Planet PDF ForumPlanet PDF Classic

Enterprise & Government
Find Software and ServicesPDF EventsFreeNewslettersAboutSite MapOur SponsorsAdvertise
News

Adobe downplays latest vulnerabilities

Nettie Hartsock Planet PDF Contributing Editor

March 04, 2010

Advertisement
Advertisement
 

Adobe continues to be dogged by the vulnerability of some of its leading programs, including its own Download Manager program that was recently cited by Israeli security researcher Aviv Raff, as a serious security issue.

In late February, Adobe updated its security update on what it termed the "critical" vulnerability in Adobe Reader 9.3 for Windows and Macintosh, as well as Adobe Reader 8.2 and Acrobat 8.2 for Windows and Macintosh. (The full security update is here.)

As noted on the CSOonline.com site, Brad Arkin, director of product security and privacy at Adobe System, spent a significant amount of time updating Adobe customers on these issues, at the recent RSA security conference.

While Arkin notes in the interview that Adobe is trying to achieve transparency, the latest fix last Tuesday in regard to its Download Manager program does not inspire confidence. For Aviv Raff's part, his response to Adobe's security release and statement on the Download Manager vulnerability that he as well as Dutch researcher Yorick Koster discovered was to note the company was reticent in his opinion to fully admit the design flaw.

Raff notes on his blog post, "I think they missed the whole point here. While it is true that Adobe Download manager is removed upon computer restart, the user, who has just updated their Adobe product (usually without requirement to restart the computer after the update), is still expose to forced automatic installation when they start their computer."

Raff also stated on his blog that he's already found another remote code execution flaw in the Adobe Download Manager, through which "an attacker can force an automatic download and installation of any executable he desires."

For its part, Adobe has not responded to Raff's newly found code execution flaw, and is still maintaining that the vulnerability has been addressed.

Related Products at PDF Store

PDF Password

Prevents unauthorized copying of PDF files ? the perfect solution for e-books and other publications... View full product details
Download free demo

Nitro PDF Professional

Nitro PDF Professional, your PDF creation and editing product. Priced at $99.99, Nitro PDF Pro is th... View full product details
Download free demo

Adobe? Acrobat? & PDF Software

The No.1 PDF and Acrobat software store for tools to create, edit and publish PDF files. Get Nitro P... View full product details
Download free demo

Advertisement
PDF In-Depth Free Product Trials Ubiquitous PDF
  • Section 508 and PDF: The facts
  • Is PDF an open standard?
  • No, PDF is NOT owned by Adobe!
  • How to (successfully) switch to a paperless practice
  • What's your preference, sir?

Nitro PDF Professional

the perfect PDF product for business and enterprise, combining an extremely competitive price with a...

Download free demo

XpdfViewer

This ActiveX control (OCX) provides a PDF file viewer component, enabling developers to add PDF viewing...

Download free demo

Ubiquitous PDF: Planning for unexpected cash

It's the end of the financial year and some lucky souls are expecting a tax return. Whether or not the dollars are stacking up for you, it's worth keeping in mind this new PDF tool from Squawkfox.

July 29, 2010
Advertisement
Search Planet PDF
more searching options...
Advertisement







Create PDF Free

Advertisement
Advertisement
Most Popluar Articles
  1. Section 508 and PDF: The facts
  2. Word doesn't do Section 508, PDF gets the blame
  3. Is PDF an open standard?
  4. No, PDF is NOT owned by Adobe!
  5. The Tablet: What it means for publishing
Planet PDF Newsletter

Features

Adding a PDF Stamp Comment

OK, so you want to stamp your document. Maybe you need to give reviewers some advice about the document's status or sensitivity. This tip from author Ted Padova demonstrates how to add stamps with the Stamp Tool along with related comments.

Featured Product

Docmetrics

Generate more, higher-quality sales leads from your PDF marketing content. Docmetrics is a web-based system that lets you capture previously unavailable reader data. Free trial.

Platinum Sponsor
Create & Edit PDF - Nitro PDF Software

ARTS PDF

Silver Sponsors

PDF-Tools QuickPDF: The Unrivaled PDF Developer Toolkit

Advertisement

Advertise | Submit news | Newsletters | About | Contact | Site Map | Forum Archive
  Planet PDF RSS Feeds | Buy PDF Software | Find PDF Software | Free PDF eBooks

Powered by CM3To connect with us: Read Nitro's PDF Blog, follow nitro pdf on Twitter, or join the Nitro PDF LinkedIn group. Planet PDF, PDF Store, Nitro PDF Software and ARTS PDF are all copyright © 2009 Nitro PDF, Inc. and Nitro PDF Pty Ltd. All Rights Reserved. Privacy

Planet PDF