Re: 'High risk' zero-day flaw haunts Adobe Acrobat, Reader

Subject: Re: 'High risk' zero-day flaw haunts Adobe Acrobat, Reader
From: "Gene Kim-Eng" <techwr -at- genek -dot- com>
To: <techwr-l -at- lists -dot- techwr-l -dot- com>
Date: Wed, 24 Oct 2007 09:16:24 -0700

It's not possible to be sure without one of those POC PDFs,
but I think there's probably another fix. Go into the "Trust
Manager" in "Preferences," and for both trusted and Non-
trusted documents disable all the permissions, most
especially the "Allow documents to open other files and
launch other applications." This has been my default
setup for Acrobat for as far back as I can remember.

All of these security flaws are the result ot Adobe taking
a perfectly usable application for transmitting electronic
versions of printed documents and stuffing it full of gee-
whiz "user experience" bloatware. The more they
overthink the plumbing the easier it is to stop up the
works.

Gene Kim-Eng



----- Original Message -----
From: "Dan Goldstein" <DGoldstein -at- riverainmedical -dot- com>

>A free security update to Adobe Reader 8.1.1 is now available at
> http://tinyurl.com/2p2g9r.
>
> Those of us with Adobe Acrobat 7 or earlier can choose between:
>
> * An expensive upgrade to Acrobat 8.1.1
> * Switching to a different PDF reader, such as Foxit.
> * The workaround previously published at http://tinyurl.com/2az4tz
> (you'll need to scroll down)
> * Absolutely, positively uninstalling IE 7
>
> Happy Wednesday!

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

Create HTML or Microsoft Word content and convert to Help file formats or
printed documentation. Features include support for Windows Vista & 2007
Microsoft Office, team authoring, plus more.
http://www.DocToHelp.com/TechwrlList

True single source, conditional content, PDF export, modular help.
Help & Manual is the most powerful authoring tool for technical
documentation. Boost your productivity! http://www.helpandmanual.com

---
You are currently subscribed to TECHWR-L as archive -at- web -dot- techwr-l -dot- com -dot-

To unsubscribe send a blank email to
techwr-l-unsubscribe -at- lists -dot- techwr-l -dot- com
or visit http://lists.techwr-l.com/mailman/options/techwr-l/archive%40web.techwr-l.com


To subscribe, send a blank email to techwr-l-join -at- lists -dot- techwr-l -dot- com

Send administrative questions to admin -at- techwr-l -dot- com -dot- Visit
http://www.techwr-l.com/ for more resources and info.


References:
RE: 'High risk' zero-day flaw haunts Adobe Acrobat, Reader: From: Dan Goldstein

Previous by Author: Re: The future of technology (article)
Next by Author: Re: Generating bad documentation -- funny
Previous by Thread: RE: 'High risk' zero-day flaw haunts Adobe Acrobat, Reader
Next by Thread: RE: 'High risk' zero-day flaw haunts Adobe Acrobat, Reader


What this post helpful? Share it with friends and colleagues:


Sponsored Ads