Live data from Hacker News

“Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

blogs.adobe.com

1–10 of 43 posts

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#2
Adobe exploits are still a thing. I regularly get emails from silicon valley investors asking for me to open their pdf file which contains their propsal...I chuckle everytime at that line, THERES SIMPLY NO WAY IM GOING TO OPEN A PDF or visit a site with Flash turned on in 2016.

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#4

Adobe exploits are still a thing. I regularly get emails from silicon valley investors asking for me to open their pdf file which contains their propsal...I chuckle everytime at that line, THERES SIMPLY NO WAY IM GOING TO OPEN A PDF or visit a site with Flash turned on in 2016.

Most browsers have a sandboxed pdf reader implementation. What are you afraid of?

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#5

Adobe exploits are still a thing. I regularly get emails from silicon valley investors asking for me to open their pdf file which contains their propsal...I chuckle everytime at that line, THERES SIMPLY NO WAY IM GOING TO OPEN A PDF or visit a site with Flash turned on in 2016.

Is the PDF format itself broken, or just the awful Adobe Reader? There are dozens of PDF reader implementations, including all the major browsers. I cannot imagine they are all exploitable in the same way.

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#6
post #5

Adobe exploits are still a thing. I regularly get emails from silicon valley investors asking for me to open their pdf file which contains their propsal...I chuckle everytime at that line, THERES SIMPLY NO WAY IM GOING TO OPEN A PDF or visit a site with Flash turned on in 2016.

Is the PDF format itself broken, or just the awful Adobe Reader? There are dozens of PDF reader implementations, including all the major browsers. I cannot imagine they are all exploitable in the same way.

Early PDF was quite sane. It was the Postscript imaging model turned into a binary bytecode format with almost all the programmability features removed.

Later on it got wonky (though never even close to the extent to which Flash did!) with all the hypertextification features. But basic PDF is actually one of the Great File Formats in computer history.

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#7

Adobe exploits are still a thing. I regularly get emails from silicon valley investors asking for me to open their pdf file which contains their propsal...I chuckle everytime at that line, THERES SIMPLY NO WAY IM GOING TO OPEN A PDF or visit a site with Flash turned on in 2016.

Most browsers have a sandboxed pdf reader implementation. What are you afraid of?

They are much better in my opinion, but not perfect. Last year there was a pdf.js vulnerability: https://blog.mozilla.org/security/2015/08/06/firefox-exploit...

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#8

Adobe exploits are still a thing. I regularly get emails from silicon valley investors asking for me to open their pdf file which contains their propsal...I chuckle everytime at that line, THERES SIMPLY NO WAY IM GOING TO OPEN A PDF or visit a site with Flash turned on in 2016.

You are depriving yourself of a lot of information by avoiding files based solely on file extension (most academic papers are in PDF format, for example). Avoiding Flash, on the other hand, I completely understand.

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#9
post #5

Adobe exploits are still a thing. I regularly get emails from silicon valley investors asking for me to open their pdf file which contains their propsal...I chuckle everytime at that line, THERES SIMPLY NO WAY IM GOING TO OPEN A PDF or visit a site with Flash turned on in 2016.

Is the PDF format itself broken, or just the awful Adobe Reader? There are dozens of PDF reader implementations, including all the major browsers. I cannot imagine they are all exploitable in the same way.

The standard is 1000 pages long. Most reader implementations are written in C/C++.

They are of course exploitable in different ways.

Adobe sometimes does not follow its own spec.

People publishing PDFs sometimes use that non-standard behavior to display some graphics. This is especially true with many research papers that only render on Adobe Reader.

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#10

Adobe exploits are still a thing. I regularly get emails from silicon valley investors asking for me to open their pdf file which contains their propsal...I chuckle everytime at that line, THERES SIMPLY NO WAY IM GOING TO OPEN A PDF or visit a site with Flash turned on in 2016.

Why not open it in firefox with pdfjs?

PDF is still the single best/easiest format to use to render some things.

Post reply on HN