PDA

View Full Version : Acrobat Reader zero day exploit


PrntRhd
02-20-2009, 10:32 PM
Fully patched Reader 8 and 9 are vulnerable:
http://www.theregister.co.uk/2009/02/20/adobe_reader_exploit/
http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20090219

Adobe says March 11 is their best guess for a patch. In the meantime, turn off Adobe Javascript in the Reader. (A good practice anytime BTW)
Acrobat JavaScript can be disabled in the General preferences dialog (Edit > Preferences >Acrobat JavaScript).

FoxIt is looking at their reader to see if vulnerable too.

classicsoftware
02-20-2009, 11:02 PM
Or better yet, DON'T USE Acrobat Reader. It is the most attacked program on the Internet. It's on every PC, it's never updated. If you have Acrobat Reader this is the way the bad guys see you:

https://www.msu.edu/~socomm/bullseye.gif

mjc
02-20-2009, 11:16 PM
Great...just great.

awaj
02-21-2009, 12:37 AM
I am glad I use Fox-it... What are the chances Fox-it is plagued as well?

PrntRhd
02-21-2009, 01:07 AM
Fox-It reader also has a FoxIt Javascript setting inside it, turn it off.

The zero day exploit for Adobe has nothing to do with the javascript but the application will simply crash without the infection taking place vs crashing and being infected if you do nothing.

Paul Komski
02-21-2009, 03:58 AM
Fox-It reader also has a FoxIt Javascript setting inside it, turn it off.You need Foxit v 3 to be able to turn off the setting.

Sylvander
02-21-2009, 08:56 AM
1. Updated Foxit to v3.0 and disabled "Javascript actions".

2. Are any of the updates displayed in red worth installing?
.

PrntRhd
02-21-2009, 11:33 AM
You need Foxit v 3 to be able to turn off the setting.

Agreed, also note that the Foxit reader v3 update fixed some critical security concerns with earlier versions.

Acrobat Reader v 7,8, & 9 may have the settings on the Adobe side, don't know about v6. Reader 5 did not have the js setting.

Sylvander,
The plugins are extra cost options in Foxit.
See the bottom third of the page here:
http://www.foxitsoftware.com/pdf/rd_intro.php

PrntRhd
02-22-2009, 02:44 PM
Just an update, Foxit is not currently susceptible to the current exploits but Foxit is looking at how it works to keep them from being targets in the future.

PrntRhd
02-23-2009, 11:19 PM
Several security vendors believe the exploits started showing up November-December 2008. Several AVs now detect the current trojan program being loaded by the exploit.

mjc
03-05-2009, 01:26 PM
This just gets worse...

http://blog.didierstevens.com/2009/03/04/quickpost-jbig2decode-trigger-trio/

PrntRhd
03-11-2009, 03:22 AM
Fixed version 9.1.0 is available now but does not show up in Adobe updater.
It can be installed on top of the existing version, the installer removes the old version.
(for those who are running the Adobe Reader 9)
http://www.adobe.com/support/security/bulletins/apsb09-03.html