<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; adobe acrobat</title> <atom:link href="http://www.ghacks.net/tag/adobe-acrobat/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Fri, 10 Feb 2012 20:51:26 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Here We Go Again: Yet Another Flash 0-day Vulnerability Emerges</title><link>http://www.ghacks.net/2011/04/12/here-we-go-again-yet-another-flash-0-day-vulnerability-emerges/</link> <comments>http://www.ghacks.net/2011/04/12/here-we-go-again-yet-another-flash-0-day-vulnerability-emerges/#comments</comments> <pubDate>Tue, 12 Apr 2011 09:05:30 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe flash]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[flash vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=43815</guid> <description><![CDATA[Flash player users, which is the majority of Internet users, do not come to rest in past years. There is seldom a month passing by without another Flash vulnerability. Adobe today released a security advisory warning for all Flash users that describes a critical security vulnerability in the popular software. Affected are more or less [...]]]></description> <content:encoded><![CDATA[<p>Flash player users, which is the majority of Internet users, do not come to rest in past years. There is seldom a month passing by without another Flash vulnerability. Adobe today released a security advisory warning for all Flash users that describes a critical security vulnerability in the popular software.</p><p>Affected are more or less all Flash users. This includes Flash installations on Windows, Mac and Linux, the built-in Flash Player of the Google Chrome browser, Flash on Android and Flash in Adobe Reader and Acrobat.</p><ul><li>Flash Player 10.2.153.1 and earlier versions on Windows, Mac, Linux, Solaris</li><li>Adobe Flash Player 10.2.154.25 and earlier for Chrome</li><li>Adobe Flash Player 10.2.156.12 and earlier versions for Android</li><li>Adobe Reader and Acrobat X (10.0.2) and earlier 10.x and 9.x versions for Windows and Macintosh operating systems</li></ul><p>Adobe confirmed reports that the vulnerability is actively exploited. The vulnerability uses embedded Flash files in Microsoft Word documents to exploit the issue. According to Adobe&#8217;s information those are delivered as email attachments and targeting the Windows platform.</p><p>Adobe Reader and Acrobat do not appear to be targeted right now. Adobe Reader X users are protected from this exploit by the program&#8217;s Protected Mode.</p><p>Adobe is currently finalizing a schedule for delivering updates for all affected versions of Flash Player except for Adobe Reader X which will receive the update on the next quarterly security update on June 14, 2011.</p><p>How can users protect their system from these kind of attacks? You should be cautious when you receive document attachments, especially if they come from unknown senders. Probably the best option in this case is to save those attachments to the computer, and open them in an online viewer such as Google Docs.</p><p>You could alternatively use a third party document viewer that does not support Flash, but the safest bet is an online viewer.</p><p>Interested users find <a
href="http://www.adobe.com/support/security/advisories/apsa11-02.html">additional information</a> about the newly discovered Flash vulnerability at the Adobe Security Bulletin.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/04/12/here-we-go-again-yet-another-flash-0-day-vulnerability-emerges/feed/</wfw:commentRss> <slash:comments>10</slash:comments> </item> <item><title>New Critical 0-day Flash Vulnerability Exploited Via Excel Attachments</title><link>http://www.ghacks.net/2011/03/14/new-critical-0-day-flash-vulnerability-exploited-via-excel-attachments/</link> <comments>http://www.ghacks.net/2011/03/14/new-critical-0-day-flash-vulnerability-exploited-via-excel-attachments/#comments</comments> <pubDate>Mon, 14 Mar 2011 19:46:36 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe flash]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[security vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=42506</guid> <description><![CDATA[Adobe today has released a new security advisory for Adobe Flash Player, Adobe Reader and Acrobat. All three applications are affected by a critical 0-day vulnerability that is exploited via Excel email attachments. Vulnerable versions are Adobe Flash Player 10.2.154.33 and earlier for all supported desktop operating systems, Adobe Flash Player 10.1.106.16 and earlier for [...]]]></description> <content:encoded><![CDATA[<p>Adobe today has released a new security advisory for Adobe Flash Player, Adobe Reader and Acrobat. All three applications are affected by a critical 0-day vulnerability that is exploited via Excel email attachments. Vulnerable versions are Adobe Flash Player 10.2.154.33 and earlier for all supported desktop operating systems, Adobe Flash Player 10.1.106.16 and earlier for Android and Adobe Reader and Acrobat X, 10.x and 9.x for Windows and Macintosh.</p><p>Adobe has confirmed reports that the vulnerability is actively exploited via swf files that are embedded in Microsoft Excel files that are delivered via email attachments. A successful exploit causes a crash of the application and could give an attacker control over the computer system.</p><p>A security fix is in the final stages of development, and Adobe estimates that it can be distributed during the next week. Computer users for now should be very cautious when they receive emails with Excel attachments, especially if the sender is unknown. It may be a good idea to open the documents online, for instance via Google Docs instead of a desktop client to block potential attacks.</p><p>Protected Mode of Adobe Reader X mitigates the issue according to Adobe, so that the security fix for that version will be delivered with the quarterly security update that is scheduled for June 14.</p><p>In short:</p><ul><li>All Flash Player versions 10 are affected for all supported desktop and mobile operating systems.</li><li>All versions of Adobe Reader and Acrobat X, 10 and 9 are affected</li><li>The vulnerability is exploited via Excel email attachments that have a Flash file embedded.</li><li>A patch will be delivered in the next week</li></ul><p>Additional information are available at the <a
href="http://www.adobe.com/support/security/advisories/apsa11-01.html">Security Advisory</a> over at Adobe&#8217;s website.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/03/14/new-critical-0-day-flash-vulnerability-exploited-via-excel-attachments/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Adobe Security Bulletin Summary Feburary 2011</title><link>http://www.ghacks.net/2011/02/09/adobe-security-bulletin-summary-feburary-2011/</link> <comments>http://www.ghacks.net/2011/02/09/adobe-security-bulletin-summary-feburary-2011/#comments</comments> <pubDate>Wed, 09 Feb 2011 08:23:40 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe flash player]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=39719</guid> <description><![CDATA[Adobe Software yesterday released updates for some of its popular software applications, including updates for Adobe Reader, Acrobat and the Adobe Flash Player. The updates address critical security issues in the products making them mandatory updates for all users of said products. The security update for Adobe Flash Player fixes several critical vulnerability in Flash [...]]]></description> <content:encoded><![CDATA[<p>Adobe Software yesterday released updates for some of its popular software applications, including updates for Adobe Reader, Acrobat and the Adobe Flash Player. The updates address critical security issues in the products making them mandatory updates for all users of said products.</p><p>The security update for Adobe Flash Player fixes several critical vulnerability in Flash Player 10.1.102.64 and earlier on Windows, Macintosh, Linux and Solaris. Successful exploits could &#8220;cause the application to crash and could potentially allow an attacker to take control of the affected system&#8221;.</p><p>The update increases the version of the application to Adobe Flash Player 10.2.152.26 on all affected systems.</p><p>The update can be downloaded <a
href="http://get.adobe.com/flashplayer/">directly</a> from Adobe.</p><p>More information about the update are <a
href="http://www.adobe.com/support/security/bulletins/apsb11-02.html">available</a> on Adobe&#8217;s Security Bulletin page.</p><h3>Adobe Reader, Acrobat</h3><p>Critical vulnerabilities have also been identified in Adobe Reader and Acrobat. Affected versions include Adobe Reader X, Adobe Reader 9.4.1 for Windows, Macintosh and Unix, and Adobe Acrobat X and earlier for Windows and Macintosh. Please note that the update incorporates the Adobe Flash Player update.</p><p>The vulnerabilities &#8220;could cause the application to crash and potentially allow an attacker to take control of the affected system. Risk for Adobe Reader X users is significantly lower, as none of these issues bypass Protected Mode mitigations&#8221;.</p><p>Updates are available to increase the version of Adobe Reader X to 10.0.1, Adobe Reader 9.4.1 to 9.4.2 and Adobe Acrobat X to 10.0.1.</p><p>Download links for all affected applications are <a
href="http://www.adobe.com/support/security/bulletins/apsb11-03.html">posted</a> on the security bulletin page over at Adobe.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/02/09/adobe-security-bulletin-summary-feburary-2011/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Adobe Patches, And Reports New Vulnerabilities</title><link>http://www.ghacks.net/2010/11/05/adobe-patches-and-reports-new-vulnerabilities/</link> <comments>http://www.ghacks.net/2010/11/05/adobe-patches-and-reports-new-vulnerabilities/#comments</comments> <pubDate>Fri, 05 Nov 2010 11:31:41 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[flash player]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=36568</guid> <description><![CDATA[Adobe&#8217;s Flash Player was updated yesterday fixing several security vulnerabilities in the process. The patch was initially slated for a November 9 release but released in advance yesterday. But Adobe Flash was not the only vulnerable Adobe product. Adobe has scheduled an update for their popular pdf readers Adobe Reader and Adobe Acrobat on November [...]]]></description> <content:encoded><![CDATA[<p>Adobe&#8217;s Flash Player was updated yesterday fixing several security vulnerabilities in the process. The patch was initially slated for a November 9 release but released in advance yesterday. But Adobe Flash was not the only vulnerable Adobe product. Adobe has scheduled an update for their popular pdf readers Adobe Reader and Adobe Acrobat on November 15 to fix an actively exploited vulnerability.</p><p>To make matters worse, a new vulnerability has been confirmed by Adobe affecting Adobe Reader 9.2 or later and Adobe Reader 8.1.7 or later. A &#8220;proof-of-concept file demonstrating a Denial of Service was published&#8221; already that crashes the pdf reader.  The exploit does not demonstrate arbitrary code execution, but Adobe is not eliminating the possibility at this point in time. It has to be noted that Adobe Acrobat is not affected by the security vulnerability.</p><p>The blog post <a
href="http://blogs.adobe.com/psirt/2010/11/potential-issue-in-adobe-reader.html">of the</a> Security and Response team offers instructions on how to protect the computer system from this vulnerability.</p><blockquote><p>Adobe Reader 9.2 and later and Adobe Reader 8.1.7 and later – Windows</p><p>On Windows, the JavaScript Blacklist can be in two locations. Please review the following options and then create the registry key of your choice:</p><p>Enterprise list: This blacklist helps enterprises roll out policies that block exploitable API(s) from executing in their environment. Populating the blacklist in this location is the responsibility of the enterprise. Adobe patches never modify this registry location.<br
/> To create the registry key:<br
/> HKLM\SOFTWARE\Policies\Adobe\&lt;product&gt;\&lt;version&gt;\FeatureLockDown\cJavaScriptPerms\tBlackList</p><p>Adobe’s update/patch list: The Adobe blacklist is modified by Adobe Reader patches whenever an API is deemed vulnerable. APIs are also removed from the blacklist whenever a fix for a vulnerability is provided by the current patch.<br
/> To create the registry key:<br
/> HKLM\SOFTWARE\Adobe\&lt;product&gt;\&lt;version&gt;\JavaScriptPerms\tBlackList</p><p> On a 64 bit Windows system, the path is:<br
/> HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Adobe</p><p>->To prevent this particular issue, add the following value to the registry key created in the previous step (case sensitive):<br
