So, why Adobe made built-in JavaScript their Acrobat?
とうとうAdobeが公式に JavaScriptをOFFにするように発表してしまいましたトサ。
Buffer overflow issues in Adobe Reader and Acrobat
A critical vulnerability has been identified in Adobe Reader 9.1 and Acrobat 9.1 and earlier versions. This vulnerability (
CVE-2009-1492) would cause the application to crash and could potentially allow an attacker to take control of the affected system. A second vulnerability has also been reported that appears to affect Adobe Reader for Unix only (
CVE-2009-1493).
1. Launch Acrobat or Adobe Reader.
2. Select Edit>Preferences
3. Select the JavaScript Category
4. Uncheck the ‘Enable Acrobat JavaScript’ option
5. Click OK
Microsoftも(たぶん)泣く泣く
USB Autorunを殺したことですし、Adobeもそれに倣った方がいいんじゃないのかなぁ?
5 月 10th, 2009 at 6:53 PM
[...] Adobe Acrobat Readerの JavaScript OFF ---------- 参考: Pakes.kmm 以前発見された "78.109.29.112:2111"を C&C [...]