Are there any available workarounds that would mitigate the threat?  I suppose I could just upload all my PDFs to Google Docs in the meantime, but I&#39;m looking for something that I could use while offline...<br><br>--Rohit Patnaik<br>
<br><div class="gmail_quote">On Tue, Oct 13, 2009 at 7:35 PM, mrx <span dir="ltr">&lt;<a href="mailto:mrx@propergander.org.uk">mrx@propergander.org.uk</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
<div class="im">-----BEGIN PGP SIGNED MESSAGE-----<br>
Hash: SHA1<br>
<br>
<br>
</div>No, I installed latest updates prior to testing.<br>
They should be aware of this however considering what appear to be<br>
striking similarities in the code base between Foxit and Adobe<br>
readers, at least as far as shared bugs go.<br>
If not they will be aware of this after they read the email I sent them.<br>
<br>
MrX<br>
<div class="im"><br>
Rohit Patnaik wrote:<br>
&gt; Has Foxit released an update for this?<br>
&gt;<br>
&gt; --Rohit Patnaik<br>
&gt;<br>
&gt; On Tue, Oct 13, 2009 at 6:40 PM, mrx &lt;<a href="mailto:mrx@propergander.org.uk">mrx@propergander.org.uk</a>&gt; wrote:<br>
&gt;<br>
&gt;<br>
</div><div><div></div><div class="h5">&gt; It would appear that Foxit reader version 3.1.1.0928 is also<br>
&gt; vulnerable to this memory corruption flaw.<br>
&gt; Foxit reader was also vulnerable to the JPEG2000/JBIG2 decoder bug.<br>
&gt;<br>
&gt; Makes me wonder how much code is common to both Adobes and Foxits PDF<br>
&gt; readers<br>
&gt;<br>
&gt; MrX<br>
&gt;<br>
&gt;<br>
&gt; Berend-Jan Wever wrote:<br>
&gt; &gt;&gt;&gt; Adobe bulletin:<br>
&gt; &gt;&gt;&gt; <a href="http://www.adobe.com/support/security/bulletins/apsb09-15.html" target="_blank">http://www.adobe.com/support/security/bulletins/apsb09-15.html</a><br>
&gt; &gt;&gt;&gt;<br>
&gt; &gt;&gt;&gt; Short description and repro case:<br>
&gt; &gt;&gt;&gt;<br>
&gt; <a href="http://skypher.com/index.php/2009/10/13/memory-corruption-when-loadingunloading-adobe-objects-through-embed-tag-in-firefox/" target="_blank">http://skypher.com/index.php/2009/10/13/memory-corruption-when-loadingunloading-adobe-objects-through-embed-tag-in-firefox/</a><br>

&gt; &gt;&gt;&gt; Cheers,<br>
&gt; &gt;&gt;&gt;<br>
&gt; &gt;&gt;&gt; SkyLined<br>
&gt; &gt;&gt;&gt; &lt;<br>
&gt; <a href="http://skypher.com/index.php/2009/10/13/memory-corruption-when-loadingunloading-adobe-objects-through-embed-tag-in-firefox/" target="_blank">http://skypher.com/index.php/2009/10/13/memory-corruption-when-loadingunloading-adobe-objects-through-embed-tag-in-firefox/</a><br>

&gt; &gt;&gt;&gt; Berend-Jan Wever &lt;<a href="mailto:berendjanwever@gmail.com">berendjanwever@gmail.com</a>&gt;<br>
&gt; &gt;&gt;&gt; <a href="http://skypher.com/SkyLined" target="_blank">http://skypher.com/SkyLined</a><br>
&gt; &gt;&gt;&gt;<br>
&gt; &gt;&gt;&gt;<br>
&gt; &gt;&gt;&gt;<br>
&gt; ----------------------------------------------------------------------<br>
&gt; &gt;&gt;&gt;<br>
&gt; &gt;&gt;&gt; _______________________________________________<br>
&gt; &gt;&gt;&gt; Full-Disclosure - We believe in it.<br>
&gt; &gt;&gt;&gt; Charter: <a href="http://lists.grok.org.uk/full-disclosure-charter.html" target="_blank">http://lists.grok.org.uk/full-disclosure-charter.html</a><br>
&gt; &gt;&gt;&gt; Hosted and sponsored by Secunia - <a href="http://secunia.com/" target="_blank">http://secunia.com/</a><br>
&gt;&gt;<br>
_______________________________________________<br>
Full-Disclosure - We believe in it.<br>
Charter: <a href="http://lists.grok.org.uk/full-disclosure-charter.html" target="_blank">http://lists.grok.org.uk/full-disclosure-charter.html</a><br>
Hosted and sponsored by Secunia - <a href="http://secunia.com/" target="_blank">http://secunia.com/</a><br>
&gt;&gt;<br>
<br>
-----BEGIN PGP SIGNATURE-----<br>
Version: GnuPG v1.4.2 (MingW32)<br>
Comment: Using GnuPG with Mozilla - <a href="http://enigmail.mozdev.org/" target="_blank">http://enigmail.mozdev.org/</a><br>
<br>
</div></div>iQEVAwUBStUc0LIvn8UFHWSmAQIITggAxL/oV6LGNuqfXj59xbV3fLAdh/6aeE7I<br>
hna0TysRDSi/bN+lE/JLyh+F8WDdr/uNb4Kzc+mTEd5vVqTp2Qlw5ctkQu9AcCxn<br>
Gk9khwhgRkxYfE/DF9RsFluRMacEaYMUNuectMz+ViCiLhYiLSBrcN9N6khSBIHZ<br>
o8ttvZBlt9ovlIu08dmuexcIVpIax8SHJj+lPWtuuRYNw/PB02hu3Pnm839nP0cD<br>
o8ZQPXkG7zvVgBVdMoVCGLWkMgw1T9P73+32TqTC7aAuY9mwRWhG3o2LZo+/Iicl<br>
Z/uIBT74SWzWZOdhzwdQdlXpmKXad1A8W7XxqfFLhea6WYmbj/MzHg==<br>
=bPXc<br>
<div><div></div><div class="h5">-----END PGP SIGNATURE-----<br>
<br>
_______________________________________________<br>
Full-Disclosure - We believe in it.<br>
Charter: <a href="http://lists.grok.org.uk/full-disclosure-charter.html" target="_blank">http://lists.grok.org.uk/full-disclosure-charter.html</a><br>
Hosted and sponsored by Secunia - <a href="http://secunia.com/" target="_blank">http://secunia.com/</a><br>
</div></div></blockquote></div><br>