Browser Security Bugs That Aren't: JavaScript in PDF
textslashplain.com
textslashplain.com
I like Safari's approach much more than having to hunt down some obscure browser setting or trust that it does the right thing.
Overall Safari and Firefox seem to be the best in terms of privacy and security.
https://madaidans-insecurities.github.io/firefox-chromium.ht...
I'm curious: what legitimate use cases exist for embedding a turing-complete scripting language into an image format?
PostScript, the printer file format, is Turing-complete, for different reasons.
ninja edit: It's also from a time when W3C started to lose focus and authority.
It's amazing that SVG was so successful despite this mess and also the confusion potential of CSS in SVG.
Browsers ignore scripts in external SVG images. Don't know if that is for security reasons (JS sandbox unreliable) or because a full isolated JS context per image would be to expensive...
The core issue iirc was that one of the major use cases for SVG was map/navigation systems where a number of environments required fully standardized systems. But they didn’t want to say implement a full browser stack”, so they just came up with their own “networking api” that was just “sockets!”.
A lot of this work predated html5, and the subsequent rationalization of web specs such that (for example) the xhr API was not fully specified, and it was not a separate specification from the rest of the browser stack, so SVG couldn’t just do what they could (in principle) do now.
The SVG WG was not the most functional - i recall that something a subset of the committee did at one point was to after the end of one person’s work day they rescheduled a meeting to later “that day” (while they were asleep) and took a vote without them present.
A number of other choices were made to the detriment of the spec for specific use cases (the various performance profiles have fundamentally incompatible rendering behavior rather than gradual decay, etc)
Funnily enough we did end up saying "implement a full browser stack" :/
Competing with flash?
SVG tries to be a lot of things, one of them was to be a full on interactive app.
That's how cursed enterprise software develops email clients and chat services. Just say no.
Since they can contain code, they can carry malicious code. PDFs have, in fact, been used for exploits. Meaning that you shouldn't really trust them. Which is a shame.
[1] https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
[2] https://techcrunch.com/2018/02/16/iphone-bug-telugu-unicode-...
Fixing other kinds of bugs is fairly straightforward. Update your toolchain, update your dependencies, use the right dependencies, avoid undefined behavior, etc. Fixing scripting issues means participating in an active arms race.
Yes. Bugs. Bugs can be fixed.
By-design (mis)features can't be fixed. The only way to fix them is by removing the feature.
Unless you're agreeing that JS-in-PDFs is a bug, you're conflating fundamentally different issues.
Yes, removing JS support would get rid of potential security exploits. It doesn't change the fact that said exploits rely on bugs in the implementation.
IMO it’s be nice to define a file format for PDFs main use (I think?), papers and documentation. PDF, scripting, but maybe the ability to zoom and pan figures?
PDF viewers can have a matching PDF/A mode where all non-PDF/A features are disabled.
> Instead, Firefox offers an individual pdfjs.enableScripting preference that can be configured from the about:flags page.
As a long time FF user I have never heard of about:flags and it does not work either. about:config contains the setting like a million of other ones that no ordinary mortal can ever manage.
Just a mistake in TFA or am I missing something?
In any case, its pretty similar in both cases. Even in the client side rendering case, if there is a sandbox you still have to escape it before your script execution is a real vuln.
Here you go: https://blog.invisiblethings.org/2013/02/21/converting-untru...
Converts incoming documents into a PDF that is a sequence of filtered/optimised images. Dangerzone will also handle office docs, epub, and a lot of different image formats (e.g. SVG and others that can possibly contain active content).
Sandboxes don't have network access, so if a malicious document can compromise one, it can't phone home
With a combo CSS, HTML, JS it is networkable from localhost.
(those are the only ones I have installed right now, I think)
Or there's poppler-utils which contains a bunch of tools for dealing with PDF files. You might be able to write a script which uses them to extract the contents into a safe format (maybe even a different PDF file?).
Issue is that PDF has turned into a form submitting for some US government agencies and other organizations. Until PDFs are no longer used for form submission and are transitioned to static documents they are a good exploit entry.