You could be getting more than you bargained for when you download a PDF or receive one as an email attachment. PDFs can run scripts upon opening them and could potentially compromise your system.
Adobe Systems Inc. confirmed the existence of two new vulnerabilities in their Adobe Acrobat Reader application. The news was announced May 4 by Trustwave and other security agencies which stated that Adobe expects to release patches by May 12, 2009. The vulnerabilities involve JavaScript functions that 'getAnnots ()' (CVE-2009-1492) and spell.customDictionaryOpen (CVE-2009-1493). According to Secunia.com the 'getAnnots ()' function is a JavaScript API in Acrobat Reader and Acrobat that allows remote assault to cause a denial of service through memory corruption or execute an arbitrary code via a PDF that contains that annotation. This is conducted through an OpenAction entry using JavaScript code that issues a series of crafted integer arguments or calls.
The customDictionaryOpen spell method is also a JavaScript API that affects Adobe Reader 8.x - 9.1 running primarily on Linux System. It allows remote hackers to deny services through a memory corruption and, similar to the 'getAnnots', may be executed through an arbitrary code via a PDF. Mac users don't have to be too concerned about the customDictionaryOpen function as this is mainly something that will come up using Linux. The most troubling out of the two is the 'getAnnots ()'.
These vulnerabilities cause a Macintosh-based Acrobat Reader versions 9.x - 8.x and Acrobat 9.x - 8.x to crash and have the potential to allow a hacker to attack and take control of a vulnerable system. Simply disabling JavaScript will not resolve anything; it only disables the vulnerable JavaScript component but does not reduce system compromise. The United States Computer Emergency Readiness Team (US-CERT) has recommended the following precautions for those that have or yet to encounter these PDFs.
Do not open unsolicited PDF files from distrusted or suspicious sources; switch your default PDF handler to Preview for the time being; and disable Adobe Reader JavaScript Preferences to prevent hackers from exploiting system vulnerabilities. To do this:
(1) Launch Adobe Acrobat Reader
(2) Select Edit from the Menu Bar
(3) Select Preferences
(4) Select the Internet Tab
(5) Uncheck the "Display PDF in Browser"
In addition, prevent your default browser (Internet Explorer, Firefox, Safari, etc.) from automatically opening PDF documents. The installer that loads Adobe Reader and Acrobat configures any one of your browsers to open a PDF file without any user interaction. To disable the browser from displaying of PDF documents:
(1) Launch Adobe Acrobat Reader
(2) From the main Menu select Edit
(3) Select Preferences, Click on the Internet tab
(4) Uncheck "Display PDF in browser" checkbox.
Avoiding opening PDF documents in a web browser reduces the possibility of attack. The following workaround applied to the updated version of Adobe Reader should protect against future vulnerabilities.
If you have a PC, additional preventative measures are listed at the US-CERT site that further reduce your chances of attack. Currently Adobe recognizes this as a critical issue and recommends that you follow the above listed steps and exercise common sense when opening PDF files. Please visit the Adobe Product Security Incident Response Team blog for further updates on this issue.
- Related Videos
- Related Articles
- Ask / Related Q&A




Tips on Purchasing Dell Laptop Chargers
By: orsondixon | 10/11/2009An increasing number of Dell laptop users are opting for the latter because of their incredible offers in terms of quality as well as price.
How Much Memory Is Sufficient For Your Computer?
By: Terro White | 10/11/2009In general the average computer user is of the opinion that the more RAM he has embedded into his computer system the faster and better it will operate. However this may not always be the case. When it comes to computer memory you need to know what you require and what is enough keeping your computer’s specifications in mind.
Why to have iPhone skins
By: BhratBrij | 10/11/2009This article gives you plenty of information about iPhone skins and how they can be used for protecting your iPhone from superficial damage.
Email management plays important role in your business, handle it efficiently
By: quinlanmurray | 10/11/2009Email has assumed high importance in accelerating the pace of business transactions and has become a fastest medium for communication, exchange of ideas and information. With widespread use of email in handling important and sensitive transactions, email security has become one of the critical functions of email management.
Nine Tips Prevent You from Harmful Computer Radiation
By: Felicia luo | 10/11/2009The author has collected nine effective tips for us to prevent computer radiation.
Get An Effective Online PC Support Service
By: Sarah Jones19 | 10/11/2009It is not possible for the computer users to carry their entire system to their nearest service station whenever any problem occurs. Online PC support service is launched to make them relieved and provide instant solutions to their problems.
You Can Save Your Money by Using Registry Fixer Software
By: Robert Blackmen | 10/11/2009If your PC is performing very slowly to the level that it can not be relied on, you don't have to buy a new computer immediately yet. If your PC freezes every so often, you don't have to take apart your computer hoping to fix it.
What is the Most Excellent Registry Cleaner Software?
By: Robert Blackmen | 10/11/2009If you are worried by a slow PC or worse yet, one that can come into view "frozen", then you is almost certainly dealing with Windows registry errors. In order to repair registry problems, the suggested way is to download registry cleaning software.
Annotations Have the Last Word: Adobe Reader PDF Makes Mac OS Vulnerable
By: Carl Berkeley | 23/05/2009 | ComputersYou could be getting more than you bargained for when you download a PDF or receive one as an email attachment. PDFs can run scripts upon opening them and could potentially compromise your system. Adobe Systems Inc. confirmed the existence of two new vulnerabilities in their Adobe Acrobat Reader application. The...
ITunes Plus: Is the Upgrade Worth It?
By: Carl Berkeley | 30/04/2009 | ComputersApple launched iTunes plus over a year ago, offering higher quality DRM-Free tracks through their iTunes store. For those of you who aren't familiar with iTunes Plus, you're probably asking what this means and perhaps even wondering how it will affect your iTunes music library. Well, the basics are pretty...
IPhone OS 3.0 : Exactly How Advanced is "Advanced"?
By: Carl Berkeley | 27/04/2009 | ComputersDon't mess with a good thing. And the iPhone is definitely a good thing. Most iPhone users will tell you they couldn't imagine living without it, but how much better can it get? How could Apple possibly cram another 100 features into the already unbelievable software included in iPhone SDK...