/> Doc.printSeps</p><p>->Exit and restart the application</p><p>Adobe Reader 9.2 and later and Adobe Reader 8.1.7 and later – Macintosh</p><p> On your Macintosh computer, go to the Applications folder or to the location where you have Adobe Reader installed.<br
/> Right-click on Adobe Reader<br
/> Click on Show Package Contents<br
/> Expand Contents<br
/> Expand MacOS<br
/> Expand Preferences<br
/> Create a backup of the FeatureLockDown file.<br
/> Right-click on FeatureLockDown.<br
/> Open With TextEdit.<br
/> Just before the last >> add the following line to the FeatureLockDown file (case sensitive):<br
/> /JavaScriptPerms [ /c &lt;&lt; /BlackList [ /t (Doc.printSeps) ] &gt;&gt; ]<br
/> Save the file<br
/> Restart Adobe Reader</p><p>Adobe Reader 9.2 and later – UNIX</p><p> Go to the Global Prefs file at:<br
/> /Reader/GlobalPrefs/reader_prefs<br
/> Add the following line to the file:<br
/> /JavaScriptPerms [/c << /BlackList [/t (Doc.printSeps) ] >> ]</p></blockquote><p>There you have it. Make sure you protect your version of Adobe Reader from the vulnerability by following the instructions posted above. The posting does not offer any information on the consequences of protecting the pdf reader from the vulnerability. It is also not clear if Adobe will be able to include the patch for this vulnerability in the upcoming update.</p><p>As if that was not enough, there is <a
href="http://secunia.com/advisories/42112/">also a new</a> vulnerability in Adobe Shockwave Player.</p><blockquote><p>Krystian Kloskowski has discovered a vulnerability in Shockwave Player, which can be exploited by malicious people to compromise a user&#8217;s system.</p><p>The vulnerability is caused due to a use-after-free error in an automatically installed compatibility component as a function in an unloaded library may be called.</p><p>Successful exploitation allows execution of arbitrary code, but requires that a user is tricked into opening the &#8220;Shockwave Settings&#8221; window when viewing a web page.</p><p>The vulnerability is confirmed in version 11.5.9.615. Other versions may also be affected.</p></blockquote><p>The description makes it clear that systems are only vulnerable to this attack if the user opens the Shockwave Settings window on a specially prepared website.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/11/05/adobe-patches-and-reports-new-vulnerabilities/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>New 0-day Adobe Vulnerabilities</title><link>http://www.ghacks.net/2010/10/29/new-0-day-adobe-vulnerabilities/</link> <comments>http://www.ghacks.net/2010/10/29/new-0-day-adobe-vulnerabilities/#comments</comments> <pubDate>Fri, 29 Oct 2010 08:12:15 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe flash security]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <category><![CDATA[flash player]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=36334</guid> <description><![CDATA[It has been a bad year for Adobe&#8217;s security team, as Adobe products where hit with many critical security vulnerabilities in that time. The latest was just announced yesterday in a security advisory over at Adobe. The critical vulnerability affects both Adobe Flash Player versions 10.1.85.3 and earlier on all supported operating systems (that&#8217;s Windows, [...]]]></description> <content:encoded><![CDATA[<p>It has been a bad year for Adobe&#8217;s security team, as Adobe products where hit with many critical security vulnerabilities in that time. The latest was just announced yesterday in a security advisory over at Adobe. The critical vulnerability affects both Adobe Flash Player versions 10.1.85.3 and earlier on all supported operating systems (that&#8217;s Windows, Mac, Linux, Solaris and Android [gasp]) and Adobe Reader 9.4 and earlier 9.x versions on Windows, Mac and Unix.</p><p>Basically, both Flash Player and Adobe Reader / Acrobat are affected by the security vulnerability. According to Adobe&#8217;s security bulletin, the issue is actively exploited against Adobe Reader and Acrobat on Windows.</p><p><a
href="http://www.adobe.com/support/security/advisories/apsa10-05.html">Adobe</a> is currently working on patches and aims to release the Flash Player patch on November 9, 2010 and the Adobe Reader / Acrobat patch on November 15, 2010. That&#8217;s puzzling considering that the company has admitted that the issue is actively exploited against Adobe Reader and Acrobat.</p><p>Mitigations were posted to protect the computer system.</p><blockquote><p>Deleting, renaming, or removing access to the authplay.dll file that ships with Adobe Reader and Acrobat 9.x mitigates the threat for those products, but users will experience a non-exploitable crash or error message when opening a PDF file that contains Flash (SWF) content. The authplay.dll that ships with Adobe Reader and Acrobat 9.x for Windows is typically located at C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll for Adobe Reader or C:\Program Files\Adobe\Acrobat 9.0\Acrobat\authplay.dll for Acrobat.</p></blockquote><p>No mitigating factors were offered for the Flash vulnerability. The only ones that are known to work are to either disable Adobe Flash in the browser, or to use a flash blocking script such as NoScript for Firefox.</p><p><a
href="http://www.theregister.co.uk/2010/10/28/adobe_reader_critical_vuln/">The Register</a> has additional information about the pdf exploit. According to their information, attackers &#8220;install a nasty trojan known as Wisp, which according to Microsoft, steals sensitive user data and installs a backdoor on compromised systems.&#8221;</p><p>With patches as far away as two weeks, it is recommended to disable authplay.dll in Adobe Reader or Acrobat, and disable or block the Flash plugin in the web browser to protect the computer system against these attacks.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/10/29/new-0-day-adobe-vulnerabilities/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Adobe Reader 9.4 Download Available</title><link>http://www.ghacks.net/2010/10/06/adobe-reader-9-4-download-available/</link> <comments>http://www.ghacks.net/2010/10/06/adobe-reader-9-4-download-available/#comments</comments> <pubDate>Wed, 06 Oct 2010 08:25:29 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader update]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[pdf reader]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=35618</guid> <description><![CDATA[Adobe has just released an update for their popular pdf reader Adobe Reader and Adobe Acrobat, raising versions of the two programs to 9.4. Both program updates fix critical security vulnerabilities identified in Adobe Reader 9.3.4 and earlier, as well as Acrobat 9.3.4 and earlier. Vulnerabilities affect all supported operating systems, and users are encouraged [...]]]