Annotations Have the Last Word: Adobe Reader PDF Makes Mac OS Vulnerable

Posted: May 23, 2009 | Comments: 0 | Views: 173 | Bookmark and Share

You could be getting more than you bargained for when you download a PDF or receive one as an email attachment. PDFs can run scripts upon opening them and could potentially compromise your system.

Adobe Systems Inc. confirmed the existence of two new vulnerabilities in their Adobe Acrobat Reader application. The news was announced May 4 by Trustwave and other security agencies which stated that Adobe expects to release patches by May 12, 2009. The vulnerabilities involve JavaScript functions that 'getAnnots ()' (CVE-2009-1492) and spell.customDictionaryOpen (CVE-2009-1493). According to Secunia.com the 'getAnnots ()' function is a JavaScript API in Acrobat Reader and Acrobat that allows remote assault to cause a denial of service through memory corruption or execute an arbitrary code via a PDF that contains that annotation. This is conducted through an OpenAction entry using JavaScript code that issues a series of crafted integer arguments or calls.

The customDictionaryOpen spell method is also a JavaScript API that affects Adobe Reader 8.x - 9.1 running primarily on Linux System. It allows remote hackers to deny services through a memory corruption and, similar to the 'getAnnots', may be executed through an arbitrary code via a PDF. Mac users don't have to be too concerned about the customDictionaryOpen function as this is mainly something that will come up using Linux. The most troubling out of the two is the 'getAnnots ()'.

These vulnerabilities cause a Macintosh-based Acrobat Reader versions 9.x - 8.x and Acrobat 9.x - 8.x to crash and have the potential to allow a hacker to attack and take control of a vulnerable system. Simply disabling JavaScript will not resolve anything; it only disables the vulnerable JavaScript component but does not reduce system compromise. The United States Computer Emergency Readiness Team (US-CERT) has recommended the following precautions for those that have or yet to encounter these PDFs.

Do not open unsolicited PDF files from distrusted or suspicious sources; switch your default PDF handler to Preview for the time being; and disable Adobe Reader JavaScript Preferences to prevent hackers from exploiting system vulnerabilities. To do this:

(1) Launch Adobe Acrobat Reader
(2) Select Edit from the Menu Bar
(3) Select Preferences
(4) Select the Internet Tab
(5) Uncheck the "Display PDF in Browser"

In addition, prevent your default browser (Internet Explorer, Firefox, Safari, etc.) from automatically opening PDF documents. The installer that loads Adobe Reader and Acrobat configures any one of your browsers to open a PDF file without any user interaction. To disable the browser from displaying of PDF documents:

(1) Launch Adobe Acrobat Reader
(2) From the main Menu select Edit
(3) Select Preferences, Click on the Internet tab
(4) Uncheck "Display PDF in browser" checkbox.

Avoiding opening PDF documents in a web browser reduces the possibility of attack. The following workaround applied to the updated version of Adobe Reader should protect against future vulnerabilities.

If you have a PC, additional preventative measures are listed at the US-CERT site that further reduce your chances of attack. Currently Adobe recognizes this as a critical issue and recommends that you follow the above listed steps and exercise common sense when opening PDF files. Please visit the Adobe Product Security Incident Response Team blog for further updates on this issue.

(ArticlesBase SC #932401)

Rate this Article
  • 1
  • 2
  • 3
  • 4
  • 5
  • 0 vote(s)
    Feedback
    RSS
    Print
    Email
    Re-Publish

    Source:  http://www.articlesbase.com/computers-articles/annotations-have-the-last-word-adobe-reader-pdf-makes-mac-os-vulnerable-932401.html

    Article Tags:

    annotations have the last word: adobe reader pdf makes mac os vulnerable

    How to Download and Install Adobe Acrobat Reader

    Learn how to Download and Install Adobe Acrobat (“PDF”) Reader in Windows. (03:27)

    Do I Need Acrobat Reader?

