Computer security researchers said Wednesday they have discovered a vulnerability in Adobe Systems Inc.'s ubiquitous Acrobat Reader software that allows cyber-intruders to attack personal computers through trusted Web links.
Virtually any Web site hosting Portable Document Format, or PDF, files are vulnerable to attack, according to researchers from Symantec Corp. and VeriSign Inc.'s iDefense Intelligence.
The attacks could range from stealing cookies that track a user's Web browsing history to the creation of harmful worms, the researchers said.
The flaw, first revealed at a hacker conference in Germany over the holidays, exists in a plug-in that enables Acrobat users to view PDF files within Web browsers.
By manipulating the Web links to those documents, hackers and online thieves are able to commandeer the Acrobat software and run malicious code when users attempt to open the files, according to Ken Dunham, director of the rapid response team at VeriSign's iDefense Intelligence.
Dunham gave this hypothetical scenario: an attacker finds a PDF file on a banking Web site. The attacker creates a hostile Web site that links to the bank's PDF file. Included is malicious JavaScript code that will run on the unsuspecting user's computer once the link is clicked.
''PDF is trusted and tried and true — everyone uses it,'' Dunham said. ''But instead of just viewing the file, you've initiated script that shouldn't be executed. All you have to do is click on the PDF and the ball starts rolling.''
Representatives from Adobe did not return a call from The Associated Press on Wednesday night.
The flaw appears to target Microsoft Corp.'s Internet Explorer 6.0 Web browser and earlier versions, and Mozilla's Firefox browser, the researchers said.
They recommended that users protect themselves by upgrading Internet Explorer or changing Firefox's user options so the browser does not use the Acrobat plug-in.
Researchers said it's unclear how pervasive or harmful any future attacks might be.
''Given that it is easy to exploit, I would expect that we will see this method used considerably in the coming days and weeks, until it is resolved,'' a Symantec researcher said in a posting on a company Web log.
Flaw Found in Adobe's Acrobat PDF Format
By: AP
| Jan 04, 2007
| Ads by Google | ||
Why don't you post one?
LATEST NEWS
- Make VoIP Calls From Your iPod Touch
- Airtel Offers Online Account Management
- Bluetooth 2.2 To Be Introduced In 09
- Sanyo Releases Wi-fi Radio
- SanDisk Launches Enterprise Cruzer USB Drive
- Mirror's Edge PC Version Dated
- GRID DLC Available Now
- Fable 2 DLC Hits Xbox Live This December
- Grand Theft Auto Invading India
- Rockstar Responds to GTA IV PC Issues
| Ads by Google | ||
RELATED
Hot Searches & Keywords :
AMD
ATI
Acer
Adobe
Apple
Asus
Benq
Blackberry
Blizzard
Blu-Ray
Bluetooth
CES 2007
Canon
Capcom
Creative
DVD
Dell
E3 2007
E3 2008
EA
Electronic Arts
Facebook
Google
HP
Halo
IBM
ITunes
Intel
Internet
Ipod
LCD
LG
Linux
Logitech
Microsoft
Mobile
Mobile Phone
Mobile Phones
Motorola
Mp3
Myspace
Nintendo
Nokia
Nvidia
PC
PMP
PS2
PS3
PSP
Philips
Reliance Communications
Samsung
Sandisk
Search Engine
Skype
Smartphone
Sony
Sony Ericsson
Toshiba
Ubisoft
Valve
Vista
Voip
Website
Wii
Windows
Windows Mobile
Windows Vista
WoW
Xbox 360
Xbox Live
Xbox360
Yahoo!
Youtube
Zune
digicam
digital camera
iPhone
laptop
mp3 player
printer
social networking site
test
yahoo
| Ads by Google | ||
|
|
Sections
Products
Camcorders |
Controllers |
CPUs |
Desktop PCs |
Digital Cameras |
Digital Video Recorders |
DVD Players |
Games |
Gaming Consoles |
General |
GPS Systems |
Handhelds / PDAs |
Hard Drives |
Headphones & Headsets |
HiFi Audio Systems |
Home Theater Systems |
Input Devices |
Internet |
Laptops |
lenovo |
Low Level Components |
Mac Systems |
Mobile Phone Accessories |
Mobile Phones |
Monitors |
Motherboards |
MP3 / Audio Players |
Multi-Function Devices |
Networking |
Optical Drives |
PC Accessories |
PC Add-on Cards |
PC Cabinets |
PC Games |
Printers |
Projectors |
RAM Modules |
Scanners |
Software |
Speakers |
Telecom |
TVs |
Video Players |



