PDF In-Depth

EDITORIAL: Adobe Reader rollercoaster slows to a halt

January 11, 2007

Advertisement
Advertisement
 

After such headlines as "Adobe flaw may be 'worst' bug of 2007" scarcely a week into the new year, one could perhaps be forgiven for feeling a little nervous. As it turns out however, this latest flaw now seems more like a falling acorn than a piece of sky.

Basically, Adobe's Reader browser plug-in leaves user systems vulnerable to attack from JavaScript-based malware via cross-site-scripting (XSS). According to a January 8 Computerworld article, "...the flaw affects Adobe Reader and Acrobat Versions 7.0.8 and older running in the open-source Firefox browser, and Adobe 6.x and older versions running in Microsoft Corp.'s Internet Explorer." An attack exploiting the weakness could be crafted by appending the JavaScript to a Web link to any existing PDF file. Since the danger is in the link rather than the PDF document itself, this method allows even PDFs from trusted sources to be used in this way.

Sounds pretty scary, huh? Well, there are a few reasons that the problem now appears so much less imposing. For a start, the bug only occurs in quite unusual Web browser/PDF viewer combinations. The other point to note is that, due to the rarity of the vulnerable configurations, it's hardly worth the cost of the instant coffee they'd drink while coding for malicious programmers to write the appropriate malware in the first place.

In any case, the simplest fix for the issue is to upgrade to the latest version of the free Adobe Reader (version 8.x), which does not possess the flaw. Basically, that equates to peace-of-mind at the cost of a little bandwidth. For the users who are particularly attached to their older versions (e.g. those using a full version of Acrobat 7.08 or older), Adobe has pledged to release patches to nix the bug. In the interim, such users can adjust their browser preferences to prevent the Reader plug-in from opening within the browser.

Although the vulnerability is a dangerous one, it is only a potential problem and even then, it can only affect a very small percentage of users. I tend to agree with Duff Johnson that the flaw's dangers have been much exaggerated, although I wonder if it isn't more of a case of "Chicken-Little-itis" rather than a deliberate media beat-up.

Related Products at PDF Store

Nitro PDF Professional

Nitro PDF Professional, your PDF creation and editing product. Priced at $99, Nitro PDF Pro is the m... View full product details
Download free demo

ARTS PDF Aerialist

Take Acrobat to the next level with advanced splitting and merging; flexible bookmark creation and m... View full product details
Download free demo

ARTS PDF Split & Merge Lite

The easiest way to split and merge PDFs! It provides a simpler method of splitting and merging your ... View full product details
Download free demo

PDF In-Depth Free Product Trials Ubiquitous PDF

Nitro PDF Professional

the perfect PDF product for business and enterprise, combining an extremely competitive price with a...

Download free demo

XpdfViewer

This ActiveX control (OCX) provides a PDF file viewer component, enabling developers to add PDF viewing...

Download free demo

Ubiquitous PDF: PDF eBooks-Library

If you are looking for a good store of PDF content, you could do a lot worse than visiting eBooks-Library.com...

September 03, 2009
Search Planet PDF
more searching options...







Convert PDF Files

Planet PDF Newsletter
Most Popluar Articles
Features

How to Create Slide Shows and Self-running Kiosks in Acrobat

In this tutorial, Ted Padova and Wendy Halderman explain how to best use the features of Acrobat 6 Professional to create a self-running multi-media kiosk for use with displays such as tradeshow exhibits.

Featured Product

ARTS PDF Aerialist

The ultimate plug-in for Adobe Acrobat and #1 selling product at PDF Store. Advanced splitting, merging, stamping, bookmarking, and link control. Take Acrobat to the next level.

Platinum Sponsor
Create & Edit PDF - Nitro PDF Software

ARTS PDF

Silver Sponsors

PDF-Tools enfocus

QuickPDF: The Unrivaled PDF Developer Toolkit