."
Just about every binary distribution on windows is doing something similar these days. Short of someone building a proper, open, distributed, secure package manager for windows, they're probably doing the best they can by having updates at all. It's better than having to go check the webpage for corrections.
That said, if this kind of complaint becomes more common, and all software is seen as flawed in this regard, then it'll be a great push towards proper package management on windows.
How many websites have you seen that say "here's a PDF of a document - you'll need to download Adobe Reader [insert link] if you want to view it" and how many say "here's a PDF of a document - you'll need to download a PDF reader such as Adobe Reader [insert link], Foxit [insert link], ... if you want to view it"? Most commercial sites that distribute PDFs recommend Adobe, and if you're not a techy then you'll assume that Adobe is all you can use. Why do you think so many people used IE6 when Firefox and Opera were available?
If all a person ever needs to do is read a document published on the web, he doesn't even NEED any features.
At least you've made the clarification. There are too many people who reckon Acrobat is bloated because they have never done anything more with a PDF than double-click the icon and read it. In the Industry I work, Acrobat is missing features that we need, which we make up by using plugins.
How about the other five listed here?I'm not running Linux, so I can't wipe your bottom for you. Maybe some research on your part would be useful?
Here, I'll save you some effort and GoogleThatForYou
Finally had enough. Come see us over at https://soylentnews.org/
Evince is pretty lacking in PDF functionality anyway. If you want to compare best of breed on each system, you should probably compare KPDF. It would still fall short of Acrobat Reader. However, I think it's silly to expect otherwise, given that Adobe set the standard AND develop the software meeting that standard in one go.
Adobe began using javascript in their reader beginning with v7 and that has opened up this whole new world of security issues. Wouldn't it be better if the 'reader' just rendered a static file and didn't run embedded script?
I never understood why a simple PDF reader needs to have enough access to a system that the vulnerabilities that are in the Adobe Reader could even exist. Of course I only use a PDF reader to actually read the file. I guess there are some âoesuper eliteâ things to do with Adobe Reader that I have no clue about.