></description> <content:encoded><![CDATA[<p>Adobe has just released an update for their popular pdf reader Adobe Reader and Adobe Acrobat, raising versions of the two programs to 9.4. Both program updates fix critical security vulnerabilities identified in Adobe Reader 9.3.4 and earlier, as well as Acrobat 9.3.4 and earlier. Vulnerabilities affect all supported operating systems, and users are encouraged to upgrade their version as soon as possible to protect their computer system from exploits.</p><p>The rushed state of the release indicates that the issue gets actively exploited which is confirmed in Adobe&#8217;s Security Bulletin that mentions that the issue is being actively exploited in the wild. Attackers may be able to crash the application on the computer and take control of the affected system in the process. Upgrading is the only way of protecting the computer from those vulnerabilities.</p><blockquote><p>Adobe recommends users of Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX update to Adobe Reader 9.4. (For Adobe Reader users on Windows and Macintosh,<br
/> who cannot update to Adobe Reader 9.4, Adobe has provided the Adobe Reader 8.2.5 update.) Adobe recommends users of Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh update to Adobe Acrobat 9.4. Adobe recommends users of Adobe Acrobat 8.2.4 and earlier versions for Windows and Macintosh update to Adobe Acrobat 8.2.5.</p></blockquote><p>This accelerated patch breaks Adobe&#8217;s quarterly patch day that is set for every second Tuesday of each quarter of the year to fall in line with Microsoft&#8217;s Patch Tuesday. Interested users can take a closer look at the <a
href="http://www.adobe.com/support/security/bulletins/apsb10-21.html">Security Bulletin</a>, or point their web browsers to <a
href="http://get.adobe.com/reader/">Get Adobe Reader</a> right away to download the latest version of the pdf reader. Updates are also available directly in the program (by clicking on Help > Check for Updates).</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/10/06/adobe-reader-9-4-download-available/feed/</wfw:commentRss> <slash:comments>7</slash:comments> </item> <item><title>Another Adobe Reader Zero-Day Vulnerability Emerges</title><link>http://www.ghacks.net/2010/08/06/another-adobe-reader-zero-day-vulnerability-emerges/</link> <comments>http://www.ghacks.net/2010/08/06/another-adobe-reader-zero-day-vulnerability-emerges/#comments</comments> <pubDate>Fri, 06 Aug 2010 08:08:51 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <category><![CDATA[pdf]]></category> <category><![CDATA[pdf reader]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=32092</guid> <description><![CDATA[What is it with Adobe Reader and vulnerabilities? It feels like new security vulnerabilities are found in the software at an accelerated pace this year. Adobe yesterday released a security advisory for Adobe Reader and Acrobat, to announce to the world that critical security vulnerabilities have been found &#8211; once again &#8211; in Adobe Reader [...]]]></description> <content:encoded><![CDATA[<p>What is it with Adobe Reader and vulnerabilities? It feels like new security vulnerabilities are found in the software at an accelerated pace this year. Adobe yesterday released a security advisory for Adobe Reader and Acrobat, to announce to the world that critical security vulnerabilities have been found &#8211; once again &#8211; in Adobe Reader and Adobe Acrobat.</p><p>Adobe expects to make the updates &#8220;available during the week of August 16, 2010&#8243;, which does mean that millions of computer systems running either Adobe Reader or Adobe Acrobat are left vulnerable for the time being.</p><p><span
id="more-32092"></span><br
/><blockquote>Adobe is planning to release updates for Adobe Reader 9.3.3 for Windows, Macintosh and UNIX, Adobe Acrobat 9.3.3 for Windows and Macintosh, and Adobe Reader 8.2.3 and Acrobat 8.2.3 for Windows and Macintosh to resolve critical security issues, including CVE-2010-2862 which was discussed at the Black Hat USA 2010 security conference on Wednesday, July 28, 2010. Adobe expects to make these updates available during the week of August 16, 2010</p></blockquote><p><a
href="http://www.adobe.com/support/security/bulletins/apsb10-17.html">The</a> security advisory does not reveal information about the vulnerabilities, only that one was discussed at last month&#8217;s Black Hat USA 2010 security conference, that all platforms are affected, and that Adobe Reader 9.3.3 and earlier, and Adobe Acrobat 9.3.3 and earlier are affected.</p><p>The advisory over at <a
href="http://secunia.com/advisories/40766">Secunia</a> reveals additional details about the vulnerability discussed at the Black Hat conference. The Adobe Reader / Acrobat Font Parsing Integer Overflow Vulnerability has been rated as highly critical, the second highest possible rating.</p><blockquote><p>The vulnerability is caused due to an integer overflow error in CoolType.dll when parsing the &#8220;maxCompositePoints&#8221; field value in the &#8220;maxp&#8221; (Maximum Profile) table of a TrueType font. This can be exploited to corrupt memory via a PDF file containing a specially crafted TrueType font.</p></blockquote><p>Successful exploits may allow remote code execution on the targeted system.</p><p>Users with Adobe Reader or Adobe Acrobat installed may want to consider switching to another pdf reader for the time being, to protect their computer system from those vulnerabilities. Alternatives are listed on our <a
