Live data from Hacker News

Adobe CVEs

cve.mitre.org

1–10 of 23 posts

Re: Adobe CVEs

#2
Looking at crazy stuff like this, I'm so glad most browsers can render PDFs natively and I don't have to rely on any Adobe software anymore.

Re: Adobe CVEs

#4
post #3
post #2

Looking at crazy stuff like this, I'm so glad most browsers can render PDFs natively and I don't have to rely on any Adobe software anymore.

OK, but then again: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=chrome+pdf

Count the instances of "arbitrary code execution" for chrome vs adobe. Its a huge improvement! Granted its not just the pdf reader in the case of adobe.

Re: Adobe CVEs

#5
Keywords for the safety minded ones:

- exploitable memory corruption

- exploitable heap overflow

- exploitable use after free

Re: Adobe CVEs

#6
post #2

Looking at crazy stuff like this, I'm so glad most browsers can render PDFs natively and I don't have to rely on any Adobe software anymore.

The vastly lower attack surface in PDF viewers built into browsers has been quite frustrating for me.

I've seen Adobe vulnerabilities in the wild, and I've seen the improvements to an organisations security by removing Adobe Reader. Not to mention, the immediate reduction in labour of managing its colossal updates regularly.

However, try to remove Adobe PDF in a business with more than a few people, and ime, it's only a matter of time before you start getting demands for Adobe Reader. End users receive complex PDFs the reader in Chrome and Edge can't deal with more than tech people realise.

I hit this myself recently, having decided to spend a week learning TLA+, and finding the published Hyperbook is just totally broken without a third party PDF viewer.

Re: Adobe CVEs

#7
post #3
post #2

Looking at crazy stuff like this, I'm so glad most browsers can render PDFs natively and I don't have to rely on any Adobe software anymore.

OK, but then again: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=chrome+pdf

Huh. I had assumed PDFium ran in the NaCl sandbox or similar. Is that not the case?

Re: Adobe CVEs

#8
How does Adobe allow this to happen? After enough of these over time, you'd think they'd fine some way to invest majorly in securing their runtimes.... either via another language like Mozilla is doing with Rust, some provably secure math-vm-thingie like Microsoft Research, massive security reviews & reduction of attack surfaces like OpenBSD, or another CS-driven solution.

Re: Adobe CVEs

#9
post #8

How does Adobe allow this to happen? After enough of these over time, you'd think they'd fine some way to invest majorly in securing their runtimes.... either via another language like Mozilla is doing with Rust, some provably secure math-vm-thingie like Microsoft Research, massive security reviews & reduction of attack surfaces like OpenBSD, or another CS-driven solution.

Their customers don't care and they are not altruistic like Mozilla or OpenBSD.

Re: Adobe CVEs

#10
post #3
post #2

Looking at crazy stuff like this, I'm so glad most browsers can render PDFs natively and I don't have to rely on any Adobe software anymore.

OK, but then again: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=chrome+pdf

Versus Firefox': https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=pdf.js
Post reply on HN