Jump to content


Adobe Reader Vulnerability


14 replies to this topic

#1 OFFLINE   Nullack

    Member

  • Members
  • PipPip
  • 25 posts

Posted 24 December 2009 - 11:47 PM

http://secunia.com/advisories/37690/

Not good. I tried to use foxit reader but found the interface and ads an annoyance.

#2 OFFLINE   Corona

    Power Member

  • Members
  • PipPipPipPip
  • 1,932 posts
  • Gender:Male
  • Location:US

Posted 25 December 2009 - 05:33 AM

I just avoid PDFs like the bubonic plague. Nothing worthwhile is encrypted on them. They're garbage.

#3 OFFLINE   abu aufa

    Power Member

  • Members
  • PipPipPipPip
  • 694 posts
  • Gender:Male
  • Location:Ardhillah

Posted 26 December 2009 - 03:36 AM

TRY PDF X-Change Viewer

Spyware free and no ASK toolbar ;) Adobe is my PAST and Foxit has ASK Toolbar bundled in its installer,forget it :(

#4 OFFLINE   marmite

    Relax, it's only ones and zeros!

  • Members
  • PipPipPipPip
  • 877 posts
  • Location:UK

Posted 26 December 2009 - 01:52 PM

View PostNullack, on Dec 24 2009, 11:47 PM, said:

Fix is due out on 12 Jan. In the meantime just go into the Adobe Reader's Edit/Preferences and turn off JavaScript - it's very rarely needed.

View PostCorona, on Dec 25 2009, 05:33 AM, said:

I just avoid PDFs like the bubonic plague. Nothing worthwhile is encrypted on them. They're garbage.
Avoid them? It's a good format. A lot of stuff that I want or need to read is published in PDF format. I also find it a good way of securing the content of published documents. Yes, the Adobe reader has been heavily targeted by malware but that doesn't devalue the document format.

As to 'PDFs being garbage' ... that's a bit of a nonsensical statement!

#5 OFFLINE   Corona

    Power Member

  • Members
  • PipPipPipPip
  • 1,932 posts
  • Gender:Male
  • Location:US

Posted 26 December 2009 - 10:11 PM

Okay, I exaggerated. But every app Adobe makes is so bloated, and I find navigation in PDF readers annoying. If it's their attempt at a limited 'browser' app to read pages with pictures, it's pretty funky. If you're comfortable using it, I got no problem with that. I guess it's just not my taste.

#6 OFFLINE   marmite

    Relax, it's only ones and zeros!

  • Members
  • PipPipPipPip
  • 877 posts
  • Location:UK

Posted 30 December 2009 - 04:22 PM

And the rumour mill suggests it ain't gonna get any better for a while ... http://www.theregister.co.uk/2009/12/29/se...edictions_2010/ ... so keep yer reader / flash up-to-date in the coming year ;)

[Quick plug for checking your software patch state with Secunia PSI ... http://secunia.com/v...nning/personal/ :)]

#7 OFFLINE   Andavari

    Captain Spectacular

  • Moderators
  • 13,330 posts
  • Gender:Male
  • Location:Shadow Moses

Posted 30 December 2009 - 06:41 PM

View Postabu aufa, on Dec 25 2009, 09:36 PM, said:

TRY PDF X-Change Viewer

Spyware free and no ASK toolbar ;) Adobe is my PAST and Foxit has ASK Toolbar bundled in its installer,forget it :(
I just installed it and I like it, removed an old clean version of Foxit in the process to which by now had to have vulnerabilities. PDF X-Change Viewer has more features than I would ever possibly use, it can't be called basic, and should work very good as a complete Adobe or Foxit replacement.
Complexity of incoherent design.

#8 OFFLINE   marmite

    Relax, it's only ones and zeros!

  • Members
  • PipPipPipPip
  • 877 posts
  • Location:UK

Posted 30 December 2009 - 06:49 PM

View PostAndavari, on Dec 30 2009, 06:41 PM, said:

... and should work very good as a complete Adobe or Foxit replacement.
Just don't forget updates to Flash player ... so many sites use this these days.

#9 OFFLINE   abu aufa

    Power Member

  • Members
  • PipPipPipPip
  • 694 posts
  • Gender:Male
  • Location:Ardhillah

Posted 31 December 2009 - 02:45 AM

View PostAndavari, on Dec 31 2009, 01:41 AM, said:

I just installed it and I like it, removed an old clean version of Foxit in the process to which by now had to have vulnerabilities. PDF X-Change Viewer has more features than I would ever possibly use, it can't be called basic, and should work very good as a complete Adobe or Foxit replacement.

yes,it was completely replaced them. Loading faster and portable version also available,here

and don't forget to check new version via Live Update if available, at least every two weeks ;)

#10 OFFLINE   Andavari

    Captain Spectacular

  • Moderators
  • 13,330 posts
  • Gender:Male
  • Location:Shadow Moses

Posted 31 December 2009 - 10:47 AM

View Postmarmite, on Dec 30 2009, 12:49 PM, said:

Just don't forget updates to Flash player ... so many sites use this these days.
I always update Flash when a stable build is available, kind of hard to miss any updates since I visit Filehippo.com everyday.

View Postabu aufa, on Dec 30 2009, 08:45 PM, said:

and don't forget to check new version via Live Update if available, at least every two weeks ;)
I know, that's probably mostly due to the Javascript support which is most likely always going to have vulnerability updates non-stop.
Complexity of incoherent design.

#11 OFFLINE   Aethec

    Red Panda

  • Members
  • PipPipPipPip
  • 1,714 posts
  • Gender:Male
  • Location:Lausanne, Switzerland

Posted 31 December 2009 - 12:57 PM

SumatraPDF is very good, if you only read PDFs.
It only takes 1,2 Mb :o
Piriform French translator

#12 OFFLINE   marmite

    Relax, it's only ones and zeros!

  • Members
  • PipPipPipPip
  • 877 posts
  • Location:UK

Posted 31 December 2009 - 01:07 PM

View PostAndavari, on Dec 31 2009, 10:47 AM, said:

I always update Flash when a stable build is available, kind of hard to miss any updates since I visit Filehippo.com everyday.
Yeah - that wasn't aimed at you Andavari, just a general comment ;) ... it's probably one that quite a few people miss. I generally only pick Flash updates up when I run PSI! Though I think the regulars using these forums are more likely to be up-to-date than your average PC user.

#13 OFFLINE   marmite

    Relax, it's only ones and zeros!

  • Members
  • PipPipPipPip
  • 877 posts
  • Location:UK

Posted 05 January 2010 - 12:39 PM

Sophisticated exploit in the wild ... http://www.theregist..._reader_attack/.

Few of the major AVs caught this one according to the linked article.

#14 OFFLINE   marmite

    Relax, it's only ones and zeros!

  • Members
  • PipPipPipPip
  • 877 posts
  • Location:UK

Posted 13 January 2010 - 07:47 PM

View PostNullack, on Dec 24 2009, 11:47 PM, said:

The fix for this vulnerability is now available.

To download it, open your Adobe Reader and select Help / Check for Updates.

#15 OFFLINE   abu aufa

    Power Member

  • Members
  • PipPipPipPip
  • 694 posts
  • Gender:Male
  • Location:Ardhillah

Posted 23 February 2010 - 02:45 AM

I'm just warn you,friends.

I am very disappointed with pdf x-change viewer. The latest version now has the Ask toolbar and forcing users to download. Run and read the installer carefully.

anyway,I'd stick with this great Adobe Reader replacement.


EDIT : I just found another good PDF Reader, have a look http://www.nuance.co.../pdf-reader.asp