Vulnerabilities and Attack Surface

From CERT (Will Dormann)

Two recent US-CERT Vulnerability Notes [cert.org] describe similar issues in the Adobe Reader and Foxit Reader PDF viewing applications. The vulnerabilities, that both applications failed to properly handle JPEG2000 (JPX) data streams, were discovered as part of our Vulnerability Discovery initiative. The two vulnerability notes are quite similar, except for one aspect: attack surface.  Read the full blog post [cert.org]

From CERT (Will Dormann)

Two recent US-CERT Vulnerability Notes [cert.org] describe similar issues in the Adobe Reader and Foxit Reader PDF viewing applications. The vulnerabilities, that both applications failed to properly handle JPEG2000 (JPX) data streams, were discovered as part of our Vulnerability Discovery initiative. The two vulnerability notes are quite similar, except for one aspect: attack surface.  Read the full blog post [cert.org]

Suggested articles