Originally published January 4, 2007 at 12:00 AM | Page modified January 4, 2007 at 1:01 PM
Adobe Reader flaw seen as major PC security problem
Computer security researchers said Wednesday they have discovered a vulnerability in Adobe Systems Inc.'s ubiquitous Acrobat Reader software that allows cyber-intruders to attack personal computers through trusted Web links.
The Associated Press
SAN FRANCISCO (AP) — Computer security researchers said Wednesday they have discovered a vulnerability in Adobe Systems Inc.'s ubiquitous Acrobat Reader software that allows cyber-intruders to attack personal computers through trusted Web links.
Virtually any Web site hosting Portable Document Format, or PDF, files are vulnerable to attack, according to researchers from Symantec Corp. and VeriSign Inc.'s iDefense Intelligence.
The attacks could range from stealing cookies that track a user's Web browsing history to the creation of harmful worms, the researchers said.
The flaw, first revealed at a hacker conference in Germany over the holidays, exists in a plug-in that enables Acrobat users to view PDF files within Web browsers.
By manipulating the Web links to those documents, hackers and online thieves are able to commandeer the Acrobat software and run malicious code when users attempt to open the files, according to Ken Dunham, director of the rapid response team at VeriSign's iDefense Intelligence.
Dunham gave this hypothetical scenario: an attacker finds a PDF file on a banking Web site. The attacker creates a hostile Web site that links to the bank's PDF file. Included is malicious JavaScript code that will run on the unsuspecting user's computer once the link is clicked.
"PDF is trusted and tried and true — everyone uses it," Dunham said. "But instead of just viewing the file, you've initiated script that shouldn't be executed. All you have to do is click on the PDF and the ball starts rolling."
Representatives from Adobe did not return a call from The Associated Press on Wednesday night.
The flaw appears to target Microsoft Corp.'s Internet Explorer 6.0 Web browser and earlier versions, and Mozilla's Firefox browser, the researchers said.
They recommended that users protect themselves by upgrading Internet Explorer or changing Firefox's user options so the browser does not use the Acrobat plug-in.
Researchers said it's unclear how pervasive or harmful any future attacks might be.
"Given that it is easy to exploit, I would expect that we will see this method used considerably in the coming days and weeks, until it is resolved," a Symantec researcher said in a posting on a company Web log.
Copyright © 2007 The Seattle Times Company
Landmark Smith Tower mostly vacant
Toyota's Toyoda scolds execs for emulating U.S. car companies' mistakes
Money Makeover: Financial makeover: A "go-getter" goes after her spending habit
Do your homework before buying brokered CDs
Mutual-fund deposits shift into low gear

Tribal Fireworks Rivalry
The Fourth of July marks a long-standing fireworks rivalry between two clans of a Native-American family in Suquamish.
Entertainment | Top Video | World | Offbeat Video | Sci-Tech
shopping

events for Sunday, Jul. 5th
- Emery's Garden Pink Flamingo Sale
- Kuhlman Summer Sale
- Seattle Premium Outlets July 4th Summ...
- Pink Ginger First Anniversary Sale
editors' picks
More shopping guides- Plasma and LCD beware; OLED screens ready to go mainstream
- Former NFL MVP McNair killed
- Palin takes to Web for hints of political future
- Russell Branyan, Mariners fight off the Red Sox
- Fourth of July festivals and fireworks in Seattle, the suburbs and beyond
- The Blotter | Man pistol-whipped after argument at nightclub
- Desert-lobster dispute turns pair into sagebrush heroes
- Close-up | Prison guards intercept carrier pigeon with a cellphone
- Woman accuses Sounders FC player Nate Jaqua of sexual assault, seeks more than $10 million
- Rob Johnson's double in 11th powers Mariners past Red Sox, 7-6
- Palin resigning as Alaska governor
762 - Seattle Mariners at Boston Red Sox: 07/04 game thread
244 - Reports: NKorean missile arrives at launch site
100 - Palin's Declaration of Independence
75 - Hatred for the NBA runs deep, but don't take it out on the players
73 - Former NFL MVP McNair killed
70 - Mariners score unlikely win over Red Sox in battle of bullpens
58 - Palin links resignation to 'higher calling' and blasts media in Facebook posting
47 - Man pistol-whipped after argument at nightclub
43 - Tukwila residents rally against light-rail noise
36
- Plasma and LCD beware; OLED screens ready to go mainstream
- Merchant Marine veterans fight for recognition
- Property taxes: Appeals shoot up in King, Snohomish Counties
- Close-up | Prison guards intercept carrier pigeon with a cellphone
- Pre-grill drill: marinate steaks
- Lake Washington's sockeye run may hit a record low
- Amtrak cleared for 2nd daily train to Vancouver, B.C.
- Concert Review | Green Day blasts off 4th weekend with KeyArena show
- Hard times for tourist towns means good deals for travelers
- Yakima teacher reprimanded for sending 5-year-old student home with bag of feces in backpack
