Ah, okay. I do that anyway, because I've had bad experiences with Firefox crashing when displaying embedded PDFs in the past. Sounds like I should be okay until Foxit updates its reader.
Thanks, Rohit Patnaik On Tue, Oct 13, 2009 at 8:15 PM, mrx <[email protected]> wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > Adobe has fixed this issue > > http://www.adobe.com/support/security/bulletins/apsb09-15.html > > And as this bug relates to Firefox rendering embedded COM objects > (PDF) inside a browser window. It should be safe to view PDF's inside > both Adobe and Foxit readers whilst offline. > > MrX > > Rohit Patnaik wrote: > > Are there any available workarounds that would mitigate the threat? I > > suppose I could just upload all my PDFs to Google Docs in the meantime, > but > > I'm looking for something that I could use while offline... > > > > --Rohit Patnaik > > > > On Tue, Oct 13, 2009 at 7:35 PM, mrx <[email protected]> wrote: > > > > > > No, I installed latest updates prior to testing. > > They should be aware of this however considering what appear to be > > striking similarities in the code base between Foxit and Adobe > > readers, at least as far as shared bugs go. > > If not they will be aware of this after they read the email I sent them. > > > > MrX > > > > Rohit Patnaik wrote: > > >>> Has Foxit released an update for this? > > >>> > > >>> --Rohit Patnaik > > >>> > > >>> On Tue, Oct 13, 2009 at 6:40 PM, mrx <[email protected]> > > wrote: > > >>> > > >>> > > >>> It would appear that Foxit reader version 3.1.1.0928 is also > > >>> vulnerable to this memory corruption flaw. > > >>> Foxit reader was also vulnerable to the JPEG2000/JBIG2 decoder bug. > > >>> > > >>> Makes me wonder how much code is common to both Adobes and > > Foxits PDF > > >>> readers > > >>> > > >>> MrX > > >>> > > >>> > > >>> Berend-Jan Wever wrote: > > >>>>>> Adobe bulletin: > > >>>>>> http://www.adobe.com/support/security/bulletins/apsb09-15.html > > >>>>>> > > >>>>>> Short description and repro case: > > >>>>>> > > > http://skypher.com/index.php/2009/10/13/memory-corruption-when-loadingunloading-adobe-objects-through-embed-tag-in-firefox/ > > >>>>>> Cheers, > > >>>>>> > > >>>>>> SkyLined > > >>>>>> < > > > http://skypher.com/index.php/2009/10/13/memory-corruption-when-loadingunloading-adobe-objects-through-embed-tag-in-firefox/ > > >>>>>> Berend-Jan Wever <[email protected]> > > >>>>>> http://skypher.com/SkyLined > > >>>>>> > > >>>>>> > > >>>>>> > > >>> > > ---------------------------------------------------------------------- > > >>>>>> _______________________________________________ > > >>>>>> Full-Disclosure - We believe in it. > > >>>>>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html > > >>>>>> Hosted and sponsored by Secunia - http://secunia.com/ > > _______________________________________________ > > Full-Disclosure - We believe in it. > > Charter: http://lists.grok.org.uk/full-disclosure-charter.html > > Hosted and sponsored by Secunia - http://secunia.com/ > >> > _______________________________________________ > Full-Disclosure - We believe in it. > Charter: http://lists.grok.org.uk/full-disclosure-charter.html > Hosted and sponsored by Secunia - http://secunia.com/ > >> > > > ---------------------------------------------------------------------- > > > _______________________________________________ > > Full-Disclosure - We believe in it. > > Charter: http://lists.grok.org.uk/full-disclosure-charter.html > > Hosted and sponsored by Secunia - http://secunia.com/ > > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.2 (MingW32) > Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ > > iQEVAwUBStUmKrIvn8UFHWSmAQLvGgf/ZUENmHdfks44uiGTreeEAMkAtcJ0DmYB > /CyHB6omJWnSWIyxUrClcIU62eK1Oue698BjIG1hiyquqFSbnLqzivhB4OSvneYH > 8aQodO4gdCO8vwSaQenxO9hk1HPE8RJN9Ds5QqvPZ7qDdhEvdVeaCDyBgn4kERz/ > jrgIJKTCYR67EJPuUu31QFWWpp/qIBBAN3ragqXhq5lQxpOxnWohZ0E1kCB9BdIH > BIqZW8Laa62IkGH4ZVDhwwek883m7QzJCGUVOrWt5e02QaZoX9D2ompW2Od6FwJJ > Ro1wlm1bgVPXNhCPJ+Ohq41F96X8S0a9OHlnUwV88EicFwV0Fu9c6Q== > =H/jn > -----END PGP SIGNATURE----- > > _______________________________________________ > Full-Disclosure - We believe in it. > Charter: http://lists.grok.org.uk/full-disclosure-charter.html > Hosted and sponsored by Secunia - http://secunia.com/ >
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