href="http://www.ghacks.net/2010/07/02/pdf-reader-rendering-quality-comparison-which-is-the-best/">pdf reader comparison</a> page.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/08/06/another-adobe-reader-zero-day-vulnerability-emerges/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Adobe Updates Security Advisory, Promises Patches Soon</title><link>http://www.ghacks.net/2010/06/08/adobe-updates-security-advisory-promises-patches-soon/</link> <comments>http://www.ghacks.net/2010/06/08/adobe-updates-security-advisory-promises-patches-soon/#comments</comments> <pubDate>Tue, 08 Jun 2010 08:04:07 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe vulnerability]]></category> <category><![CDATA[flash player]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=26314</guid> <description><![CDATA[Critical vulnerabilities that affected Adobe&#8217;s flagship products Adobe Reader, Acrobat and Flash Player were revealed in a security advisory by the Adobe Product Incident Response Team. The vulnerability affects Flash Player 10 and 9 as well as Adobe Reader 9 and Acrobat 9 which covers the majority of the install base. The vulnerabilities received a [...]]]></description> <content:encoded><![CDATA[<p><a
href="http://www.ghacks.net/2010/06/05/critical-adobe-reader-and-flash-vulnerabilities-emerge/">Critical vulnerabilities</a> that affected Adobe&#8217;s flagship products Adobe Reader, Acrobat and Flash Player were revealed in a security advisory by the Adobe Product Incident Response Team. The vulnerability affects Flash Player 10 and 9 as well as Adobe Reader 9 and Acrobat 9 which covers the majority of the install base.</p><p>The vulnerabilities received a severity rating of highly critical, the highest possible rating, by Secunia since they were both actively exploited and would allow remote code execution on affected computer systems.</p><p><span
id="more-26314"></span>Adobe&#8217;s Response Team has <a
href="http://www.adobe.com/support/security/advisories/apsa10-01.html">updated</a> the security vulnerability with the planned schedule for a patch to resolve the issue.</p><p>According to those information a patch for Flash Player 10 will be released on June 10 while Adobe Reader and Acrobat 9 users have to wait until June 29 for the patch.</p><p>The patches will be made available for all supported operating systems with the exception of Flash Player for Solaris.</p><p>The delay until the page becomes available is bad news for Adobe Reader and Acrobat users who have to find ways to protect their systems from the security vulnerability in the meantime.</p><p>Adobe is offering mitigation instructions on their website for Windows, Unix and Macintosh.</p><p>Adobe Reader and Acrobat &#8211; Windows</p><blockquote><p>Deleting, renaming, or removing access to the authplay.dll file that ships with Adobe Reader 9.x and Acrobat 9.x mitigates the threat for those products, but users will experience a non-exploitable crash or error message when opening a PDF file that contains SWF content.</p><p>The authplay.dll that ships with Adobe Reader 9.x and Acrobat 9.x for Windows is typically located at C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll for Adobe Reader or C:\Program Files\Adobe\Acrobat 9.0\Acrobat\authplay.dll for Acrobat.</p></blockquote><p>Adobe Reader 9.x &#8211; Macintosh</p><blockquote><p>1) Go to the Applications->Adobe Reader 9 folder.<br
/> 2) Right Click on Adobe Reader<br
/> 3) Select Show Package Contents<br
/> 4) Go to the Contents->Frameworks folder<br
/> 5) Delete or move the AuthPlayLib.bundle file</p></blockquote><p>Acrobat Pro 9.x &#8211; Macintosh</p><blockquote><p>1) Go to the Applications->Adobe Acrobat 9 Pro folder.<br
/> 2) Right Click on Adobe Acrobat Pro<br
/> 3) Select Show Package Contents<br
/> 4) Go to the Contents->Frameworks folder<br
/> 5) Delete or move the AuthPlayLib.bundle file</p></blockquote><p>Adobe Reader 9.x- UNIX</p><blockquote><p>1) Go to installation location of Reader (typically a folder named Adobe)<br
/> 2) Within it browse to Reader9/Reader/intellinux/lib/ (for Linux) or Reader9/Reader/intelsolaris/lib/ (for Solaris)<br
/> 3) Remove the library named &#8220;libauthplay.so.0.0.0&#8243;</p></blockquote><p>It is recommended to either perform the operations on affected computer systems or switch to another pdf reader at least for the time until the vulnerability gets fixed.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/06/08/adobe-updates-security-advisory-promises-patches-soon/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Critical Adobe Reader And Flash Vulnerabilities Emerge</title><link>http://www.ghacks.net/2010/06/05/critical-adobe-reader-and-flash-vulnerabilities-emerge/</link> <comments>http://www.ghacks.net/2010/06/05/critical-adobe-reader-and-flash-vulnerabilities-emerge/#comments</comments> <pubDate>Sat, 05 Jun 2010 20:39:03 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[flash player vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=26221</guid> <description><![CDATA[Two new vulnerabilities affecting the Adobe products Adobe Reader and Adobe Flash were reported by Secunia earlier this day. They have in common that they have been both rated as extremely critical, the highest available severity rating for vulnerabilities posted at Secunia. Highly critical is a rating for &#8220;remotely exploitable vulnerabilities that can lead to [...]]]></description> <content:encoded><![CDATA[<p>Two new vulnerabilities affecting the Adobe products Adobe Reader and Adobe Flash were reported by <a
href="http://secunia.com/">Secunia</a> earlier this day. They have in common that they have been both rated as extremely critical, the highest available severity rating for vulnerabilities posted at Secunia.</p><p>Highly critical is a rating for &#8220;remotely exploitable vulnerabilities that can lead to system compromise&#8221; that usually do not &#8220;require any interaction&#8221; and where exploits are already in the wild.</p><p>The Adobe Flash vulnerability that has been reported is affecting Adobe Flash Player 10.x and Adobe Flash Player 9.x.</p><p><span
id="more-26221"></span><br
/><blockquote>A vulnerability has been reported in Adobe Flash Player, which can be exploited by malicious people to compromise a user&#8217;s system.</p><p>The vulnerability is caused due to an unspecified error. No more information is currently available.</p><p>Successful exploitation allows execution of arbitrary code.</p><p>The vulnerability is reported in version 10.0.45.2 and prior 10.0.x and 9.0.x versions for Windows, Macintosh, Linux, and Solaris.</p><p>NOTE: The vulnerability is reportedly being actively exploited.</p></blockquote><p>The release candidate of the upcoming Adobe Flash Player 10.1 does not seem to be affected by the vulnerability according to the information <a
href="http://secunia.com/advisories/40026">at</a> the Secunia website.</p><p>Users who want to protect their computer system from being exploited by the vulnerability can either disable Adobe Flash for the time being or <a
