Author Topic: Adobe Reader vulnerability  (Read 3783 times)

0 Members and 1 Guest are viewing this topic.

ednsandy

  • Guest
Adobe Reader vulnerability
« on: March 03, 2009, 12:52:32 AM »
Does an updated data base and Avast program catch these problems if an infected .pdf file is scanned before opening?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89057
  • No support PMs thanks
Re: Adobe Reader vulnerability
« Reply #1 on: March 03, 2009, 01:39:46 AM »
The vulnerability is in the reader being exploited and not so much the .pdf files so you should always ensure that acrobat is fully up to date, though I gave up on it some time ago. It doesn't seem like very long from when one hole is closed up than another is discovered.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Adobe Reader vulnerability
« Reply #2 on: March 03, 2009, 01:43:26 AM »
Also, set opened files to be scanned (the default) in the Standard Shield settings.
The best things in life are free.

Avastfan1

  • Guest
Re: Adobe Reader vulnerability
« Reply #3 on: March 03, 2009, 09:16:10 AM »
There is a simple yet 100% effective security update for Adobe Reader:

http://mirrors.foxitsoftware.com/pub/foxit/reader/desktop/win/3.x/3.0/enu/FoxitReader30_enu_Setup.exe

Faster, much more secure and a lot more stable as a program.

Enjoy!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89057
  • No support PMs thanks
Re: Adobe Reader vulnerability
« Reply #4 on: March 03, 2009, 03:42:53 PM »
I don't know about much more secure, that isn't proven.

However, it certainly isn't such a big target as acrobat PDF reader is the virtual default industry standard PDF reader, so exploiting that is much more productive. That said I have been using foxitreader for a considerable time as it is no bloated monster that acrobat has become.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Alan Baxter

  • Guest
Re: Adobe Reader vulnerability
« Reply #5 on: March 03, 2009, 06:53:14 PM »
Thank you for the Foxit Reader recommendation, David.  I'll use that instead of Adobe and see how it goes.  There are no Secunia security advisories for it, i.e. if there are any vulnerabilities, they haven't been reported.  I disabled JavaScript in Foxit's preferences, just in case there's ever an exploit that takes advantage of that.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Adobe Reader vulnerability
« Reply #6 on: March 03, 2009, 07:28:04 PM »
Hi DavidR,

Proven, proven: http://forums.foxitsoftware.com/showthread.php?p=28255
And that is also a reassuring thought for Alan Baxter.

The matter with Open Software is that when the cat is out of the bag, it is. When it is not we know about it at the same time it is found up.
With Closed Software when the cat is out of the bag we know it, but we do not know how long it was out of the bag before we knew of that fact. That is the big difference between Adobe and FoxitReader, no security through obscurity,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89057
  • No support PMs thanks
Re: Adobe Reader vulnerability
« Reply #7 on: March 03, 2009, 08:44:21 PM »
Sorry but I wouldn't call that total proof, but one area dealing with one exploit assuming that the user has also downloaded the JBIG2 decoder, which wasn't installed by default on my version and presumably others.

As you may be gathering, I'm a trusting sod, not :P
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Adobe Reader vulnerability
« Reply #8 on: March 03, 2009, 09:05:23 PM »
Hi DavidR,

That is why I am always trying to go to the bottom of it, just for that vital bit of  information. In my Foxit version I have that dll running...

 "Trust nothing and no one" always has been a good guideline in what we are trying to do here. There are two things with Windows and third party software - do not take anything for granted. And I know you aren't Alice in Wonderland nor the Easter Bunny, right?

pol
« Last Edit: March 03, 2009, 09:40:17 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!