Reply to topic  [ 25 posts ]  Go to page 1, 2  Next
Adobe Zero Day, again... 
Author Message
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
http://www.pcpro.co.uk/news/security/36 ... o-day-flaw

Zero day remote execution flaw in Adobe Acrobat and Reader 9.3.4 and earlier (the latest version available for download IS 9.3.4) on Windows and OS X. Opening a malformed PDF document can allow the attacker full control of the affected system.

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Thu Sep 09, 2010 9:41 am
Profile ICQ
I haven't seen my friends in so long
User avatar

Joined: Tue May 05, 2009 3:29 pm
Posts: 7173
Reply with quote
.PDF files are not generally ones where I generally think "Be careful, it could be malicious". Perhaps I ought to re-think that policy :shock:.

I'm also wary of the fact that this will apparently affect a PC with UAC set to the highest setting. :?

_________________
timark_uk wrote:
That's your problem. You need Linux. That'll fix all your problems.
Mark


Thu Sep 09, 2010 9:47 am
Profile
What's a life?
User avatar

Joined: Thu Apr 23, 2009 7:26 pm
Posts: 17040
Reply with quote
Linux_User wrote:
.PDF files are not generally ones where I generally think "Be careful, it could be malicious". Perhaps I ought to re-think that policy :shock:.
I'm also wary of the fact that this will apparently affect a PC with UAC set to the highest setting. :?

Simplest solution is not to use Adobe reader to look at PDFs. IIRC, a lot of the other readers (FoxIt, SumatraPDF, Preview on Mac OS) don't suffer from the same security bugs.

Adobe. They really can't program for toffee, it has to be said.


Thu Sep 09, 2010 10:42 am
Profile
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
Foxit has suffered from most of the recent security flaws in PDF, because they were in the actual design of the specification that the flaws were, not in the code used to implement it... :?

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Thu Sep 09, 2010 11:05 am
Profile ICQ
Legend
User avatar

Joined: Fri Apr 24, 2009 2:02 am
Posts: 29240
Location: Guantanamo Bay (thanks bobbdobbs)
Reply with quote
With a mac I cannot remember when I last used Adobe reader. I keep updating it but use the inbuilt Preview almost all the time.

_________________
Do concentrate, 007...

"You are gifted. Mine is bordering on seven seconds."

https://www.dropbox.com/referrals/NTg5MzczNTk

http://astore.amazon.co.uk/wwwx404couk-21


Thu Sep 09, 2010 11:16 am
Profile
Moderator

Joined: Thu Apr 23, 2009 6:13 pm
Posts: 7262
Location: Here, but not all there.
Reply with quote
Adobe's labyrinthine updating process seriously annoyed me. Who creates an installer that has to download a package, unpack it, run it to then download the proper installer? Who then builds an installer that coughs up two dialog boxes, but the one you have to dismiss first is UNDER the top one? :|

After umpteen attempts to update Acrobat Pro, I deleted the entire package completely. I've not looked back. No more annoying nagging about another tweak or bug fix, no more crashing and memory hogging.

Once we rid the world of Flash as well, I will be happy. ;)

_________________
My Flickr | Snaptophobic Bloggage
Heather Kay: modelling details that matter.
"Let my windows be open to receive new ideas but let me also be strong enough not to be blown away by them." - Mahatma Gandhi.


Thu Sep 09, 2010 11:23 am
Profile
I haven't seen my friends in so long
User avatar

Joined: Thu Apr 23, 2009 6:36 pm
Posts: 5161
Location: /dev/tty0
Reply with quote
So is this with or without the new Adobe Reader sandboxing stuff that Adobe was talking about the other month?


Thu Sep 09, 2010 11:28 am
Profile WWW
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
Without, sandboxing is due in the next release of Reader. That won't help Acrobat users though.

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Thu Sep 09, 2010 11:45 am
Profile ICQ
I haven't seen my friends in so long
User avatar

Joined: Thu Jun 18, 2009 5:10 pm
Posts: 5836
Reply with quote
HeatherKay wrote:
Adobe's labyrinthine updating process seriously annoyed me. Who creates an installer that has to download a package, unpack it, run it to then download the proper installer? Who then builds an installer that coughs up two dialog boxes, but the one you have to dismiss first is UNDER the top one? :| ...

...Once we rid the world of Flash as well, I will be happy. ;)


Well said.

Okular ftw!

_________________
Jim

Image


Thu Sep 09, 2010 11:53 am
Profile
Legend
User avatar

Joined: Fri Apr 24, 2009 2:02 am
Posts: 29240
Location: Guantanamo Bay (thanks bobbdobbs)
Reply with quote
HeatherKay wrote:
Adobe's labyrinthine updating process seriously annoyed me. Who creates an installer that has to download a package, unpack it, run it to then download the proper installer? Who then builds an installer that coughs up two dialog boxes, but the one you have to dismiss first is UNDER the top one? :|

After umpteen attempts to update Acrobat Pro, I deleted the entire package completely. I've not looked back. No more annoying nagging about another tweak or bug fix, no more crashing and memory hogging.