href="http://labs.adobe.com/downloads/flashplayer10.html">update to</a> the Adobe Flash Player 10.1 Release Candidate. Additional information about the vulnerability are posted in a Security Bulletin <a
href="http://www.adobe.com/support/security/advisories/apsa10-01.html">at the</a> Adobe website.</p><p>The Adobe Reader and Adobe Acrobat vulnerability might be related to the Adobe Flash vulnerability. The <a
href="http://secunia.com/advisories/40034">Secunia Advisory</a> lists Adobe Reader 9 versions for Windows, Macintosh and Linux as affected by the vulnerability.</p><blockquote><p>The vulnerability is caused due to a vulnerable bundled version of Flash Player (authplay.dll).Successful exploitation allows execution of arbitrary code.</p><p>The vulnerability is reported in version 9.3.2 and earlier 9.x versions for Windows, Macintosh, and UNIX.</p><p>NOTE: The vulnerability is currently being actively exploited.</p></blockquote><p>The temporary solution to protect the computer system from the exploits is to delete, rename or remove access to autoplay.dll to prevent Flash content from being executed in Adobe Reader and Acrobat.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/06/05/critical-adobe-reader-and-flash-vulnerabilities-emerge/feed/</wfw:commentRss> <slash:comments>7</slash:comments> </item> <item><title>Adobe Reader 9.3.2 Security Update Released</title><link>http://www.ghacks.net/2010/04/13/adobe-reader-9-3-2-security-update-released/</link> <comments>http://www.ghacks.net/2010/04/13/adobe-reader-9-3-2-security-update-released/#comments</comments> <pubDate>Tue, 13 Apr 2010 19:06:06 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader update]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[pdf reader]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=24522</guid> <description><![CDATA[Adobe, just like Microsoft, releases security updates on a schedule unless a vulnerability is actively exploited on a large scale and requires immediate attention. Updates for their pdf readers Adobe Reader and Acrobat have been released today that fix several security vulnerabilities. The critical vulnerabilities are affecting all operating systems that Adobe Reader is compatible [...]]]></description> <content:encoded><![CDATA[<p>Adobe, just like <a
href="http://www.ghacks.net/2010/04/13/microsoft-security-updates-april-2010/">Microsoft</a>, releases security updates on a schedule unless a vulnerability is actively exploited on a large scale and requires immediate attention. Updates for their pdf readers Adobe Reader and Acrobat have been released today that fix several security vulnerabilities.</p><p>The critical vulnerabilities are affecting all operating systems that Adobe Reader is compatible with (Microsoft Windows, Apple Macintosh and Unix based) and versions of Adobe Reader 9.3.1 and Adobe Acrobat 9.3.1 or earlier.</p><p>The critical nature of the vulnerabilities requires immediate attention from users who have affected software versions installed on their computer systems.</p><p><span
id="more-24522"></span>Adobe is offering the update through various channels. It is possible to check for updates from within the pdf readers by clicking on Help > Check for updates or to download the updates from the official Adobe website.</p><blockquote><p>Adobe Reader users on Windows can also find the appropriate update here:<br
/> http://www.adobe.com/support/downloads/product.jsp?product=10&#038;platform=Windows.</p><p>Adobe Reader users on Macintosh can also find the appropriate update here:<br
/> http://www.adobe.com/support/downloads/product.jsp?product=10&#038;platform=Macintosh.</p><p>Adobe Reader users on UNIX can find the appropriate update here:<br
/> ftp://ftp.adobe.com/pub/adobe/reader/unix/9.x/9.3.2/.</p></blockquote><p>The update is still separated from the full version of Adobe Reader that is offered on the Adobe homepage. There is still no full version of Adobe Reader 9.3.2 available on the Adobe homepage which still offers Adobe Reader 9.3.0 to visitors.</p><p>Users who want to find out more about the security vulnerabilities can <a
href="http://www.adobe.com/support/security/bulletins/apsb10-09.html">check out</a> the security bulletin that contains detailed information about the vulnerabilities that are closed with the new release.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/04/13/adobe-reader-9-3-2-security-update-released/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Adobe Reader And Acrobat Get Yet Another Security Update</title><link>http://www.ghacks.net/2010/02/17/adobe-reader-and-acrobat-get-yet-another-security-update/</link> <comments>http://www.ghacks.net/2010/02/17/adobe-reader-and-acrobat-get-yet-another-security-update/#comments</comments> <pubDate>Tue, 16 Feb 2010 22:12:58 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader update]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=23123</guid> <description><![CDATA[Adobe Reader and Adobe Flash seem to be two of the most targeted software programs by malicious software and hackers besides the Microsoft Windows operating system and Internet Explorer. It is rare that a month passes by without yet another update that fixes a security vulnerability in Adobe Reader or Acrobat. Today a critical vulnerability [...]]]></description> <content:encoded><![CDATA[<p>Adobe Reader and Adobe Flash seem to be two of the most targeted software programs by malicious software and hackers besides the Microsoft Windows operating system and Internet Explorer. It is rare that a month passes by without yet another update that fixes a security vulnerability in Adobe Reader or Acrobat.</p><p>Today a critical vulnerability was disclosed that is affecting all Adobe Reader 9.3 and earlier and Adobe Acrobat 9.3 and earlier versions on Windows and Macintosh. The Adobe Reader 9.3 or earlier Unix versions are also vulnerable.</p><p><span
id="more-23123"></span><br
