Adobe Reader Vulnerability

Started by Atomm · 2 posts · 435 views

  1. #1
    This one got me. Luckily I was running a virus program, but even then it was a pain to clean up.

    Overview

    Vulnerabilities in Adobe Reader and Acrobat may allow an attacker

    to take control of your computer. Adobe has released Security

    Bulletin APSB09-07, which describes the issues.

    Solution

    Update

    Adobe has released updates to address this issue. Users are

    encouraged to read Adobe Security Bulletin APSB09-07 and update

    vulnerable versions of Adobe Reader and Acrobat.

    Disable JavaScript in Adobe Reader and Acrobat

    Disabling Javascript may prevent some exploits from resulting in

    code execution. Acrobat JavaScript can be disabled using the

    Preferences menu:

    * Open the Edit menu.

    * Select Preferences.

    * Choose JavaScript.

    * Un-check Enable Acrobat JavaScript.

    Disable the display of PDF documents in the web browser

    Preventing PDF documents from opening inside a web browser will

    partially mitigate this vulnerability. This workaround may also

    mitigate future vulnerabilities.

    To prevent PDF documents from automatically being opened in a web

    browser, do the following:

    * Open Adobe Acrobat Reader.

    * Open the Edit menu.

    * Choose the Preferences option.

    * Choose the Internet section.

    * Un-check the Display PDF in browser check box.

    Do not access PDF documents from untrusted sources

    Do not open unfamiliar or unexpected PDF documents, particularly

    those hosted on websites or delivered as email attachments. See

    Cyber Security Tip ST04-010.

  2. #2
    good post.

    I generally use Foxit reader which is quicker and is integrated with firefox. I wonder if that has a similar vulnerability...