It has been a few months since I posted anything here but tonight as I was fiddling around with the Launch action within a PDF file I discovered another oddity that I thought would make an interesting blog posting. As we are all probably aware of the Launch action within the PDF specification allows for arbitrary files to be opened and/or executed in Adobe reader versions prior to version 9.3.3 with very little restrictions. Adobe attempted to apply some basic blacklisting restrictions to prevent the Launch action from executing these arbitrary executables in version 9.3.3, but this attempt was poorly implemented as the blacklist was easily escaped by simply adding double quotes. Needless to say Adobe quickly corrected this with the release of Adobe reader version 9.4. So what was the oddity I discovered in a fully patched Adobe reader version 9.4 release that may be of interest?
What I discovered is that the PDF Launch action specification allows for any PDF file accessible by the end user to be printed to the default printer and Adobe reader implements this specification without properly disclosing that a print action is being carried out. What I mean by not properly disclosing that a print action is being carried out is that a warning dialog box is presented to the end user, but the message within the this dialog box provides no indication that the PDF file is being printed. The following screen capture is what is displayed to the end user prior to the Launch action being executed to print a PDF file:
...|
New Acrobat Generation Praised for Powerful Collaboration Tools, Enterprise ... New Microsoft(R) SharePoint integration enables consistency of Adobe PDF documents across the enterprise; users can check-in and check-out PDF files for |
|
Toshiba smartbooks Excel, Powerpoint and Adobe PDF files and SingleClick Connect (180-day trial) to remotely access your desktop and print to your home network printer and |
|
Nifty scanner eases farewell to paper Only the bundled versions of the PDF-editing software, Adobe Acrobat, are specific to Windows or Mac. However, the basic software that comes with each |
|
Adobe Launches New Cloud Services in comparison to Adobe's past online PDF creation products, such as the ability to combine multiple documents into a single PDF file, install a printer |
|
Review: Nifty Scanner Eases Farewell To Paper Only the bundled versions of the PDF-editing software, Adobe Acrobat, are specific to Windows or Mac. However, the basic software that comes with each |