Slashdot Mirror


Adobe Warns of Reader, Acrobat Attack

itwbennett writes "Monday afternoon, Adobe 'received reports of a vulnerability in Adobe Reader and Acrobat 9.2 and earlier versions being exploited in the wild,' the company said in a post to the company's Product Security Incident Response Team blog. According to malware tracking group Shadowserver, the vulnerability is due to a bug in the way Reader processes JavaScript code. Several 'tests have confirmed this is a 0-day vulnerability affecting several versions of Adobe Acrobat [Reader] to include the most recent versions of 8.x and 9.x. We have not tested on 7.x, but it may also be vulnerable,' Shadowserver said in a post on its Web site. The group recommends that concerned users disable JavaScript within Adobe's software as a work-around for this problem. (This can be done by un-checking the 'Enable Acrobat JavaScript' in the Edit -> Preferences -> JavaScript window). 'This is legit and is very bad,' Shadowserver added."

3 of 195 comments (clear)

  1. Anyone still has JavaScript enabled? by Anonymous Coward · · Score: 5, Funny

    I thought after so many vulnerabilities everyone had turned that off in Reader...

    1. Re:Anyone still has JavaScript enabled? by jasonwc · · Score: 5, Insightful

      Somewhat ironic, isn't it? If you want to use Adobe's security features (digital signing/encryption) and 3rd party software to achieve SOX compliance - you must accept security vulnerabilities from Acrobat/Reader itself.

  2. Acrobat attack. by NoYob · · Score: 5, Funny
    They're horrible. You have guys flipping and attacking you with their feet while standing on their hands. You have two other guys with one sitting on the other's shoulders while they punch down on you. You try to fight back and they just do backflips away or jump and balance on some pole way above your head.

    Yikes! I hate acrobat attacks!

    --
    It's NOT me! It's the meds! I'm on 1000mg of Fukitol.