News

New Adobe hacker vulnerability found

July 23, 2009

Advertisement
Advertisement
 

Symantec has identified a vulnerability in Adobe Flash.

Patrick Fitzgerald on Symantec's blog, noted their discovery of an Adobe Acrobat PDF file that "upon opening drops and executes a malicious binary." Fitzgerald goes on to say in the post, "It was quite clear that this PDF was exploiting some vulnerability in order to drop its payload."

Fitzgerald also noted that upon further inspection it was a new vulnerability that they had not seen in the wild before. "What was even more surprising was that this vulnerability affects Adobe Flash -- not Adobe Reader as we initially suspected."

He writes, "The authors of the exploit have managed to take a bug and turn it into a reliable exploit using a heap spray technique." Fitzgerald also noted that in the newly discovered exploitation the PDF exploiting the vulnerability includes multiple Flash streams. And that their testing revealed the vulnerability is exploitable on both Windows XP and Vista, but the dropped executables will not run on Vista if UAC is enabled.

Adobe posted on its site, that it was aware of the "potential vulnerability" and would update users with more information soon.

Using an alternative reader like those from Nitro PDF Software or Foxit might be a short-term solution. Or users can also disable the Flash in Adobe Reader 9 and disable Flash Player as well.

Related Products at PDF Store

Adobe? Acrobat? & PDF Software

The No.1 PDF and Acrobat software store for tools to create, edit and publish PDF files. Get Nitro P... View full product details
Download free demo

ARTS PDF Split & Merge Lite

The easiest way to split and merge PDFs! It provides a simpler method of splitting and merging your ... View full product details
Download free demo

Quite Imposing Plus

A plug-in for Adobe Acrobat to perform imposition. Additional functionality is added to that of Quit... View full product details
Download free demo

PDF In-Depth Free Product Trials Ubiquitous PDF

Nitro PDF Professional

the perfect PDF product for business and enterprise, combining an extremely competitive price with a...

Download free demo

XpdfViewer

This ActiveX control (OCX) provides a PDF file viewer component, enabling developers to add PDF viewing...

Download free demo

Ubiquitous PDF: PDF eBooks-Library

If you are looking for a good store of PDF content, you could do a lot worse than visiting eBooks-Library.com...

September 03, 2009
Search Planet PDF
more searching options...







Create PDF Free

Most Popluar Articles
Planet PDF Newsletter
Features

Adding a PDF Stamp Comment

OK, so you want to stamp your document. Maybe you need to give reviewers some advice about the document's status or sensitivity. This tip from author Ted Padova demonstrates how to add stamps with the Stamp Tool along with related comments.

Featured Product

Docmetrics

Generate more, higher-quality sales leads from your PDF marketing content. Docmetrics is a web-based system that lets you capture previously unavailable reader data. Free trial.

Platinum Sponsor
Create & Edit PDF - Nitro PDF Software

ARTS PDF

Silver Sponsors

PDF-Tools enfocus

QuickPDF: The Unrivaled PDF Developer Toolkit