ghacks Technology News

Unofficial Adobe Reader Patch Released

You might have read about a new vulnerability in Adobe Reader 9 and previous versions that is affecting all platforms and rated with a critical severity by Adobe. The vulnerability can be used to crash an application to allow an attacker to take control of the attacked computer system. Adobe announced plans to release the official patch for all affected products on March 11. That’s more than two weeks after the patch has been acknowledged by them and a serious problem considering that there are reports that the vulnerability is already exploited.

Lurene Grenier, a security researcher at Sourcefire, has published an unofficial patch for Adobe Reader 9 that is installed on a computer running the Microsoft Windows operating system. The patch comes with no guarantees and involves the replacement of a dll file in the Adobe Reader directory. Users should make sure to backup the dll before replacing it to be prepared for eventualities. Windows users with previous Adobe Reader versions will have to upgrade to Adobe Reader 9 before they can apply the patch.

There is another recommendation (by US-CERT)which is helpful for users of other operating systems or Windows users who do not like the idea of replacing a dll on the computer system:

  • Disabling Javascript in Adobe Reader by going to Edit > Preferences > JavaScript and unchecking enable Acrobat JavaScript.
  • Preventing IE from automatically displaying PDFs. This can be done via a Registry tweak described on the US-CERT notification.
  • Disable rendering of PDFs within web pages. This can be done from the Edit-Preferences menu in Adobe Reader.

It is recommended to act swiftly to prevent that the vulnerability can get exploited on the computer system. Users of third party PDF software programs are not affected by the vulnerability.

Update: Adobe has patched all Adobe Reader products in the meantime. Users who have updated the pdf reader cannot be attacked anymore.

Enjoyed the article?: Then sign-up for our free newsletter or RSS feed to kick off your day with the latest technology news and tips, or share the article with your friends and contacts on Facebook or Twitter.

Related Articles:

Adobe Patch Day Brings Fixes For Flash, Shockwave And Adobe Reader
Adobe Reader 9.3 Lite Released [PDF]
Critical Adobe Reader Update
Another Adobe Reader Zero Day Vulnerability In The Wild
Adobe release ‘critical’ Flash patch



About the Author:Martin Brinkmann is a journalist from Germany who founded Ghacks Technology News Back in 2005. He is passionate about all things tech and knows the Internet and computers like the back of his hand. You can follow Martin on Facebook or Twitter.

Author: , Tuesday February 24, 2009 -
Tags:, , ,


Responses so far:

  1. Transcontinental says:

    I always disable Adobe Javascript as I disable rendering of PDFs within web pages, but I ignored all of point (2), “preventing IE from automatically displaying PDFs” with a Registry hack. I would have imagined that disabing rendering of PDFs within web pages included that point as well … well, nops.

  2. iowagambling says:

    I don’t care, just fix the error

Leave a Reply   Follow Ghacks   Subscribe To Comment Rss

Subscribe without commenting

© 2005-2012 Ghacks.net. All Rights Reserved. Privacy Policy - About Us