Adobe Issues Fix for Reader, Acrobat Flaw

Adobe Issues Fix for Reader, Acrobat Flaw

Written By
Ryan Naraine
Ryan Naraine
Apr 26, 2005
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Users of the ubiquitous Adobe Reader and Adobe Acrobat programs are at risk of a local file detection flaw, according to an alert from a private security research outfit.

Adobe Systems Inc. earlier this month sneaked out a fix for the vulnerability and recommended that users upgrade to versions 7.0.1 of the freely available programs.

Hyperdose Security, the company credited with finding and reporting the bug, said an attacker could target the “Safe for Scripting” method in the Adobe programs to direct unsuspecting users to a malicious Web site.

Once the user lands on the malicious site, the attacker can use the “LoadFile” method to send a local file name on the victims computer. Using this method, the attacker is able to determine file existence on their victims machine, said Robert Fly, a researcher at Hyperdose Security.

Although the risk is considered low, Fly said the attack would be useful as a stepping stone to further attacks. “Knowing the existence of a local file an attacker can gain knowledge as to the software and likely versions of software the individual is using,” he said.

/zimages/5/28571.gifRead the full story on PDFzone.com: Adobe Issues Fix for Reader, Acrobat Flaw

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.