Slashdot Mirror


Adobe Warns of Reader, Acrobat Attack

itwbennett writes "Monday afternoon, Adobe 'received reports of a vulnerability in Adobe Reader and Acrobat 9.2 and earlier versions being exploited in the wild,' the company said in a post to the company's Product Security Incident Response Team blog. According to malware tracking group Shadowserver, the vulnerability is due to a bug in the way Reader processes JavaScript code. Several 'tests have confirmed this is a 0-day vulnerability affecting several versions of Adobe Acrobat [Reader] to include the most recent versions of 8.x and 9.x. We have not tested on 7.x, but it may also be vulnerable,' Shadowserver said in a post on its Web site. The group recommends that concerned users disable JavaScript within Adobe's software as a work-around for this problem. (This can be done by un-checking the 'Enable Acrobat JavaScript' in the Edit -> Preferences -> JavaScript window). 'This is legit and is very bad,' Shadowserver added."

5 of 195 comments (clear)

  1. Javascript Again by Anonymous Coward · · Score: 4, Informative

    If you have to use Reader, ALWAYS disable Javascript. It always seems like that's was these exploits use. Or use one of the many PDF reader alternatives.

  2. Re:Limit permissions and seek alternatives? by oDDmON+oUT · · Score: 3, Informative

    Replying to my own last line as an informational thing:

    http://en.wikipedia.org/wiki/List_of_PDF_software

    --
    Some days it's just not worth
    chewing through my restraints.
  3. Re:Preferences? by clone53421 · · Score: 3, Informative

    You could try the Edit -> Preferences -> JavaScript window. Here, I’ll make a little instruction sheet for you.

    http://img38.imagefra.me/img/img38/1/12/15/clone53421/f_viwjj0m_1729695.jpg

    --
    Alexander Peter Kristopeit bought his basement from his mommy for one dollar.
  4. Re:Anyone still has JavaScript enabled? by Zumbs · · Score: 3, Informative
    --
    The truth may be out there, but lies are inside your head
  5. Re:seen it, I think by StuartHankins · · Score: 3, Informative

    Sounds like you need NoScript and AdBlock.