On mySimon: Body Solid EXM 3000LPS
BNET Business Network:
BNET
TechRepublic
ZDNet

March 10th, 2009

Adobe PDF patch released, but only for some

Posted by Ryan Naraine @ 4:26 pm

Categories: Adobe, Arbitrary Code Execution, Browsers, Complex Attacks, Exploit code, Flash, Malware, Passwords, Patch Watch, Pen testing, Responsible disclosure, Viruses and Worms, Vulnerability research, Zero-day attacks

Tags: Adobe Systems Inc., Adobe PDF, Adobe Acrobat, Adobe Acrobat Reader, Security, Ryan Naraine

After weeks of swinging and missing on proper response to a gaping security hole in its ever-present PDF Reader software, Adobe has finally shipped a patch but only for some affected users.

On the same day Microsoft issued its scheduled batch of patches, Adobe dropped a security bulletin warning of a “critical” vulnerability in Adobe Reader 9 and Acrobat 9 and earlier versions.  However, if you are a user of one of those “earlier versions,” you’ll have to wait at least for another week.

[ SEE: Adobe swings and misses as PDF abuse worsens ]

The Adobe bulletin explains the severity:

  • This vulnerability would cause the application to crash and could potentially allow an attacker to take control of the affected system. There are reports that this issue is being exploited.

Only Adobe Reader 9 and Acrobat 9 is patched.

  • Adobe is planning to make available updates for Adobe Reader 7 and 8, and Acrobat 7 and 8, by March 18. In addition, Adobe plans to make available Adobe Reader 9.1 for Unix by March 25.

ALSO SEE:

Unofficial ‘patch’ for Adobe Reader, Acrobat zero-day

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 4 Talkback(s)
Not exactly
Sure its not Adobe, but I believe the poster was referring to FoxIT because it runs leaner, lighter, and faster than PDF. Like he said, at the time of the post - he could be patched already.

I... (Read the rest)
Posted by: JT82 Posted on: 03/11/09 You are currently: a Guest | | Terms of Use
Just switch to FoxIT  JoeMama_z | 03/10/09
Security by obscurity fails again  ejhonda | 03/11/09
RE: Adobe PDF patch released, but only for some  Gis Bun | 03/11/09
Not exactly  JT82 | 03/11/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc