2009-03-13

PDF Vulnerability

A very serious pdf vulnerability is out in the open and is doing rounds in the news. The interesting part of this vulnerability is that a victim could get effected, even without opening the infected pdf file..!!

Here is one of the most comprehensive articles I have come across. The author demos three methods to trigger the vulnerability:
  1. When the user just selects the infected pdf doc with a single click
  2. If the user changes his Windows Explorer's view to Thumbnails View
  3. If the victim hovers his mouse's cursor over the document

1 comment:

  1. This is shocking…
    Now this will make me think before downloading any PDF.

    My questions would be:
    1. How do we identify if it’s a malicious file before downloding ?
    2. How do we prevent it from affecting our system ?

    ReplyDelete