Beta
×

Welcome to the Slashdot Beta site -- learn more here. Use the link in the footer or click here to return to the Classic version of Slashdot.

Thank you!

Before you choose to head back to the Classic look of the site, we'd appreciate it if you share your thoughts on the Beta; your feedback is what drives our ongoing development.

Beta is different and we value you taking the time to try it out. Please take a look at the changes we've made in Beta and  learn more about it. Thanks for reading, and for making the site better!

Adobe Toughens Sandbox Security in Reader, Acrobat

wiredmikey (1824622) writes | about 2 years ago

Security 0

wiredmikey (1824622) writes "Adobe has beefed up the security capabilities of its Reader and Acrobat software with a more robust sandbox and new security mitigation features, the company said today.

Adobe Reader XI and Acrobat XI, which shipped this week, include a new whitelisting framework, cryptographic capabilities, and a feature that forces all of the DLL files loaded to use ASLR (Address Space Layout Randomization), even if the files were not originally compiled with ASLR enabled.
The biggest change in Reader and Acrobat XI, however, is in the sandbox. The original sandbox in Reader X focused on "write protection" to prevent attackers from installing malware on to the machine or recording user keystrokes. Reader XI now restricts "read-only activities" to prevent attackers from reading sensitive information.

Adobe said that since they added sandbox protection to Adobe Reader and Acrobat, they have not seen any exploits in the wild that break out of the Adobe Reader and Acrobat X sandboxes."

Link to Original Source

cancel ×

0 comments

Sorry! There are no comments related to the filter you selected.

Check for New Comments
Slashdot Login

Need an Account?

Forgot your password?

Submission Text Formatting Tips

We support a small subset of HTML, namely these tags:

  • b
  • i
  • p
  • br
  • a
  • ol
  • ul
  • li
  • dl
  • dt
  • dd
  • em
  • strong
  • tt
  • blockquote
  • div
  • quote
  • ecode

"ecode" can be used for code snippets, for example:

<ecode>    while(1) { do_something(); } </ecode>