Saturday, 21 February 2009

Adobe Reader critical vulnerability

As software designers add more features to their software it gradually becomes
a) bloated and
b) insecure
This common path is being followed once again by adobe with their acrobat reader software now found on probably nine from ten machines (statistic randomly made up by me and probably bearing little relation to truth (tm)) as they try to make it more functional. The fact that no-one wants or needs any more function from a reader is irrelvant of course and the once 1mb package is now busting out at 30+ megs of irrelevance and exploitfest.

As usual you can expect a long round of emailed PDFs from various botnets, spammers and virus writers coming to a PC near you soon with snappy titles like UPS_invoice.PDF and Fedex_Invoice.PDF.