Home » General News, PDF Reader

PDF Bomb

27 May 2008 | Rowan Hanna | No Comment

IT security professional Didier Stevens has highlighted a potential exploit in PDF Stream Objects which could be used to cause a PDF file to balloon in size, prompting Computerworld to label it the ‘PDF equivalent of the Zip bomb, or a PDF Bomb’.

Using filter parameters and filter cascading Stevens was able to create document that was only 2642 bytes in size, but when opened, decompressed to 1GB of data. This, as you can probably imagine, would cause some PDF readers to freeze up.

I recommend reading some of Didier Stevens other posts on security issues in PDFs as well.

No related posts.

1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...

Leave your response!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.