--
You can read about it HERE and HERE.
You can directly download the Adobe Reader 10.0.3 update HERE.
You can directly download the Adobe Acrobat X 10.0.3 update HERE.
The security flaws involved are those Adobe posted on April 11th in the second article linked above. These are the promised updates of Reader and Acrobat, ahead of schedule by four days. Thank you Adobe!
Computer PWNing through the use of PDFs and Flash media is thick and fast these days, particularly on Windows, including Windows 7 (7ista). I have read speculation that hackers have a pile of 'zero-day' Adobe security hole hacks that are being used one after the other as Adobe provide patch after patch, trying to keep up. Note that it is possible to at least compromise a Mac using similar cracking methods and Trojan horses.
THEREFORE, user beware. I wrote in detail about precautions and protections available if you must use PDFs and/or Flash. Simply scroll back through my previous blog posts.
:-Derek
--
Showing posts with label PDF. Show all posts
Showing posts with label PDF. Show all posts
Thursday, April 21, 2011
Thursday, August 19, 2010
Adobe 'Out Of Band' CRITICAL Updates Parade:
Acrobat and Reader v9.3.4
--
And the parade marches on. At last we have the latest in CRITICAL Adobe security hole updates. This time the updates are for Adobe Acrobat and Adobe Reader. GET THEM NOW!
Because the process of getting to actual download links at the Adobe site is a huge PITA, here are direct URLs for English Intel Mac users. Send me virtual luv:
Acrobat Reader v9.3.4 update
Adobe Acrobat 9.3.4 Pro update
The general update page for all other users and versions is HERE.
What's so CRITICAL? The update's security bulletin is HERE.
To quote Adobe:
1) The updates patch memory corruption vulnerabilities that could lead to hacked code execution on your Mac and/or program crashes. IOW its more of the same old buffer overflow problem that plagues current computer coding in general. (As found in CVE-2010-2862).
Quoting from the CVE:
2) They solve a social engineering attack security hole via PDF files that could lead to hacked code execution on your Mac. (As found in CVE-2010-1240).
Quoting from the CVE:
BTW: Looking up CVE reports is easy, if snooze inducing. Just go to the National Vulnerability Database site (at the National Institute of Standards and Technology) and search on the CVE number. Here is the URL to get you started:
National Vulnerability Database (NVD) Search Vulnerabilities
And now for a rant:
If you're wondering why these simple and specific CVE searches take a long time (zzzzz) to resolve, it's the decrepit US government. It's Microsoft Windows. It's ancient old PCs the government is too cheap to replace, cranking away on stuff that takes any modern Mac a microsecond. (But of course, the government did manage to fund the infamous 'Bridge To Nowhere' in Alaska, hardy har har, porky pork, oinky oink, so long Ted Stevens you parasite).
I was once offered a job at the Department of Wildlife. I took one look at their computers and wondered what would be the appropriate response: Running away screaming OR sauntering out laughing?
In any case, if you've ever wondered why it's so incredibly easy for The Red Hacker Alliance in Red China and other such scum to hack into US government computers, look no further for your answer. Much as I hated the Bush League, much as I'd like to support the Obama Era, this stupid state of affairs continues. Note the fact that the Obama Administration hired ex-Microsoft executives and coders to help them solve their computer security crisis. That's right! They hired the CAUSE of the problem to SOLVE the problem.
(o_0)
Hmm. What would be the appropriate response? I'll leave it to you to decide.
CUL8R!
Stay safe.
Stay secure.
Don't touch my cookies.
;-Derek
--
And the parade marches on. At last we have the latest in CRITICAL Adobe security hole updates. This time the updates are for Adobe Acrobat and Adobe Reader. GET THEM NOW!
Because the process of getting to actual download links at the Adobe site is a huge PITA, here are direct URLs for English Intel Mac users. Send me virtual luv:
Acrobat Reader v9.3.4 update
Adobe Acrobat 9.3.4 Pro update
The general update page for all other users and versions is HERE.
What's so CRITICAL? The update's security bulletin is HERE.
To quote Adobe:
These updates address CVE-2010-2862, which was discussed at the Black Hat USA 2010 security conference on Wednesday, July 28, 2010. They also incorporate the Adobe Flash Player update as noted in Security Bulletin APSB10-16.My summary:
1) The updates patch memory corruption vulnerabilities that could lead to hacked code execution on your Mac and/or program crashes. IOW its more of the same old buffer overflow problem that plagues current computer coding in general. (As found in CVE-2010-2862).
Quoting from the CVE:
Integer overflow in CoolType.dll in Adobe Reader 8.2.3 and 9.3.3, and Acrobat 9.3.3, allows remote attackers to execute arbitrary code via a TrueType font with a large maxCompositePoints value in a Maximum Profile (maxp) table.
2) They solve a social engineering attack security hole via PDF files that could lead to hacked code execution on your Mac. (As found in CVE-2010-1240).
