The cyber-terrorist who discovered a of late patched QuickTime flaw affecting the Firefox web browser says he has found an as serious fault in Adobe Systems ’ PDF file format .
“ Adobe Acrobat / Reader PDF documents can be used to compromise your Windows boxwood . totally ! ! ! Invisibly and unwillingly ! ! ! , ” wrote Petko Petkov , in a breathless Thursdayblog bill . “ All it takes is to unfold a PDF document or bumble across a page which embed one . ”
Petkov said he had reassert the issue on Adobe Reader 8.1 on Windows XP and that other rendering may be affected .
The certificate researcher said he would not release code that shows how this flack work until Adobe provided a patch for the problem , but he has already broadcast other software program developer skin for bug fixes over the past week .
On Sept. 12 , Petkov reported that attacker could unravel unauthorised software program on a Firefox substance abuser ’s PC by tap a flaw in Apple ’s QuickTime media data format . Mozilla provide a partial mend for this problem on Tuesday but said Apple would ultimately have to call the issue in its QuickTime medium role player .
And on Tuesday Petkovposted codeshowing how Windows Media Player filing cabinet could be used to make Web surfer susceptible to Internet Explorer bugs , even if they were running another web internet browser such as Firefox or Opera . Microsoft has said it is investigate this issue .
If Petkov ’s PDF claim are true , it could be defective news for business users , who are used to opening PDF attachments without thinking doubly , say Andrew Storms , director of surety operation with nCircle web Security .
Though some attacker have crafted pdf attacks in recent years , Petkov ’s codification could also be more effective than typical effort , Storms added . “ Historically , those other exploits have been target for specific interpretation of Adobe Reader , ” he say via inst subject matter . “ According to the information , this affects all version . It ’s an inbuilt architectural problem in the means files are read . ”