Washington23 »Software
Print

Using FoxIt because you think it's safer than Adobe Reader? Think again.

Filed under: Security, Office

Whenever we run a post about yet another security hole in Adobe Reader, commenters chime in with their support for Foxit's free alternative. If you've been sining its praises for security reasons, think again says security pro Didier Stevens.

Foxit, it turns out, has a rather major flaw right now. An attacker can piggyback and launch an executable within a PDF which Foxit will then run without any requesting confirmation from the user. Adobe Reader, on the other hand, throws up an alert window to ask whether the file should be allowed to run. “In this case, Foxit Reader is probably worse than Adobe Reader, because no warning gets displayed to prevent the launch action,” says Stevens.

My desktop PDF viewer of choice — Sumatra — isn't affected by the exploit, nor is PDF-XChange and you can always play it safe by using the Google Docs web viewer.

And no, Stevens' exploit doesn't work on Linux or Mac. One crucial detail several commenters on his post seem to have missed is that he's calling cmd.exe, a file which you're not usually going to find on a non-Windows box…

[via Sunbelt]Using FoxIt because you think it's safer than Adobe Reader? Think again.

Source: Download Squad

No comments

Leave a comment

Image Navigator

How to solve iOS 4.3 syncing issuesWill the Budget Help Home Buyers?TIGER Projects Remind Us What America Can DoDropMocks is a beautifully simple, HTML5-powered photo sharing siteSeagate GoFlex Satellite HDD Now Serving Media to an Android Near YouDirecTV Bringing HBO Go and MAX Go to Android Later This YearNVIDIA Dual-Core Blowout: 5 Androids, 10 Cores, 1 Contest [PART 3]First Glimpse Of The Samsung Nexus Prime Revealed [Video]Graph Your Inbox uncovers your Gmail account's hidden statsWithings WiScale App Now Available for AndroidTeam Defense Start Sit Week 10, Last of the TexansTabCo Reveals Itself as Fusion Garage, Launches Android-Based Grid OS and New DevicesIDP Waiver Wire Week 6: Pickup Gary Guyton, Brian Robison, Jason AllenWill The Real Jarome Iginla Please Stand UpWhat Google’s unified Privacy Policy means for AndroidBuy Killzone 3, Get Early Access to the SOCOM 4 Multiplayer BetaLooking Inside Boeing’s New 747First Lady Michelle Obama at the Holiday Preview: Three-Week Wait for International iPad OrdersASUS might be the first to bring Android 5.0 Jelly BeanExpected Launch Date For AT&T Samsung Galaxy Note Outed In Press InviteThe Murder of Sister Valsa: a WSJ InvestigationLG Vortex is the LG Optimus One for Verizon?OnLive Launching in UK September 22ndVox shuts down, users can migrate to TypePad, Posterous or WordpressModel-Kit Business-Card Transforms into Plane, Car, BoatGoogle Maps Gets Minor Update to Version 5.6.0New Castle Crashers Character Will Benefit Breast Cancer Research