    PDF, (Portable Document Format) files are found all over the Internet. They are used by individuals and businesses alike. The PDF format was created by Adobe, but do you have to have Adobe Acrobat Reader on your computer in order to view PDF files? The short answer is no. Michael "Doctor File Finder" Callahan explains. (01:11)

    How to Save your Adobe PDF Settings

    Learn how to save your Adobe PDF settings. (03:04)

    How to Set the Policy on the Adobe PDF Settings

    Learn how to set the policy on the Adobe PDF settings. (02:19)

    How to Convert to Adobe PDF from the Contextual Menu

    Learn how to convert from the contextual menu to Adobe PDF. (02:05)

    MTS to iPad Converter for Mac provides Mac users a wonderful solution to convert mts, m2ts videos to iPad as well as iPod, iPhone, PSP and so forth with seamless quality and high converting speed.

    By: cindywu1215 l Computers l Feb 10, 2010

    Introduction Buying a motherboard these days is quite a difficult task since, in terms of performance, there is very little to choose between the top contenders. Brand loyalty is one route but leaves the feeling that something good could be missed out on through lack of awareness of the various offerings....

    By: Amar Mahmood l Computers l Feb 10, 2010

    Unquestionably, ecommerce software can really boost your business and your website. However, it can also be a cause for lack of sales and significant loss for you. The software may not really be the one directly responsible, but it could be the bugs in it or the difficulty in using...

    By: Jenny Calender l Computers l Feb 09, 2010

    Although printers are becoming more affordable with each passing year, the cost of maintaining them for daily use remains high. This article will teach you five ways to lower your printing costs this year.

    By: Real Writer l Computers l Feb 09, 2010 l Views: 1

    Passive Income It is becoming more and more standard practice for domains that are registered and not being used to be looked after by a domain parking service company. Although there are various reasons for this, often it is so the domain owners can earn passive income from a domain that...

    By: Tony Shapiro l Computers l Feb 09, 2010 l Views: 1

    Passive Marketing There

    By: Tony Shapiro l Computers l Feb 09, 2010 l Views: 1

    Electronics is something that has blended into our lives. The written matter that is now being read has also been written with the aid of electronics or more specifically electronic equipments. Therefore as a part of life, electronics and electronic devices and equipments hold major significance. We regularly use television,...

    By: Lijo George l Computers l Feb 09, 2010 l Views: 1

    Internet has provided innumerable benefits with not only making the world a smaller place, in terms of communication ease but has also revolutionized the concept of carrying on business not only in the local markets but in the global market scenario. Electronic commerce or simply e-commerce is the order of...

    By: Lijo George l Computers l Feb 09, 2010 l Views: 2

    You could be getting more than you bargained for when you download a PDF or receive one as an email attachment. PDFs can run scripts upon opening them and could potentially compromise your system. Adobe Systems Inc. confirmed the existence of two new vulnerabilities in their Adobe Acrobat Reader application. The...

    By: Carl Berkeley l Computers l May 23, 2009 l Views: 173

    Apple is now advertising their Mac mini as one of the first truly green computers. But what does this really mean, and how green is Apple. . .really? Don't get Mac users started. There are a million reasons why a Mac is better than a PC, and if you're...

    By: Carl Berkeley l Computers l May 10, 2009 l Views: 77

    Apple launched iTunes plus over a year ago, offering higher quality DRM-Free tracks through their iTunes store. For those of you who aren't familiar with iTunes Plus, you're probably asking what this means and perhaps even wondering how it will affect your iTunes music library. Well, the basics are pretty...

    By: Carl Berkeley l Computers l Apr 30, 2009 l Views: 601

    Don't mess with a good thing. And the iPhone is definitely a good thing. Most iPhone users will tell you they couldn't imagine living without it, but how much better can it get? How could Apple possibly cram another 100 features into the already unbelievable software included in iPhone SDK...

    By: Carl Berkeley l Computers l Apr 27, 2009 l Views: 32

    Add new Comment

     
    * Required fields
    Author Box
    Articles Categories
    All Categories
    0