From: Nick FitzGerald [mailto:nick@virus-l.demon.co.uk]
Sent: Friday, December 04, 2009 1:51 PM
To: bugtraq@securityfocus.com
Subject: Re: Millions of PDF invisibly embedded with your internal disk paths
Ian Bradshaw wrote:
> This isn't a security issue its a privacy issue.
If the leaked, embedded paths can be things like UNCs or IP-based
internal server addresses, it is arguably a bit more than a privacy
Ian Bradshaw wrote:
> This isn't a security issue its a privacy issue.
If the leaked, embedded paths can be things like UNCs or IP-based
internal server addresses, it is arguably a bit more than a privacy
issue, allowing silent, external, partial mapping of the corporate
intranet.
Not good if your organization is in the habit of making lots of PDFs