Adobe swings and misses as PDF abuse worsens
After
more than two weeks (months?) of inexplicable silence on mitigations
for a known code execution vulnerability in its Reader and Acrobat
product lines, Adobe has finally posted public information on the
problem but the company’s response falls well short of providing
definitive mitigation guidance for end users.
[ For background and a timeline on how *not* to handle incident response, HD Moore's blog post is a great start. ]
Adobe’s response simply confirms what we already know and reiterates that turning off JavaScript will NOT eliminate the risk entirely. However, the company does not offer any definitive suggestions or workarounds, instead pointing to a list of anti-malware vendors blocking known attacks.
Here’s what we have from Adobe:
- We have seen reports that disabling JavaScript in Adobe Reader and Acrobat can protect users from this issue. Disabling JavaScript provides protection against currently known attacks. However, the vulnerability is not in the scripting engine and, therefore, disabling JavaScript does not eliminate all risk. Keeping this in mind, should users choose to disable JavaScript, it can be accomplished following the instructions below:
- Launch Acrobat or Adobe Reader.
- Select Edit>Preferences
- Select the JavaScript Category
- Uncheck the ‘Enable Acrobat JavaScript’ option
- Click OK
While this information is better than the silence we’ve gotten from Adobe since the attacks became public, it falls well short of providing the protection information that businesses and end users need when in-the-wild malware attacks are occuring.
The company did not offer any details on the actual vulnerability. It did not provide workarounds. It did not provide mitigation guidance. Adobe simply rehashed what we already knew and confirmed that the public mitigation guidance from third parties is/was not definitive.
As my former ZDNet Zero Day blog colleague Nate McFeters points out, the issue is much worse than first imagined.
- I decided I’d test this out and found that on a fully patched Mac OS X build, Safari 4, Mail.app, Preview.app, and potentially others all crash using the proof of concept exploit provide on milw0rm. The crash is actually in PDFKit, which supports all of those applications and likely much more.
According to this Secunia’s Carsten Eiram, his company managed to create a reliable, fully working exploit which does not use JavaScript and can therefore successfully compromise users, who may think they are safe because JavaScript support has been disabled.
- All users of Adobe Reader/Acrobat should therefore show extreme caution when deciding which PDF files to open regardless of whether they have disabled JavaScript support or not.
If Secunia can do it based on information that’s public, what’s to stop malicious hackers with major financial motivation?
So what now Adobe?



This page added to Google cache Cached: http://google.com/search?q=cache:http://techblog.randtenterprises.com/2009/02/26/adobe-swings-and-misses-as-pdf-abuse-worsens.aspx?ref=rss&ei=AFQjCNHajN_OX0kgxzx7UGA1yBfPoRn TubedfWq
Reply to this
If you're going to pay Juicy Couture prices, you definitely want real Juicy Couture items. Be sure to avoid fake juicy couture sandals, and in order to do so, learn how to identify fake juicy couture flip flops and juicy couture sunglasses. Many recent Juicy Couture items will have tags that say "Born in the Glamorous USA." Be aware of anything that says otherwise. Also pay attention to the spacing on the tags: are any letters mangled or squished together? Are there any misspellings? These are obvious signs of fakes.
Reply to this
The first time I downloaded Adobe I experienced a couple of these issues. Their customer service is top notch, and I commend them for being able to respond to such a huge problem as fast as they did.
Reply to this
I really thankful to you for this great read!! You did a very great job, keep it up.
Reply to this
Thanks for providing such useful information. I really appreciate your professional approach.
Reply to this
Wow, what a great resource! Thanks for sharing this...
Reply to this
A good deed never goes unpunished.
Reply to this
I admit I was drinking a Guinness... but I did not swallow.
Reply to this
Amazing!I also wish him good luck to defend his gold medal. I like to share it with all my friends and hope they will also encourage him.
Reply to this
Hello, comrade! I'm utterly accede to that way of assessment and all of connected.
Reply to this
.
Reply to this
.
Reply to this
.
Reply to this
Super Site
Reply to this
Scribbler let student's record-book
Reply to this
Thanks for the article!
Reply to this
Sorry for the off-topic, do not tell, where can a nice template for your blog get?
Reply to this
Material for five plus.
Reply to this
I have been through the whole content of this blog which is very informative and knowledgeable stuff, I would like to visit again.
Reply to this
more and more information about home purchasing are mentioned in this blog. Please read them and keep in mind. ----- Thanks
Reply to this
I am very much pleased with the contents you have mentioned.I wanted to thank you for this great article.
Reply to this