The Steel Guitar Forum Store 

Post new topic New Adobe Reader and Acrobat Vulnerabilities
Reply to topic
Author Topic:  New Adobe Reader and Acrobat Vulnerabilities
Wiz Feinberg


From:
Mid-Michigan, USA
Post  Posted 29 Apr 2009 10:28 am    
Reply with quote

There are two brand new zero day vulnerabilities in Adobe's Acrobat and Reader software. The proof of concept code has been published and Adobe is going to work on a patch. See my blog article titled New zero-day JavaScript exploit targets Adobe Reader for the details.

These vulnerabilities affect all versions of Reader and Acrobat, including the recently updated versions 8.14 and 9.1, on all operating system platforms (Windows, Mac, Linux, Unix, etc). To be exploited one would have to be tricked into opening a specifically crafted pdf file, in an unpatched version of Reader or Acrobat. Users operating with less than Administrator privileges would be less impacted, unless they opened the malware by using "Run as Administrator."

Until Adobe releases a patched version of Reader and Acrobat, you can stay protected against these exploits by disabling JavaScript in them. To do so, follow these steps:

  1. Launch Acrobat or Adobe Reader.
  2. Select Edit>Preferences
  3. Select the JavaScript Category
  4. Uncheck the ‘Enable Acrobat JavaScript’ option
  5. Click OK

Be especially cautious about opening pdf files in email attachments or on websites.
_________________
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
View user's profile Send private message Send e-mail Visit poster's website

b0b


From:
Cloverdale, CA, USA
Post  Posted 29 Apr 2009 10:57 am    
Reply with quote

I recently saw a false positive report of a trojan downloader in a PDF file, from the virus protection software on one of the servers that I monitor. I know it was mistaken because I wrote the code that generated the PDF in question. The virus scanner deleted the file before I could examine it.

I do use Javascript in these PDF files, but I don't use the getAnnots() function. I hope that consumers don't start routinely turning off PDF Javascript, as it is a very useful feature of the format. I use it to dynamically set options in the Print Dialog for guaranteed accurate positioning when printing labels.
_________________
-𝕓𝕆𝕓- (admin) - Robert P. Lee - Recordings - Breathe - D6th - Video
View user's profile Send private message Visit poster's website

Wiz Feinberg


From:
Mid-Michigan, USA
Post  Posted 4 May 2009 7:35 pm    
Reply with quote

b0b wrote:
I hope that consumers don't start routinely turning off PDF Javascript, as it is a very useful feature of the format. I use it to dynamically set options in the Print Dialog for guaranteed accurate positioning when printing labels.

I would recommend adding a note telling your readers that JavaScript will improve their viewing experience and that no hostile code is used. With all these exploits in Acrobat and Reader many consumers and end users will disable JavaScript in Adobe products and leave it off.
_________________
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
View user's profile Send private message Send e-mail Visit poster's website

Wiz Feinberg


From:
Mid-Michigan, USA
Post  Posted 4 May 2009 7:40 pm     Adobe promises an update to fix new JavaScript vulnerability
Reply with quote

Adobe Systems expects to have patches ready to fix the latest flaws in Acrobat and Reader by next week.

Quote:
"We are in the process of fixing the issue and expect to make available product updates for the relevant supported Adobe Reader and Acrobat versions and platforms by May 12th, 2009," wrote David Lenoe, a security program manager, on Adobe's security blog.


The update will fix the problem in versions 7.x, 8.x and 9.x for Reader and Acrobat on Windows, versions 8.x and 9.x of Reader and Acrobat for Macintosh, and Reader versions 8.x and 9.x for Unix. It will repair bug CVE-2009-1492, which concerns Adobe's implementation of JavaScript in Reader and Acrobat.

You can obtain the updates for your Adobe products by running the Secunia Online Software Inspector tomorrow afternoon, or afterward.
_________________
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
View user's profile Send private message Send e-mail Visit poster's website

John Cipriano


From:
San Francisco
Post  Posted 7 May 2009 12:59 am    
Reply with quote

Wiz, you don't have the registry key handy for disabling JS in Reader, do you? I need to do it on a bunch of machines. If not, no biggie, I'll poke around.

Reader is a huge hassle to deploy, btw. It's packed in a dumb proprietary format, unlike a regular MSI. You have to get a program from Adobe to edit the package, and they make you go through an approval process. Then you edit the settings and the installer ignores some of them anyway...and which ones get ignored (whether or not to auto-update, for example) changes with each version.
View user's profile Send private message Send e-mail

Wiz Feinberg


From:
Mid-Michigan, USA
Post  Posted 7 May 2009 6:43 am    
Reply with quote

John Cipriano wrote:
Wiz, you don't have the registry key handy for disabling JS in Reader, do you?

John;
I found that each version of Reader has its own key under the main "HKCU\Software\Adobe\Acrobat Reader" key and each sub-version has a JSPrefs subkey where you can change the DWord value to 0, as in this sample for Reader 9.0:

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\JSPrefs]
"bConsoleOpen"=dword:00000000
"bEnableGlobalSecurity"=dword:00000001
"bEnableJS"=dword:00000000
"bEnableMenuItems"=dword:00000000


Note that the JS Prefs must be set for each logged on user. I did not see a universal JS key in the Adobe Local Machine section.
_________________
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
View user's profile Send private message Send e-mail Visit poster's website

John Cipriano


From:
San Francisco
Post  Posted 7 May 2009 1:05 pm    
Reply with quote

Of course they put it there. That's exactly where I can't get to with a simple remote registry operation, which means I have to start inventorying all the installations and make custom logon scripts. Fun!

Thanks for looking that up, Wiz.
View user's profile Send private message Send e-mail


All times are GMT - 8 Hours
Jump to:  

Our Online Catalog
Strings, CDs, instruction,
steel guitars & accessories

www.SteelGuitarShopper.com

Please review our Forum Rules and Policies

Steel Guitar Forum LLC
PO Box 237
Mount Horeb, WI 53572 USA


Click Here to Send a Donation

Email admin@steelguitarforum.com for technical support.


BIAB Styles
Ray Price Shuffles for
Band-in-a-Box

by Jim Baron
HTTP