News & Information for Technology Purchasers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Enterprise I.T. Hardware Software Communications More Topics...
Hardware
Average Rating:
Rate this article:  
Adobe Patches Acrobat Security Flaw Adobe Patches Acrobat Security Flaw
By David Garrett
January 11, 2007 8:54AM

    Bookmark and Share
Adobe's Acrobat flaw caused a stir when it was first announced by researchers Stefano Di Paola and Giorgio Fedon, in large part because Acrobat has seen enormous adoption rates by companies and consumers alike. The flaw let hackers use a technique known as cross-site scripting, in which they blend malicious JavaScript with a link to a PDF file on a Web site to hijack a user's computer.
 



On Tuesday, Adobe released a patch for a security flaw that affects several of its widely used programs, including Acrobat Reader, one of the Web's most popular software titles.

In fact, the flaw affects not only Acrobat Reader, but also Acrobat Standard, Professional, and Elements in versions 7.08 and older. The most recent version of these programs -- version 8.0, which had been released at the time the flaw was discovered -- is immune. In a published statement, Adobe noted that Acrobat 3D was also at risk, but did not state which versions were affected.

The flaw let hackers use a technique known as cross-site scripting, in which they blend malicious JavaScript with a link to a Portable Document Format (PDF) file on a Web site to hijack a user's computer. The problem does not affect PDF documents themselves, and can only be used when someone attempts to retrieve a PDF document by clicking a malicious link, such as one a spammer might embed in unwanted e-mail.

The Fix

Worried users can avoid the problem by upgrading their software to version 8, the most recent release. For users who can't upgrade to version 8, Adobe has released a patch for the affected programs, allowing users to upgrade to version 7.0.9.

Further information on upgrades and patches can be found on Adobe's Web site, or simply by using the auto-update features in Adobe's software.

Adobe also offered Web designers guidance on avoiding cross-site scripting attacks that involve PDFs by changing the way they deliver those files on their Web sites.

A Victim of Success

Adobe's mishap caused a stir when it was first announced by researchers Stefano Di Paola and Giorgio Fedon, in large part because Adobe's software has seen enormous adoption rates by companies and consumers alike.

Adobe's system Relevant Products/Services for making, reading, and sending PDF documents -- in which the same document can be read by Windows Relevant Products/Services, Mac, and Unix machines -- neatly solved one of the Web's more complex data Relevant Products/Services-sharing conundrums.

But any software that's widely used by consumers and knowledge workers can be widely attacked by hackers, too, no matter what developer creates it.

"The more prevalent the software is, the more important the threat is for you within your organization to handle," said Khalid Kark, an analyst at Forrester Research. Kark noted that as software gets more popular, its "footprint for risk" grows in tandem.

Fast Turnaround

But Adobe patched the problem in roughly a week -- a fast response by nearly any yardstick. In fact, researchers who find security holes often give companies a full month to patch them before releasing their findings to the public.

"That's kind of the unsaid rule," said Kark. "If you give them a few weeks or at most a month, that should be more than sufficient to figure out what needs to get done and come out with a patch."

There are, of course, those who give companies little notice at all -- a problem that's growing, according to Kark. And there's always the phalanx of hackers who consider advance notice a courtesy that's quickly disposed of. The result? As companies work harder to protect their software, more and more could be forced to match Adobe's response time.
 

Tell Us What You Think
Your Comment:



Advertisement


 Hardware
1.   IBM Power7 Server Takes on Big Load
2.   Embattled JooJoo Tablet To Ship Soon
3.   The iPad's Potential Threat to PCs
4.   Oracle Moves To Calm Sun Customers
5.   Apple Talks To Publishers on Tablet


advertisement
The iPad's Potential Threat to PCsThe iPad's Potential Threat to PCs
Could erode sales of netbooks, tablets.
Average Rating:
Apple Talks To Publishers on TabletApple Talks To Publishers on Tablet
To include e-book titles on new device.
Average Rating:
Configuring a Notebook ComputerConfiguring a Notebook Computer
Pick processors, speed and memory.
Average Rating:


advertisement
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware Spotlight
Nvidia Auto-Switches Notebook GPU To Save Battery Life
Nvidia has taken the wraps off a notebook technology that chooses the best graphics processor for any given application and automatically routes the workload to Nvidia or Intel processors.
 
Microsoft Says Battery Woes Not Caused By Windows 7
Battery problems on Windows 7 machines are not caused by the operating system. That's the position of Stephen Sinofsky, head of the Windows division, in a long posting on the Windows engineering blog.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Enterprise Technology Spotlight
Intel Launches Quad-Core Itanium 9300 Series Processor
After two unexpected delays, Intel has launched the Itanium 9300 series, a 64-bit, quad-core processor code-named Tukwila that is expected to double the performance of its predecessor.
 
Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Hardware | Software | Communications | Network Security | Wireless Tech | Linux/Open Source
Apple/Macintosh | Microsoft/Windows | World Wide Web | Data Storage | E-Commerce | Personal Tech | Tech Trends | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.