You could be getting more than you bargained for when you download a PDF or receive one as an email attachment. PDFs can run scripts upon opening them and could potentially compromise your system.
Adobe Systems Inc. confirmed the existence of two new vulnerabilities in their Adobe Acrobat Reader application. The news was announced May 4 by Trustwave and other security agencies which stated that Adobe expects to release patches by May 12, 2009. The vulnerabilities involve JavaScript functions that 'getAnnots ()' (CVE-2009-1492) and spell.customDictionaryOpen (CVE-2009-1493). According to Secunia.com the 'getAnnots ()' function is a JavaScript API in Acrobat Reader and Acrobat that allows remote assault to cause a denial of service through memory corruption or execute an arbitrary code via a PDF that contains that annotation. This is conducted through an OpenAction entry using JavaScript code that issues a series of crafted integer arguments or calls.
The customDictionaryOpen spell method is also a JavaScript API that affects Adobe Reader 8.x - 9.1 running primarily on Linux System. It allows remote hackers to deny services through a memory corruption and, similar to the 'getAnnots', may be executed through an arbitrary code via a PDF. Mac users don't have to be too concerned about the customDictionaryOpen function as this is mainly something that will come up using Linux. The most troubling out of the two is the 'getAnnots ()'.
These vulnerabilities cause a Macintosh-based Acrobat Reader versions 9.x - 8.x and Acrobat 9.x - 8.x to crash and have the potential to allow a hacker to attack and take control of a vulnerable system. Simply disabling JavaScript will not resolve anything; it only disables the vulnerable JavaScript component but does not reduce system compromise. The United States Computer Emergency Readiness Team (US-CERT) has recommended the following precautions for those that have or yet to encounter these PDFs.
Do not open unsolicited PDF files from distrusted or suspicious sources; switch your default PDF handler to Preview for the time being; and disable Adobe Reader JavaScript Preferences to prevent hackers from exploiting system vulnerabilities. To do this:
(1) Launch Adobe Acrobat Reader
(2) Select Edit from the Menu Bar
(3) Select Preferences
(4) Select the Internet Tab
(5) Uncheck the "Display PDF in Browser"
In addition, prevent your default browser (Internet Explorer, Firefox, Safari, etc.) from automatically opening PDF documents. The installer that loads Adobe Reader and Acrobat configures any one of your browsers to open a PDF file without any user interaction. To disable the browser from displaying of PDF documents:
(1) Launch Adobe Acrobat Reader
(2) From the main Menu select Edit
(3) Select Preferences, Click on the Internet tab
(4) Uncheck "Display PDF in browser" checkbox.
Avoiding opening PDF documents in a web browser reduces the possibility of attack. The following workaround applied to the updated version of Adobe Reader should protect against future vulnerabilities.
If you have a PC, additional preventative measures are listed at the US-CERT site that further reduce your chances of attack. Currently Adobe recognizes this as a critical issue and recommends that you follow the above listed steps and exercise common sense when opening PDF files. Please visit the Adobe Product Security Incident Response Team blog for further updates on this issue.
- Related Videos
- Related Articles
- Ask / Related Q&A




Laptop Skins: Not less than a revolution
By: BhratBrij | 04/12/2009This article is a help for those who are looking for knowledge about laptop skins and all things related to it as how and where to apply.
Change IP to Guard Your Privacy on the Internet
By: Andrew Virender | 04/12/2009To change IP addresses has recently become quite common in households and businesses. Because of a lot of problems which usually root from the internet, keeping your privacy in the cyberspace is very important. Of course, everybody would want to keep their confidential and personal records private. However, with the continuously developing technology, even simple IP addresses can be a way for other people to steal your identity.
Crucial factors to think when selecting Laptop Skins
By: BhratBrij | 04/12/2009Laptop skins have been appreciated by all people engaged in different fraternities. Reading this article, you will understand 4 important factors to take care while buying laptop skins.
Blackberry Pearl Skins and Blackberry Tour Skins as Fashionable Accessories
By: BhratBrij | 04/12/2009You have the means of protecting your cell phone at your fingertips in the shape of cast vinyl Blackberry Pearl Skins and Blackberry Tour Skins. So take full advantage of them.
Driving factors for recession proof Smartphones' sales
By: pirumandal | 04/12/2009The multimedia factor and wide variety of entertainment that Smartphones offer are the basic reasons for their popularity. The other reasons for the success of Smartphones in the market are discussed in the feature.
Talking About the Environment on Your Hot New Phone
By: Ezra Drissman | 04/12/2009It would only make sense that eventually those who think in green would get to talk that way. While there are other phones that can qualify as fairly eco-friendly, the Motorola A45 Eco has actually earned the Carbonfund.org's carbon neutral certification and has more features than many other comparable phones.
HIRE JOOMLA DEVELOPERS
By: prachi upadhyay | 04/12/2009Hiring the Offshore Dedicated Joomla Developers is very beneficial for both, the person hiring them & the dedicated developer as well. With hiring the offshore dedicated Joomla Developers it becomes much easier for the people to work & also to save lot of time & money as well.
Is It Possible to Customize Your LG Env3 Skins and LG Env2 Skins?
By: BhratBrij | 04/12/2009If your intention is to get really stylish LG env3 skins and LG env2 skins of your choice, you can get them on plenty of websites on the Internet, quite easily.
Annotations Have the Last Word: Adobe Reader PDF Makes Mac OS Vulnerable
By: Carl Berkeley | 23/05/2009 | ComputersYou could be getting more than you bargained for when you download a PDF or receive one as an email attachment. PDFs can run scripts upon opening them and could potentially compromise your system. Adobe Systems Inc. confirmed the existence of two new vulnerabilities in their Adobe Acrobat Reader application. The...
Green Apple: Are The New Macs Really Better For The Environment?
By: Carl Berkeley | 10/05/2009 | ComputersApple is now advertising their Mac mini as one of the first truly green computers. But what does this really mean, and how green is Apple. . .really? Don't get Mac users started. There are a million reasons why a Mac is better than a PC, and if you're...
IPhone OS 3.0 : Exactly How Advanced is "Advanced"?
By: Carl Berkeley | 27/04/2009 | ComputersDon't mess with a good thing. And the iPhone is definitely a good thing. Most iPhone users will tell you they couldn't imagine living without it, but how much better can it get? How could Apple possibly cram another 100 features into the already unbelievable software included in iPhone SDK...