All the latest UK technology news, reviews and analysis

PDF vulnerability lingers despite patch

by Shaun Nichols

03 Jul 2010

Comment: 1

  • Tweet this
Adobe
A workaround for Adobe's PDF blacklist has been found

Adobe is on the defensive following the discovery of a security loophole previously believed to have been patched.

The flaw, which exists in the Reader and Acrobat components, could allow an attacker to remotely execute a malicious application through code embedded in a PDF file by manipulating a warning dialogue.

Adobe had issued a patch to address the vulnerability by instituting a blacklist which could block executable files from being launched. Researchers are reporting, however, that the protections can be circumvented.

Bkis security researcher Le Manh Tung has said that simply adding quotation marks will fool the system and allow an attacker to once again post a misleading warning dialogue.

"With the quotes added, Adobe Reader will not block the execution," wrote Tung in a blog post.

"Adobe Reader version 9.3.3 has fixed the fake warning massage, but the threat of exploit code execution still remains."

Adobe has acknowledged the report and has issued a blog post of its own on the matter. Director of product security and privacy Brad Arkin said that the company is keeping the launch component active, but will look at updating the blacklist to protect against future attacks.

"While blacklist capabilities alone are not a perfect solution to defend against those with malicious intent, this option reduces the risk of attack while minimising the impact on customers relying on workflows that depend on the launch functionality," Arkin wrote.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

25%

1%

11%

63%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Helpdesk/Service Analyst x3

Helpdesk/Service Analyst x 3 3 Month Contract...

2nd/3rd line Technical support EMEA (FRENCH SPEAKING)

French Technical support Specialist (2/3rd Line) CCNA...

ECM Project Manager - CMS, Document Management, Web 2.0

ECM Project Manager - CMS, "Document Management", Web...

PRESALES CONSULTANT/TECHNICAL CONSULTANT (CCNA, MCITP)

Skills - Presales, Consultant / Consultancy, Technical...

To send to more than one email address, simply separate each address with a comma.