Sophos urges Adobe to disable JavaScript

author-image
DQChannels Bureau
New Update

IT security and data protection firm,
href="http://www.ciol.com/Security/Security-Enterprise/News-Reports/Sophos-joins-hands-with-Crossbeam/138268/0/">Sophos,
has urged software provider Adobe to begin disabling
JavaScript in its products by default. This comes following the most
recent security update for Adobe Acrobat and Reader, which fixed a
serious vulnerability that relies on JavaScript code.

Advertisment

The vulnerability, named CVE-2010-1297,
involved a booby-trapped PDF file, which would contain a Flash
animation and relied on JavaScript for the exploit to work. The
exploit is more complex than previous Adobe exploits, potentially
marking a new trend in the development of Adobe exploits.



“The common thread in most, if not
all, Adobe exploits is the requirement for JavaScript , as exploits
will work correctly only if JavaScript is enabled,” said Vanja
Svajcer, Principal Virus Researcher, Sophos. “This is why we
recommend all users to disable JavaScript in Adobe Acrobat and
Reader,” he further added.

“The company's regular security
updates show that Adobe is now doing more to address vulnerabilities,
but the high number of patched vulnerabilities indicate that it may
be a good time for Adobe to overhaul its approach to build security
into its products,” continued Svajcer. “If nothing else,
JavaScript should be disabled by default in Adobe Reader,” he
added.

Advertisment