Adobe Warns of Critical Zero Day Vulnerability
wiredmikey writes "Adobe issued an advisory today on a zero-day vulnerability (CVE-2011-2462) that has come under attack in the wild. According to Adobe, the issue is a U3D memory corruption vulnerability that can be exploited to cause a crash and permit an attacker to hijack a system. So far, there are reports the vulnerability is being exploited in limited, targeted attacks against Adobe Reader 9.x on Windows. However, the bug also affects Adobe Reader and Acrobat 9.4.6 and earlier 9.x versions for UNIX and Macintosh computers, as well as Adobe Reader X (10.1.1) and Acrobat X (10.1.1) and earlier 10.x versions on Windows and Mac. Patches for Windows and Mac users of Adobe Reader X and Acrobat X will come on the next quarterly update, scheduled for Jan. 10, 2012."
Why on earth isn't "Adobe Reader X Protected Mode" the default?
Jan. 10, 2012? Why not immediately? Do Adobe coders suck that bad... Honestly I think when a major vulnerability is found, companies should fix it immediately or face penalties.
...leads to increased vulnerability, whether in biology or in software.
Although there are alternatives to Adobe Reader, none of them is good enough to gain significant market share. And Adobe does everything it can to make competing with it more difficult. So a key piece of software used by a large majority of computer users is bloated beyond belief and so riddled with vulnerabilities that it seems there's a new every day. It sucks, but it's hardly surprising.
On the web, as in politics, we get what we deserve - or, in this case, we get what other web users deserve, because they vastly outnumber us.
'The Economy' is a giant Ponzi scheme whose most pitiable suckers are the youngest among us and the yet-unborn.
If you're wondering "How can this happen?", all you need to do is look at the credits of Acrobat Reader. Notice that many of the names are quite clearly Indian. Then it all makes sense.
Why do we need support for 3D files, embedded file attachments, JavaScript and all that crap in a file format that was originally intended to print documents? I'm glad that there are alternativs to Adobe Reader that just support the old idea of a printable document file format and nothing more, for example Preview on OS X, for other OS see this list. The crazy thing is that Adobe Reader is promoted by a lot of companies that use PDFs to send out bills electronically, i.e. to open the attachment, you need to download Acrobat Reader. Which is not only a wrong statement, but also a suggestion to install an application that has been plagued with security faults.
Most of our technical manuals come in PDF form now, but thank God for Okular. It has really, really improved. :)
Cogito, igitur comedam pizza.
It's a freakin' document reader. How did Adobe end up here? Not only is it such a bloated piece of crap it takes forever to open a document, but they seem to have one vulnerability after another. The functionality that they added for 0.0000001% of their customers isn't really worth the price they're paying.
Hey I don't have a problem with you being on XP friend, if it works why fix it? I have windows 7 on one machine and XP on another, why bother switching the older XP machine?
My question would be why are you trying to run Adbobe reader at all when there is both Foxit and Sumatra on Ninite. Just check the box, click the download button and run it, that's it. then you can say goodbye to crappy Adobe Reader.
As for why Adobe can't build a secure reader? you answered it yourself friend when you said you thought it was " one program to do basically one simple enough thing" when to try to sell copies of Acrobat Adobe has been piling shit into that program for years. That is why frankly for production software like Acrobat i really wish they'd go to a yearly license model like AV companies use. that way instead of being pressured to constantly add new shit to the program so they have an excuse to upsell you they could just focus on making it better and more secure and get paid without having to add crap.
ACs don't waste your time replying, your posts are never seen by me.
It has a 4.4 MB setup file, compared to Adobe Reader's 40.5 MB, for Windows 7. Installed size is 8.4 MB, whereas Adobe Reader requires 335 MB of available disk space.
Adobe PDF Reader - now with 10-40x the size of what's *really* needed! ***Bonus*** - Includes Critical 0 Day vulnerability, @ no extra charge!!!
What more could you ask for?
"...there are some things that can beat smartness and foresight. Awkwardness and stupidity can." ~ Mark Twain
I wrote it years ago, but it's still quite relevant:
http://www.cert.org/blogs/certcc/2009/06/vulnerabilities_and_software_a.html
Coding quality and exploit mitigations aside, there's something to be said for the size of the software that you're installing. The more code that's there, the more there is to attack. If you're using Reader, you might ask, why is there a 3D rendering engine in my PDF reader? Or maybe even do something about it.
> you must distinguish the difference between conforming and non-conforming implementations of PDF before comparing
Your point is valid, however, how much of that ISO standard is, itself, "ooooh, shiny"-ness which is one of the reasons why Reader has so many more possible places of failure? Before discovering better alternatives for reading PDFs under Windows, the first thing I would do to Adobe Reader was to disable scripting support inside PDF documents.
In other words, I prefer the non-conforming, because that means that (there is a chance that) the implementers might actually be ignoring stupid things which Adobe pushed into the PDF standard which shouldn't be there.
It's the old Microsoft syndrome again...
Take software which was designed for a non networked, single user standalone environment...
Throw it onto a hostile network like the Internet...
Then make sure that 95% of systems run exactly the same software...
If there was a more even marketshare of PDF viewers out there, then they would be far less attractive to target.
http://spamdecoy.net - free throwaway anonymous email - avoid spam!