NEWS

Adobe Acrobat Wins Bug of the Month

Written by Bruce Kratofil
Published February 05, 2007
Part of BugBlog

Every month the BugBlog picks its Bug of the Month, representing the most significant bug found in the past month. Sometimes, the bug will be the one which could potentially cause the most damage; sometimes it will be the bug which affects the most users. And sometimes, it will be the bug that is just the most interesting bug. This bug will be selected either from the free Bug of the Day, or from the subscription-only BugBlog Plus.

This month the Bug of the Month goes to Adobe for the problems in Adobe Reader and Adobe Acrobat. The first report was on January 4:

There are a number of bugs in the Adobe Acrobat Plug-In for browsers, and in the free Adobe Reader 6 and 7. A malicious website may be able to carry out cross-site scripting attacks because the browser plug-in doesn't correctly validate URI parameters. There's no official word from Adobe, although US CERT says that it appears the bugs were fixed in Adobe Reader 8. Read their report. Stefano Di Paola, Giorgio Fedon, and Elia Florio are credited with finding these bugs. UPDATE: Adobe now has a bulletin online.

The reason for the update in that bug report was that Adobe didn't have a bulletin online when the US CERT report (and BugBlog item) was first reported. The next BugBlog item came on January 10:

Adobe now has a patch for the security problems in Adobe Reader and Acrobat 7.0.8 and earlier versions. The bugs, which were in the 1/4 BugBlog, may allow both cross-site scripting attacks and the ability of the attackers to take over the victim's computer. Adobe's earlier advice was to upgrade to the Adobe Reader 8. They now have a patch that will fix version 7.0.8 of the Reader as well as Acrobat Elements, Standard, and Professional. (Good news for those latter users, since the upgrade from 7.0.8 to 8.0 will normally not be free). Get the patch.

Why this bug? First, because of the wide-spread use of Adobe Acrobat. Just about everyone has either the Adobe plug-in for their browser or the Adobe Reader software installed. The Adobe Acrobat software, either Elements, Standard or Professional, is not as universal, but still has a rather large installed base. Thus, the bug affects lots of users.

Second, this points out that PDF documents can cause problems, which is unfortunate because at this time many people may be suggesting PDFs as a replacement strategy for exchanging documents. The reason you may need a replacement strategy is that there are currently four unpatched zero-day bugs affecting Microsoft Word (see the January Bug of the Month for coverage of this), and you may have reason to be a little paranoid about Word docs that show up as email attachments. While you may wish to suggest PDFs as a replacement, you cannot suggest that they themselves never have security problems.

Bruce Kratofil blogs on bugs and other things that can go wrong with your computer at The BugBlog, and writes about computers and economics at BJK Research
Keep reading for information and comments on this article, and add some feedback of your own!
Adobe Acrobat Wins Bug of the Month
Published: February 05, 2007
Type: News
Section: Sci/Tech
Filed Under: Sci/Tech: Computers, Sci/Tech: Internet, Sci/Tech: Programming, Sci/Tech: Software
Part of a feature: BugBlog
Writer: Bruce Kratofil
Bruce Kratofil's BC Writer page
Bruce Kratofil's personal site
Spread the Word
Like this article?
Email this
Submit to del.icio.us Save to del.icio.us
RSS Feeds
All RSS Feeds (240+)
Comments on this article
Articles in this series
BC articles by Bruce Kratofil
Sci/Tech: Computers
Sci/Tech: Internet
Sci/Tech: Programming
Sci/Tech: Software
All Sci/Tech Articles
Bruce Kratofil's personal weblog
All News articles
All BC articles
All BC Comments

Comments

#1 — February 6, 2007 @ 00:50AM — John Dowdell [URL]

Hi, any threat to your computer's security or to your own privacy is serious, and must be guarded against. But this particular situation may not be as grim as readers might think, particularly if you already keep up to date on your internet software.

Older versions of Adobe Reader could indeed pass JavaScript requests to your browser, leading them to potential cross-domain confusion, but last year's free Adobe Reader 8 had closed off that potential exploit before it became publicized.

Not everyone with internet access is a nice person. Keeping up-to-date with your internet software is a good way to keep them from taking advantage of you. Thanks in advance if you can help spread this word!

tx, jd/adobe

#2 — February 6, 2007 @ 07:26AM — ProfEssays

I hope that other programs are not so vulnerable.

Want comments emailed to you? No spam, promise! Address:

Add your comment, speak your mind

(Or ping: http://blogcritics.org/mt/tb/59215)

Personal attacks are not allowed. Please read our comment policy.





Remember Name/URL?

Please preview your comment!

Fresh
Articles
Fresh
Comments