Graphic Design Blog > A New Twist to the Adobe Vulnerability - ReadWriteWeb

[ReadWriteWeb] "Under the right circumstances, a Windows Explorer Shell Extension will read the PDF document to provide extra information, and in doing so, it will execute the buggy code and trigger the vulnerability. Just like it would when you would explicitly open the document," Stevens explained.

Previous [Previous] Adobe Events at SXSW | Ryan Stewart - Rich Internet Ap...

Next [Next] 5 Simple Ways to Improve Web Typography | Webdesigner Dep...

Some related posts from Technorati and Google.

[Geek-News.Net] Geek-News.Net: Foxit PDF Viewer Shares Adobe Reader Flaw: the creators of Foxit PDF Viewer, a great alternative to Adobe Reader, have released three critical bug patches today. One of which is related to the same JBIG2 image compression format vulnerability found to affect .

[Blippitt] Warning: New Adobe Vulnerability | Blippitt: The exploit can be triggered by hovering over the PDF document, single clicking on it, or viewing the thumbnail. Adobe acknowledged this vulnerability back February 19 and has admitted that it’s a major issue.

[Maildir.net] Vuln: Adobe Acrobat and Reader PDF File Handling JBIG2 Image ...: Adobe Acrobat and Reader PDF File Handling JBIG2 Image Remote Code Execution Vulnerability.

[Didier Stevens] Quickpost: /JBIG2Decode Trigger Trio « Didier Stevens: [...] If you’ve been living in fear of opening any suspicious PDF files since we let you know about a still-unpatched bug in Adobe Acrobat that could expose your PC to a malware infection, we’ve got some bad news for you: it turns out that, due to how the bug is integrated into the software, it’s possible for malware authors to still get into your system, even if you never actually open an infected file. [...]

i-penny: Didier Stevens, an IT security consultant last week demonstrated that simply viewing the folder containing .Adobe acknowledged this vulnerability in all versions of Adobe Reader on February 19, 2009 and categorized it as a critical issue.

[TechNews AM] A New Twist to the Adobe Vulnerability ... (ReadWriteWeb ...: Didier Stevens, an IT security consultant last week demonstrated that simply viewing the folder containing compromised PDF documents within Microsoft's Windows Explorer is enough to launch the exploit. It appears that this is due to Adobe's shell extension for Windows Explorer which allows the malicious code to be invoked in three ways;

[Governmentsecurity.org] Adobe PDF Exploit Code Analysis | Governmentsecurity.org: Websense® Security Labsâ™ ThreatSeekerâ™ Network has been monitoring [ 1 2 3 ] the malicious use of the now widely known zero-day vulnerability (CVE-2009-0658) affecting Adobe Reader 8.x and 9.x since last week. Adobe has released a security bulletin APSA09-01 describing the vulnerability and has stated that it will have a fix out by March 11th.

[Library Jobs, careers, placement, recruiting | LibGig - Your Career, Your Community] Adobe Vulnerability: A Critical Issue | Library Jobs, careers ...: If you think it is safe to download PDF documents and view them once Adobe finally releases its patch next week, think again. Didier Stevens, an IT security consultant .

[PC Sympathy] No User Action Required In Newly Discovered PDF Attack - PC Sympathy: a malicious PDF file can trigger an attack that exploits the new, unpatched zero-day flaw in Adobe Reader, a researcher has discovered. Didier Stevens, a researcher and IT security consultant with Contrast Europe NV, today released a proof-of-concept demonstration that shows how a file infected with the Adobe flaw can trigger a new attack when the machine uses Windows Indexing Services.

[CA Security Advisor Research Blog] Malicious PDF Server Alive and Kicking - CA Security Advisor ...: Find out what our research team is saying about the latest security threats in the CA Security Advisor blog .The PDF file contains embedded dynamic JavaScript that exploits an older Adobe security flaw: .

[Latest Blog Entires From WebSense Security Labs] Adobe PDF Exploit Code Analysis - Security Labs Blog: Stay on top of the threats as they arise - Subscribe to the Websense Security Labs RSS feeds, or sign up for our free email.

[Computerworld] Computerworld > Unpatched PDF bug poses growing threat, say ...: Adobe has acknowledged that its advice to disable JavaScript wouldn't be a panacea. In an interview last week, Brad Arkin, Adobe's director for product security and privacy, admitted that only the forthcoming patch would completely protect users.

[Internet Security Zone Blog] Internet Security Zone Blog: Adobe Acrobat PDF vulnerability is ...: The traffic cop is one of the few technologies out there that can stop drive-by downloads.  And this one is *the* only one at this time that works automatically (the others require you to change the way you download files and manage your file system).

[ReadWriteWeb] FoxIt PDF Reader Security Patches Now Available - ReadWriteWeb: The Foxit and Adobe bugs are unrelated, however, except for the fact that they are both in the code that parses JBIG2 images, said Thomas Kristensen, chief technology officer at Secunia, the Danish company that reported the flaw to Foxit. "It is a completely different vulnerability related to JBIG2,"

[Verizon Business Security Blog] Verizon Business Security Blog » Blog Archive » PDF Security ...: Disable rendering of PDFs in the browser at all. This is another measure forcing the writing of a downloaded PDF to disk before it’s opened thereby giving AV a better chance to detect and block an attack.

Reflected tags on Technorati: Blog, , , , ,