
By Elinor Mills
Excerpt:
An attacker could put malicious code in JavaScript embedded in a PDF and spread that via a Web site or e-mail. Once the file is opened, the code could manipulate the program's memory allocation pattern and trigger the vulnerability to execute arbitrary code with the privileges of the user.
Damian Frizza, a CoreLabs researcher, discovered the vulnerability in May while he was investigating a similar vulnerability in a different PDF viewer application called Foxit Reader. Core Security immediately reported the new hole to Adobe.
Source: CNET