Once we rid the world of Flash as well, I will be happy. ;)

So do mac users even need Adobe reader on their system at all? They can be read with preview. Thanks in advance.

_________________
Do concentrate, 007...

"You are gifted. Mine is bordering on seven seconds."

https://www.dropbox.com/referrals/NTg5MzczNTk

http://astore.amazon.co.uk/wwwx404couk-21


Thu Sep 09, 2010 12:00 pm
Profile
Moderator

Joined: Thu Apr 23, 2009 6:13 pm
Posts: 7262
Location: Here, but not all there.
Reply with quote
Amnesia10 wrote:
So do mac users even need Adobe reader on their system at all? They can be read with preview. Thanks in advance.


Preview is quite good, but there are occasional PDFs that won't display properly for whatever reason. I have yet to come across one since disposing of Acrobat, but when I do I may consider downloading Reader.

_________________
My Flickr | Snaptophobic Bloggage
Heather Kay: modelling details that matter.
"Let my windows be open to receive new ideas but let me also be strong enough not to be blown away by them." - Mahatma Gandhi.


Thu Sep 09, 2010 12:23 pm
Profile
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
Amnesia10 wrote:
With a mac I cannot remember when I last used Adobe reader. I keep updating it but use the inbuilt Preview almost all the time.

Preview was vulnerable to 2 PDF exploits this year. ;)

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Thu Sep 09, 2010 12:31 pm
Profile ICQ
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
Amnesia10 wrote:
HeatherKay wrote:
Adobe's labyrinthine updating process seriously annoyed me. Who creates an installer that has to download a package, unpack it, run it to then download the proper installer? Who then builds an installer that coughs up two dialog boxes, but the one you have to dismiss first is UNDER the top one? :|

After umpteen attempts to update Acrobat Pro, I deleted the entire package completely. I've not looked back. No more annoying nagging about another tweak or bug fix, no more crashing and memory hogging.

Once we rid the world of Flash as well, I will be happy. ;)

So do mac users even need Adobe reader on their system at all? They can be read with preview. Thanks in advance.

It doesn't support all features of the PDF standard, which is also why it isn't as vulnerable as some of the other readers.

I believe, it doesn't support form filling and saving, for example, or embedded Flash, for example. The latter is a very questionable feature!

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Thu Sep 09, 2010 12:33 pm
Profile ICQ
Legend
User avatar

Joined: Fri Apr 24, 2009 2:02 am
Posts: 29240
Location: Guantanamo Bay (thanks bobbdobbs)
Reply with quote
big_D wrote:
Amnesia10 wrote:
HeatherKay wrote:
Adobe's labyrinthine updating process seriously annoyed me. Who creates an installer that has to download a package, unpack it, run it to then download the proper installer? Who then builds an installer that coughs up two dialog boxes, but the one you have to dismiss first is UNDER the top one? :|

After umpteen attempts to update Acrobat Pro, I deleted the entire package completely. I've not looked back. No more annoying nagging about another tweak or bug fix, no more crashing and memory hogging.

Once we rid the world of Flash as well, I will be happy. ;)

So do mac users even need Adobe reader on their system at all? They can be read with preview. Thanks in advance.

It doesn't support all features of the PDF standard, which is also why it isn't as vulnerable as some of the other readers.

I believe, it doesn't support form filling and saving, for example, or embedded Flash, for example. The latter is a very questionable feature!

I do not need those so I might as well remove it. Even with the two exploits you mentioned in preview, which I think Apple have patched already.

_________________
Do concentrate, 007...

"You are gifted. Mine is bordering on seven seconds."

https://www.dropbox.com/referrals/NTg5MzczNTk

http://astore.amazon.co.uk/wwwx404couk-21


Thu Sep 09, 2010 2:15 pm
Profile
Has a life
User avatar

Joined: Wed Apr 29, 2009 3:03 pm
Posts: 88
Location: * out of my tree *
Reply with quote
HeatherKay wrote:
After umpteen attempts to update Acrobat Pro, I deleted the entire package completely. I've not looked back. No more annoying nagging about another tweak or bug fix, no more crashing and memory hogging.


Out of interest Heather, what do you use for checking PDFx/1a compliance (or whatever standard your printers specify) etc, or for fixing non compliant print pdfs instead of Acrobat Pro?

I've only recently upgraded to CS3 and seriously dislike Acrobat/Distiller 8 compared to 7 but am soldiering on in the interests of being a bit less hopelessly out of date...

Just beginning to prefer INDD to QX so all is not lost ;)


Thu Sep 09, 2010 3:44 pm
Profile
Display posts from previous:  Sort by  
Reply to topic   [ 25 posts ]  Go to page 1, 2  Next

Who is online

Users browsing this forum: No registered users and 11 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group
Designed by ST Software.