Adobe Issues Fix for Reader, Acrobat Flaw

執筆者
Ryan Naraine
Ryan Naraine
Published: Apr 26, 2005
Updated: Feb 2, 2021
1 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Users of the ubiquitous Adobe Reader and Adobe Acrobat programs are at risk of a local file detection flaw, according to an alert from a private security research outfit.

Adobe Systems Inc. earlier this month sneaked out a fix for the vulnerability and recommended that users upgrade to versions 7.0.1 of the freely available programs.

Hyperdose Security, the company credited with finding and reporting the bug, said an attacker could target the “Safe for Scripting” method in the Adobe programs to direct unsuspecting users to a malicious Web site.

Once the user lands on the malicious site, the attacker can use the “LoadFile” method to send a local file name on the victims computer. Using this method, the attacker is able to determine file existence on their victims machine, said Robert Fly, a researcher at Hyperdose Security.

Although the risk is considered low, Fly said the attack would be useful as a stepping stone to further attacks. “Knowing the existence of a local file an attacker can gain knowledge as to the software and likely versions of software the individual is using,” he said.

/zimages/5/28571.gifRead the full story on PDFzone.com: Adobe Issues Fix for Reader, Acrobat Flaw

Ryan Naraine

Ryan Naraine

Content Writer

Ryan Naraine is a ServerWatch, eSecurity Planet, and eWEEK contributor.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。