Slashdot Mirror


New Adobe PDF Zero-Day Under Attack

Rahmmp writes "Adobe has sounded an alarm for a new zero-day flaw in its PDF Reader/Acrobat software, warning that hackers are actively exploiting the vulnerability in-the-wild. An Adobe spokeswoman described the attacks as 'limited' but warned that that could change with the availability of public samples and exploit code."

8 of 203 comments (clear)

  1. No credibility to this story by symbolset · · Score: 5, Funny

    Whenever we have a credible PDF exploit story, the slashdot fine summary always links to a reliable PDF document that explains the exploit in detail. Sorry, not buying this one.

    --
    Help stamp out iliturcy.
  2. Re:Fortunately... by codewarren · · Score: 2, Funny

    If the exploit affects spelling, you have cause for concern

  3. I work for Adobe and... by Anonymous Coward · · Score: 4, Funny

    We invest a TON of $$ and hours into security. In fact, our security team pulls themselves inside out to fix things in a timely manner. Adobe takes security VERY seriously as we have governments all over the world trusting secrets to us. Nevertheless, as hackers focus shifts away from O/S exploits towards application level, there will likely be further attempts to compromise PDF readers. We will be vigilant and we will rise to meet future threats as they happen.

    COS based PDF is also incredibly complicated if you adopt the entire ISO 32000 specification and expose the scripting and coding API's developers want. When you can write code to pinpoint the quads and move a point of one UTF 16 character within a book, that is powerful. Enough said on that.

    Oh - and we are not lazy as some have suggested. My team pulled a 32 hour session last week.

    - the adobe1

  4. Re:Can there be a 0-day that's not under attack? by tater86 · · Score: 2, Funny

    I'm pretty sure we have this argument every time someone mentions zero day. If we could have a zero day bricking, we could have the best thread ever.

  5. Re:Fortunately... by wbhauck · · Score: 3, Funny

    Meanwhile, how do I know if I'm alreadt pwned?

    It's all explained in this FREE guide. Just download our convenient PDF for more information.

  6. Re:A ton of money is... by Lennie · · Score: 3, Funny

    Only on slashdot ?

    --
    New things are always on the horizon
  7. Re:Fortunately... by ThatsNotPudding · · Score: 4, Funny

    Meanwhile, how do I know if I'm alreadt pwned?

    You start slurring your y's.

  8. Re:Rocket Scientists... by GigsVT · · Score: 2, Funny

    The link seems to be broken.

    --
    I've had enough abrasive sigs. Kittens are cute and fuzzy.