Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
News
SHARE
Core Security finds critical Adobe Reader hole

By Elinor Mills

Excerpt:

An attacker could put malicious code in JavaScript embedded in a PDF and spread that via a Web site or e-mail. Once the file is opened, the code could manipulate the program's memory allocation pattern and trigger the vulnerability to execute arbitrary code with the privileges of the user.

Damian Frizza, a CoreLabs researcher, discovered the vulnerability in May while he was investigating a similar vulnerability in a different PDF viewer application called Foxit Reader. Core Security immediately reported the new hole to Adobe.

Source: CNET

View the full article

Related Content