Technology content trusted by users in Australia and around the world.
5,013 Articles | 30,497 Posts
Select Your Edition:  
Tweakipedia
A wealth of
tech information!

AU EditionYou are located: Home > All News > News > Adobe admits JavaScript flaw in Acrobat

Adobe admits JavaScript flaw in Acrobat

By: (more) | Posted: Apr 30, 2009 6:41 pm

I talked about the flaw that allowed Vista to fall in the Pwn2Own competition this year very briefly but I never did get into much detail. But since Adobe has admitted the flaw exists in another Adobe product it is worth bringing up again.

 

The issue is JavaScript and the way that Acrobat and Flash (the plug-in for Flash and Flash Player) handle it. They just do not do so very well at all. Because of this little problem arbitrary code can be executed by Malicious JavaScript (applets) on a system through these two 3rd party applications. It was this exact flaw in the way JavaScritpt is handled by Flash that allowed Vista to be hacked. It seems that in addition to poor handling it also allows the UAC feature in Vista to be bypassed for code executed by the plug-in and the application.

 

Adobe, although they have admitted to the flaw, has not given a time line for fixing the affected applications with include Acrobat (Reader as well) 9.1, 8.1.4, 7.1.1 and earlier.

Read more here

 

Adobe admits JavaScript flaw in Acrobat

 


Initially the firm said the vulnerability only afflicted its cumbersome Reader.

 

It appears the software's execution of JavaScript is flawed, allowing attackers to run code on targeted systems or crash applications willy-nilly.

 

Adobe Reader and Acrobat versions 9.1, 8.1.4, and 7.1.1 and earlier are vulerable. Adobe said it hadn't found any live expolits yet.

 

Related Tags



Further Reading: Read and find more news at our news index page.

TweakTown News RSS FeedDo you get our news RSS feed? Get It! Got a news tip? Tell Us!

Post a Comment about this news



Check out our
RSS feeds!


Tech News Posts

View More News Posts


TweakTown Web Poll

Question: Now you have the facts, which is your next-gen gaming console?

Microsoft Xbox One

Sony PlayStation 4

I'm a PC gamer, or not interested, or buying something else

or View the Results

View More Polls

Forum Activity

View More Forum Posts

Press Releases

View More Press Releases