• Alice Johnson

    We decided to send out a notice to people on our email list. We told them to be careful about clicking on links to any PDF files sent to them via email or posted on stock message boards.

    It was a difficult thing to explain. We couldn’t find many resources that explained the problem in simple terms non-technical people can understand. We eventually used the Washington Post article mentioned in your article above.

    We stressed in our email that it was safe for people to visit our website and then open PDF files, but not to follow direct links to our PDFs on other sites or in emails. We also urged them to upgrade their readers.

    We debated whether we should do anything. Eventually we decided that it was a service to our shareholders and analysts and it could protect us from negative publicity or worse. It was a win-win.

    Thanks for bringing this to our attention. Your site has been a valuable to us.

  • http://www.irwebreport.com/ Dominic Jones

    Alice,

    That’s a great idea, much better than trying to remove all your PDF files! I’ve had a few people ask me if they should remove their PDFs, and it’s obviously an option but not a very practical one, so what your company has done is probably the next best thing.

    I’ve also heard from a couple people who feel this is a big deal about nothing. I don’t know about that.

    The latest headline I saw on this from TechWeb paints a grave picture:

    Adobe Flaw May Be ‘Worst’ Bug Of 2007

    “The vulnerability is very pervasive as it lowers the hackability bar from the target Web site needing to have an XSS issue to simply hosting a PDF,” Grossman says. “This has the potential to be the number one worst vulnerability of 2007. Had this come out two weeks ago, it would have definitely made the top 10 list for 2006.”

    I applaud you for doing something rather than nothing, and I’m sure your shareholders will remember that you thought of them.

  • http://technocrati.ca/2007/01/04/pretty-simple-fix-for-the-recent-acrobat-pdf-vulnerability/ darron

    We’re forcing the PDF to download – that appears to bypass the plugin completely. This is how we’re fixing it.

  • Pingback: IR Web Report Blog » PDF flaw has security experts agog