Quoting from the CVE:
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in the Launch File warning dialog, which makes it easier for remote attackers to trick users into executing an arbitrary local program that was specified in a PDF document, as demonstrated by a text field that claims that the Open button will enable the user to read an encrypted message.~~~~~~~~~~
BTW: Looking up CVE reports is easy, if snooze inducing. Just go to the National Vulnerability Database site (at the National Institute of Standards and Technology) and search on the CVE number. Here is the URL to get you started:
National Vulnerability Database (NVD) Search Vulnerabilities
And now for a rant:
If you're wondering why these simple and specific CVE searches take a long time (zzzzz) to resolve, it's the decrepit US government. It's Microsoft Windows. It's ancient old PCs the government is too cheap to replace, cranking away on stuff that takes any modern Mac a microsecond. (But of course, the government did manage to fund the infamous 'Bridge To Nowhere' in Alaska, hardy har har, porky pork, oinky oink, so long Ted Stevens you parasite).
I was once offered a job at the Department of Wildlife. I took one look at their computers and wondered what would be the appropriate response: Running away screaming OR sauntering out laughing?
In any case, if you've ever wondered why it's so incredibly easy for The Red Hacker Alliance in Red China and other such scum to hack into US government computers, look no further for your answer. Much as I hated the Bush League, much as I'd like to support the Obama Era, this stupid state of affairs continues. Note the fact that the Obama Administration hired ex-Microsoft executives and coders to help them solve their computer security crisis. That's right! They hired the CAUSE of the problem to SOLVE the problem.
(o_0)
Hmm. What would be the appropriate response? I'll leave it to you to decide.
CUL8R!
Stay safe.
Stay secure.
Don't touch my cookies.
;-Derek
--
Friday, August 13, 2010
Adobe Flash, AIR, PDF, Acrobat and Reader:
Security Statistics Sources
--
Earlier today, I was helping out a reader at MacDailyNews.com who had the following question:
Earlier today, I was helping out a reader at MacDailyNews.com who had the following question:
'BSOD' asks: "Does anyone have statistics on exactly how many security holes have been opened up by Flash, Air, and PDF? I think that we need to see that stat."My answer is of general interest. Therefore, I am posting it here for your reading pleasure:
You can dig around at the CVE site for each of them. CVE stands for Common Vulnerabilities and Exposures. It keeps track of each reported software security problem:
http://cve.mitre.org/
Wikipedia.org also covers each of them and gives a general description of their security:
Adobe Flash: "As of May 17, 2010, The Flash Player has 77 CVE entries, 34 of which have been ranked with a high severity (leading to arbitrary code execution), and 40 ranked medium."
Adobe PDF: "On March 30, 2010 security researcher Didier Stevens reported an "exploit" that causes an arbitrary executable to be run when a PDF file is opened, after the user accepts a warning prompt. The exploit works in several different PDF viewers including Adobe Reader and Foxit Reader."
And, earlier this year Adobe were embarrassed into creating the Adobe Product Security Incident Response Tearm (PSIRT). You can keep up with their blog here:
http://blogs.adobe.com/psirt/
Adobe maintain their Security Bulletins and Advisories page, going back to 2005, here:
http://www.adobe.com/support/security/
• There are approximately 88 Adobe Flash security bulletins.
• There are 6 Adobe PDF security bulletins.
• There are over 100 Adobe Acrobat security bulletins.
• There are over 100 Adobe Reader security bulletins.
• The only Adobe AIR related bulletin is the Adobe Flash bulletin from June 10, 2010.
Wednesday, April 14, 2010
PDF Security Hole:
Hacking Into Copy & Print 'Locked' PDFs
-revised-
I was hoping I was wrong, but this is what I learned today:Anyone can hack around a password required to copy from or print a PDF. Anyone.
Thankfully, the full locking of a PDF remains unhacked. The 'Open' password is still required.
A hacking tool that allows you to hack copy and print permissions is today's Mac Update Promo deal of the day. It is called PDFKey Pro. (48% off the regular price of $24.99). This program is a hacking tool that clearly points out a fundamental security hole in the PDF format. Therefore, I see no point in using PDF password for copy and print protection. It's worthless.
Please note that I am not knocking hacking tools. I am not knocking PDFKey Pro. The way it is being sold sounds entirely legitimate. The fact that copy and print PDF protections can be entirely defeated has nothing to do with the developer of this application. It has 100% to do with Adobe. Yeah, I know some people are tired of the onslaught of knocking against Adobe these days. Tough. This is a big fat and ugly nasty problem. Adobe are responsible.
In the past I've talked with both David Pogue and Adam Engst about selling electronic books. David Pogue and I talked about selling protected PDFs as one option. He decided at the time to try Adam Engst's method of simply trusting the customer. As an opponent of DRM (digital rights manglement), I agree with Adam. However, authors and publishers are entirely within their rights to prevent anyone from being able to copy from or print their documents and books.
Therefore, if you want to lock up the copy and print permissions of your docs, look elsewhere. There are plenty of great locking and encryption tools for Mac, but I'm not aware of anything that only prevents copying and printing.I'd very much enjoy reading an analysis of how PDF protection is hacked. Something tells me it's already out there on the net for any hacker to read and use. What a shame.
--
Labels:
Adobe,
encryption,
GPG,
hacking,
locking,
password,
PDF,
PDFKey Pro,
PGP
Wednesday, April 29, 2009
Dump Adobe Reader? Yeah, why not.
--
Intro: I never like articles with a title ending in a question mark. You know what you're going to get: no answer to the question. Therefore, they are typically filler. Yawn on that. So here is my question and answer title. Let's get to the point right off the bat: Adobe Reader is a security risk.
The chatter on the net this past week has come to the conclusion that the long line of security holes in Adobe Reader over the past two years is enough already. Dump the thing. It's like my conclusion from decades past that Windows, among its many disappointments, is too much of a security risk to use professionally. That any business or any government uses it greatly concerns me. But it's not Microsoft bashing day. It's Adobe bashing day. If you don't need Adobe Reader, don't use it. Thankfully, Mac OS X users have Apple's Preview application, which has not got the JavaScript vulnerabilities of Adobe Reader. So use Preview instead. It's not totally immune to infected PDF files, but it's much safer than Adobe Reader.
OK, it's not like anyone's Mac got pwned by using Adobe Reader. There is no malware targeting Macs that I know of that weasels its way in via holes in Adobe Reader. So really there is no major alarm going off telling us to kick Adobe Reader off the bus for having cooties. But considering that Mac OS X is the safest professional operating system on the planet (not that I'm dissing Linux mind you), avoiding Adobe Reader at this time is a very good idea.
Personally, I've been a fan of PDF since Adobe Acrobat version 3. It's brilliant and has only become better over time. Thank you Adobe, and especially thank you for making it an open standard. Its integration into the core of Mac OS X is incredible. However, Adobe allowed in some poor code, including support for the catastrophe oddly known as JavaScript. I'll skip my usual lecture on how it got its misnomer and how it was ruined as a standard by Microsoft. Simply know that it is a security holey mess. Apple has gotten burned by JavaScript in QuickTime since 2006. The same JavaScript insecurities are equally plaguing Adobe Reader. Apple got control of their JavaScript problems. Adobe are still playing catch up.
Me, I'll still continue to use Acrobat. I'll still keep Reader around for when I absolutely need it. And there are indeed times when I require Reader. But I'm also going to keep an eye on the latest Reader problems and continue to update it (manually!) when updates are offered.
--
Intro: I never like articles with a title ending in a question mark. You know what you're going to get: no answer to the question. Therefore, they are typically filler. Yawn on that. So here is my question and answer title. Let's get to the point right off the bat: Adobe Reader is a security risk.
The chatter on the net this past week has come to the conclusion that the long line of security holes in Adobe Reader over the past two years is enough already. Dump the thing. It's like my conclusion from decades past that Windows, among its many disappointments, is too much of a security risk to use professionally. That any business or any government uses it greatly concerns me. But it's not Microsoft bashing day. It's Adobe bashing day. If you don't need Adobe Reader, don't use it. Thankfully, Mac OS X users have Apple's Preview application, which has not got the JavaScript vulnerabilities of Adobe Reader. So use Preview instead. It's not totally immune to infected PDF files, but it's much safer than Adobe Reader.
OK, it's not like anyone's Mac got pwned by using Adobe Reader. There is no malware targeting Macs that I know of that weasels its way in via holes in Adobe Reader. So really there is no major alarm going off telling us to kick Adobe Reader off the bus for having cooties. But considering that Mac OS X is the safest professional operating system on the planet (not that I'm dissing Linux mind you), avoiding Adobe Reader at this time is a very good idea.
Personally, I've been a fan of PDF since Adobe Acrobat version 3. It's brilliant and has only become better over time. Thank you Adobe, and especially thank you for making it an open standard. Its integration into the core of Mac OS X is incredible. However, Adobe allowed in some poor code, including support for the catastrophe oddly known as JavaScript. I'll skip my usual lecture on how it got its misnomer and how it was ruined as a standard by Microsoft. Simply know that it is a security holey mess. Apple has gotten burned by JavaScript in QuickTime since 2006. The same JavaScript insecurities are equally plaguing Adobe Reader. Apple got control of their JavaScript problems. Adobe are still playing catch up.
Me, I'll still continue to use Acrobat. I'll still keep Reader around for when I absolutely need it. And there are indeed times when I require Reader. But I'm also going to keep an eye on the latest Reader problems and continue to update it (manually!) when updates are offered.
--
Subscribe to:
Posts (Atom)