On mySimon: Chinese Laundry Top Over-the-Knee Boots
BNET Business Network:
BNET
TechRepublic
ZDNet

June 24th, 2008

Adobe ships critical PDF Reader, Acrobat patch

Posted by Ryan Naraine @ 7:28 am

Categories: Adobe, Arbitrary Code Execution, Browsers, Data theft, Exploit code, Java, Microsoft, Patch Watch, Pen testing, Vulnerability research, Zero-day attacks

Tags: Adobe Systems Inc., Adobe PDF, Adobe Acrobat, Adobe Acrobat Reader, Patches, Security, Ryan Naraine

Adobe ships critical PDF Reader, Acobat patch Adobe has shipped a critical update to patch a code execution vulnerability affecting multiple versions of its Reader and Acrobat products.

According to Adobe’s advisory, the flaw “could potentially allow an attacker to take control of the affected system.”

If you have Adobe Reader or Acrobat installed on your machine, this update should be treated with the highest possible priority because the vulnerability is being exploited in the wild.

The patch is available for all platforms.  The affected products are:

  • Adobe Reader 8.0 through 8.1.2
  • Adobe Reader 7.0.9 and earlier
  • Adobe Acrobat Professional, 3D and Standard 8.0 through 8.1.2
  • Adobe Acrobat Professional, 3D and Standard 7.0.9 and earlier

Adobe Reader 7.1.0 and Acrobat 7.1.0 are not vulnerable to this issue.

From a separate SecurityFocus bulletin:

Adobe Acrobat and Reader are prone to a remote code-execution vulnerability because the application fails to sufficiently sanitize user-supplied input.

An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the application or crash the application, denying service to legitimate users.

 * Image source: existentist’s Flickr photostream (Creative Commons 2.0)

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 19 Talkback(s)
RE: Adobe ships critical PDF Reader, Acrobat patch
In my opinion the new version of Adobe Reader software is the global standard for electronic document sharing. It is the only PDF viewer that can open and interact with all PDF documents.... (Read the rest)
Posted by: yman25 Posted on: 09/26/08 You are currently: a Guest | | Terms of Use
Two words:  KTLA | 06/24/08
The Adobe monoculture  Ryan NaraineZDNet Moderator | 06/24/08
A backup by any other name...  Real World | 06/24/08
Gee, another Acrobat patch  jpr75_z | 06/24/08
Add Apple And Sun to That List  PMC-CON | 06/25/08
RE: Adobe ships critical PDF Reader, Acrobat patch  reverseswing | 06/24/08
Same here  balaknair | 06/26/08
RE: Adobe ships critical PDF Reader, Acrobat patch  rregier@... | 06/24/08
RE: Adobe ships critical PDF Reader, Acrobat patch  Dewy5 | 06/24/08
RE: Adobe ships critical PDF Reader, Acrobat patch  andrewfurb44@... | 06/25/08
Amen -- Adobe Didn't Contact This Registered USer Yet.  PMC-CON | 06/25/08
RE: Adobe ships critical PDF Reader, Acrobat patch  impcad | 06/25/08
RE: Adobe ships critical PDF Reader, Acrobat patch  Doctor Neutron | 06/25/08
Adobe Reader 8.0  bernie157 | 06/27/08
8.1.2 ??  GVC2031 | 06/25/08
re: 8.1.2??  JStR2855 | 06/25/08
RE: Adobe ships critical PDF Reader, Acrobat patch  Michael Horowitz | 06/29/08
RE: Adobe ships critical PDF Reader, Acrobat patch  meister2681 | 06/29/08
RE: Adobe ships critical PDF Reader, Acrobat patch  yman25 | 09/26/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline