AplusWebMaster
Topic Starter
FYI…from the Internet Storm Center:
- http://isc.sans.org/diary.php?date=2004-08-17
Updated August 18th 2004 00:28 UTC
"…buffer overflow in the ActiveX component of Acrobat Reader for Windows. This vulnerability poses a much greater threat, for a number of reasons. First, according to the iDEFENSE, the overflow is still present in current releases of Acrobat Reader. Secondly, the number of target systems is much greater than for the UNIX Acrobat Reader vulnerability. Finally, and most importantly, the advisory contains what is essentially a roadmap for any would-be exploit developer…"
- http://idefense.com/application/poi/displa…vulnerabilities
(Workaround:
In Acrobat Reader v6.0.2, the "critical" setting mentioned is only available to an
administrator account:
1- Start Adobe Reader.
2- Go to: Edit >Preferences >Internet
3- Under "Web Browser" options, UNCHECK "Display PDF in browser"
4- Click OK )
.
- http://isc.sans.org/diary.php?date=2004-08-17
Updated August 18th 2004 00:28 UTC
"…buffer overflow in the ActiveX component of Acrobat Reader for Windows. This vulnerability poses a much greater threat, for a number of reasons. First, according to the iDEFENSE, the overflow is still present in current releases of Acrobat Reader. Secondly, the number of target systems is much greater than for the UNIX Acrobat Reader vulnerability. Finally, and most importantly, the advisory contains what is essentially a roadmap for any would-be exploit developer…"
- http://idefense.com/application/poi/displa…vulnerabilities
(Workaround:
In Acrobat Reader v6.0.2, the "critical" setting mentioned is only available to an
administrator account:
1- Start Adobe Reader.
2- Go to: Edit >Preferences >Internet
3- Under "Web Browser" options, UNCHECK "Display PDF in browser"
4- Click OK )
.