<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DigiCom &#187; Download Manager</title>
	<atom:link href="http://www.digicomgroup.com/tag/download-manager/feed" rel="self" type="application/rss+xml" />
	<link>http://www.digicomgroup.com</link>
	<description>digital digest</description>
	<lastBuildDate>Sat, 04 Feb 2012 10:31:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Adobe working to&#160;fix security bug&#160;in Download Manager</title>
		<link>http://www.digicomgroup.com/2010/02/22/82/index.html</link>
		<comments>http://www.digicomgroup.com/2010/02/22/82/index.html#comments</comments>
		<pubDate>Mon, 22 Feb 2010 15:34:50 +0000</pubDate>
		<dc:creator>vika</dc:creator>
				<category><![CDATA[Software]]></category>
		<category><![CDATA[Adobe Systems]]></category>
		<category><![CDATA[Download Manager]]></category>

		<guid isPermaLink="false">http://www.digicomgroup.com/?p=82</guid>
		<description><![CDATA[Adobe Systems is&#160;working to&#160;fix a&#160;glitch in&#160;software it&#160;uses to&#160;speed up&#160;downloads of&#160;its products that could give hackers a&#160;way to&#160;push malicious programs onto a&#160;victim&#8217;s PC. According to&#160;security researcher Aviv Raff, Download Manager&#160;&#8212; a&#160;small program Adobe users to&#160;speed up&#160;the initial installation of&#160;its products&#160;&#8212; can&#160;be misused to&#160;force victims to&#160;install unwanted software on&#160;their computers. Because of&#160;an undisclosed flaw in&#160;the way&#160;Download Manager [...]]]></description>
			<content:encoded><![CDATA[<p>Adobe Systems is&nbsp;working to&nbsp;fix a&nbsp;glitch in&nbsp;software it&nbsp;uses to&nbsp;speed up&nbsp;downloads of&nbsp;its products that could give hackers a&nbsp;way to&nbsp;push malicious programs onto a&nbsp;victim&#8217;s PC.<span id="more-82"></span></p>
<p>According to&nbsp;<a href="http://www.fxevolution.ru/161223786.html">security researcher</a> Aviv Raff, Download Manager&nbsp;&#8212; a&nbsp;small program Adobe users to&nbsp;speed up&nbsp;the initial installation of&nbsp;its products&nbsp;&#8212; can&nbsp;be misused to&nbsp;force victims to&nbsp;install unwanted software on&nbsp;their computers.</p>
<p>Because of&nbsp;an undisclosed flaw in&nbsp;the way&nbsp;Download Manager works, the&nbsp;&laquo;attacker can&nbsp;force an&nbsp;automatic download and&nbsp;installation of&nbsp;any executable he&nbsp;desires,&#8221; Raff wrote in&nbsp;a blog post. &laquo;So, if&nbsp;you go&nbsp;to Adobe&#8217;s Web&nbsp;site to&nbsp;install a&nbsp;security update for&nbsp;Flash, you&nbsp;really expose yourself to&nbsp;a zero-day attack.&#8221;</p>
<p>Adobe said Thursday that it&nbsp;was working with Raff and&nbsp;the third-party developer of&nbsp;the Download Manager product to&nbsp;fix the&nbsp;issue. Download Manager includes an&nbsp;executable program and&nbsp;an ActiveX control or&nbsp;Firefox extension file, depending on&nbsp;which browser is&nbsp;used.</p>
<p>However, it&nbsp;would be&nbsp;hard for&nbsp;a user to&nbsp;install unwanted software without realizing it, because &laquo;the user has&nbsp;to accept a&nbsp;number of&nbsp;prompts before being taken through the&nbsp;installation process,&#8221; said Wiebke Lips, an&nbsp;Adobe spokeswoman, in&nbsp;an e-mailed statement.</p>
<p>The Download Manager is&nbsp;different from Adobe&#8217;s Update Manger, which is&nbsp;used to&nbsp;patch Adobe software. Download Manager only runs on&nbsp;the computer when software is&nbsp;downloaded, and&nbsp;it removes itself on&nbsp;the next restart. So&nbsp;Raff&#8217;s attack would only work before that restart removed the&nbsp;Download Manager software.</p>
<p>Still, he&nbsp;believes it&nbsp;is a&nbsp;serious security risk. &laquo;This is&nbsp;the kind of&nbsp;scenario that&#8217;s common when skilled, motivated attackers are&nbsp;going after select targets,&#8221; Raff wrote on&nbsp;his blog.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.digicomgroup.com/2010/02/22/82/index.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