/><blockquote>As described in Security Bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb10-06.html">APSB10-06</a>, this vulnerability (CVE-2010-0186) could subvert the domain sandbox and make unauthorized cross-domain requests. In addition, a critical vulnerability (CVE-2010-0188) has been identified that could cause the application to crash and could potentially allow an attacker to take control of the affected system.</p><p>In addition, a critical vulnerability (CVE-2010-0188) has been identified that could cause the application to crash and could potentially allow an attacker to take control of the affected system.</p></blockquote><p>Adobe has reacted promptly this time as updates for Adobe Reader and Acrobat are already available for download and installation. It is suggested to download the new releases as soon as possible to protect the computer system from the security vulnerability.</p><p>The security bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb10-07.html">posted</a> at the Adobe website contains download links for all supported operating systems.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/02/17/adobe-reader-and-acrobat-get-yet-another-security-update/feed/</wfw:commentRss> <slash:comments>7</slash:comments> </item> <item><title>Microsoft and Adobe January 2010 Patch Day</title><link>http://www.ghacks.net/2010/01/13/microsoft-and-adobe-january-2010-patch-day/</link> <comments>http://www.ghacks.net/2010/01/13/microsoft-and-adobe-january-2010-patch-day/#comments</comments> <pubDate>Wed, 13 Jan 2010 16:43:46 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Microsoft]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[adobe update]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft update]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=22289</guid> <description><![CDATA[Microsoft and Adobe have released their regular security updates today. Microsoft has only released one patch for most of its operating system. The patch fixes a vulnerability in the embedded OpenType font engine that could allow remote code execution. The rating of this vulnerability is low for all operating systems but Microsoft Windows 2000 Service [...]]]></description> <content:encoded><![CDATA[<p>Microsoft and Adobe have released their regular security updates today. Microsoft has only released one patch for most of its operating system. The patch fixes a vulnerability in the embedded OpenType font engine that could allow remote code execution. The rating of this vulnerability is low for all operating systems but Microsoft Windows 2000 Service Pack 4.</p><ul><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-001.mspx">MS10-001</a> &#8211; Critical  Vulnerability in the Embedded OpenType Font Engine Could Allow Remote Code Execution (972270) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user viewed content rendered in a specially crafted Embedded OpenType (EOT) font in client applications that can render EOT fonts, such as Microsoft Internet Explorer, Microsoft Office PowerPoint, or Microsoft Office Word. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs, view, change, or delete data, or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<p>This security update is rated Critical for Microsoft Windows 2000, and is rated Low for Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2.</li></ul><p><span
id="more-22289"></span>Adobe <a
href="http://www.adobe.com/support/security/bulletins/apsb10-02.html">has</a> released security updates for Adobe Reader and Adobe Acrobat which patch critical vulnerability in Adobe Reader 9.2 and Adobe Acrobat 9.2 for Windows, Macintosh and Unix as well as Adobe Reader 8.1.7 and Acrobat 8.1.7 for Windows and Macintosh.</p><ul><li>These vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system. Adobe recommends users of Adobe Reader 9.2 and Acrobat 9.2 and earlier versions for Windows, Macintosh and UNIX update to Adobe Reader 9.3 and Acrobat 9.3. Adobe recommends users of Acrobat 8.1.7 and earlier versions for Windows and Macintosh update to Acrobat 8.2. For Adobe Reader users on Windows and Macintosh who cannot update to Adobe Reader 9.3, Adobe has provided the Adobe Reader 8.2 update. Updates apply to all platforms: Windows, Macintosh and UNIX.</li></ul> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/01/13/microsoft-and-adobe-january-2010-patch-day/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Another Adobe Reader Zero Day Vulnerability In The Wild</title><link>http://www.ghacks.net/2009/12/15/another-adobe-reader-zero-day-vulnerability-in-the-wild/</link> <comments>http://www.ghacks.net/2009/12/15/another-adobe-reader-zero-day-vulnerability-in-the-wild/#comments</comments> <pubDate>Tue, 15 Dec 2009 17:02:23 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[adobe vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=21459</guid> <description><![CDATA[Adobe Reader and Adobe Acrobat have been hit with yet another zero day vulnerability that is affecting all versions of both programs up to Adobe Reader and Adobe Acrobat 9.2. The vulnerability has been disclosed to the public by Adobe&#8217;s Security Response team who wrote in their blog that they &#8220;are currently investigating this issue [...]]]></description> <content:encoded><![CDATA[<p>Adobe Reader and Adobe Acrobat have been hit with yet another zero day vulnerability that is affecting all versions of both programs up to Adobe Reader and Adobe Acrobat 9.2. The vulnerability has been disclosed to the public by Adobe&#8217;s Security Response team <a
href="http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html">who</a> wrote in their blog that they &#8220;are currently investigating this issue and assessing the risk to [their] customers&#8221;.</p><p>Adobe itself did not reveal details about the exploit in the blog post but a post at the Shadowserver website which is run by security volunteers from around the world. According to information posted on <a
href="http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214">their</a> website the exploit has been in the wild since at least December 11. The number of attacks have been limited and targeted so far according to their information. They do expect the &#8220;exploit to become more wide spread in the next few weeks&#8221; with the potential to become fully public in the same timeframe.</p><p><span
id="more-21459"></span>The security researchers did not want to reveal all the information about the vulnerability but mentioned that it was found in the JavaScript function in Adobe Acrobat and Adobe Reader.</p><blockquote><p>With that said we can tell you that this vulnerability is actually in a JavaScript function within Adobe Acrobat [Reader] itself. Furthermore the vulnerable JavaScript is obfuscated inside a zlib stream making universal detection and intrusion detection signatures much more difficult. On the bright side though, there are some solutions to this problem.</p></blockquote><p>A temporary fix was also published on the same website.</p><blockquote><p>We have said it before and we will say it again: Disable JavaScript.</p><p>Disabling JavaScript is easy. This is how it can be done in Acrobat Reader:<br
/> Click: Edit -> Preferences -> JavaScript and uncheck Enable Acrobat JavaScript</p><p>We have not had time to fully test but enabling hardware DEP for systems that support it may also mitigate this issue.</p></blockquote><p>Adobe users are encouraged to disable JavaScript as soon as possible to block their version of the program from being vulnerable.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/12/15/another-adobe-reader-zero-day-vulnerability-in-the-wild/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Adobe Reader Security Vulnerabilities</title><link>http://www.ghacks.net/2009/10/08/adobe-reader-security-vulnerabilities/</link> <comments>http://www.ghacks.net/2009/10/08/adobe-reader-security-vulnerabilities/#comments</comments> <pubDate>Thu, 08 Oct 2009 20:06:39 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <category><![CDATA[pdf]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=17088</guid> <description><![CDATA[Adobe has posted information about a known critical security vulnerability affecting Adobe Reader and Adobe Acrobat on Windows, Mac and Unix operating systems. According to Adobe there are reports about a limited attack on the Windows versions of Adobe Reader and Adobe Acrobat 9.1.3 (and most likely earlier). A patch that is fixing the issue [...]]]></description> <content:encoded><![CDATA[<p>Adobe has posted information about a known critical security vulnerability affecting Adobe Reader and Adobe Acrobat on Windows, Mac and Unix operating systems. According to Adobe there are reports about a limited attack on the Windows versions of Adobe Reader and Adobe Acrobat 9.1.3 (and most likely earlier). A patch that is fixing the issue will be released by Adobe on October 13 for all operating systems as part of the Adobe Reader and Acrobat quarterly security update.</p><p>Windows Vista and Windows 7 who have DEP enabled (that&#8217;s Data Execution Prevention) are protected from the exploit. Users who work with different operating systems are encouraged to disable JavaScript to protect against the specific known exploit. Adobe mentions that it is on the other hand possible to create an exploit that does not rely on JavaScript.</p><p><span
id="more-17088"></span><br
/><blockquote>Adobe plans to resolve this issue as part of the upcoming Adobe Reader and Acrobat quarterly security update, scheduled for release on October 13. Adobe Reader and Acrobat 9.1.3 customers with DEP enabled on Windows Vista will be protected from this exploit. Disabling JavaScript also mitigates against this specific exploit, although a variant that does not rely on JavaScript could be possible. In the meantime, Adobe is also in contact with Antivirus and Security vendors regarding the issue and recommends users keep their anti-virus definitions up to date.</p></blockquote><p>Probably the best protection at this point is to uninstall Adobe Reader and Adobe Acrobat and install a third party pdf viewer like <a
href="http://www.ghacks.net/2008/04/26/foxit-reader-23/">Foxit Reader</a>, <a
href="http://www.ghacks.net/2009/09/20/fastest-pdf-file-viewer/">muPDF</a> or <a
href="http://www.ghacks.net/2008/07/17/stdu-viewer-for-tiff-pdf-and-djvu-documents/">STDU Viewer</a>. Additional <a
href="http://www.adobe.com/support/security/bulletins/apsb09-15.html">information</a> are available at the Adobe website.</p><p><strong>Update:</strong> New versions of Adobe Reader and Adobe Acrobat have been released by Adobe Software. The new versions are available for download at Adobe, or via the program&#8217;s internal update mechanism. Users who upgrade to the latest version are no longer vulnerable to this particular exploit.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/10/08/adobe-reader-security-vulnerabilities/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Adobe Reader and Acrobat Security Updates</title><link>http://www.ghacks.net/2009/06/11/adobe-reader-and-acrobat-security-updates/</link> <comments>http://www.ghacks.net/2009/06/11/adobe-reader-and-acrobat-security-updates/#comments</comments> <pubDate>Thu, 11 Jun 2009 12:48:30 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[acrobat]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <category><![CDATA[adobe security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=13448</guid> <description><![CDATA[Adobe has released a set of security updates for their Adobe Reader and Adobe Acrobat software products that fix a variety of security vulnerabilities that could be used to crash the Adobe application and allow the attacker to take control of the computer system. The security vulnerabilities have been rated as critical and Adobe users [...]]]></description> <content:encoded><![CDATA[<p><img
src="http://www.ghacks.net/wp-content/uploads/2009/05/adobe.jpg" alt="adobe" title="adobe" width="100" height="100" class="alignleft size-full wp-image-13093" />Adobe has released a set of security updates for their Adobe Reader and Adobe Acrobat software products that fix a variety of security vulnerabilities that could be used to crash the Adobe application and allow the attacker to take control of the computer system. The security vulnerabilities have been rated as critical and Adobe users are encouraged to update their versions of Adobe Reader and Adobe Acrobat as soon as possible.</p><p>The security updates are provided for Adobe Reader and Adobe Acrobat software products running on both Microsoft Windows and Apple Macintosh operating systems. The security bulletin that was issued yesterday contains <a
href="http://www.adobe.com/support/security/bulletins/apsb09-07.html">links</a> that point to downloads for all affected programs and operating systems.</p><p><span
id="more-13448"></span>The affected programs are:</p><ul><li>Adobe Reader 9.1.1 and earlier versions</li><li>Adobe Acrobat Standard, Pro, and Pro Extended 9.1.1 and earlier versions</li></ul><blockquote><p>Adobe recommends users of Adobe Reader and Acrobat update their product installations to versions 9.1.2, 8.1.6, or 7.1.3 using the instructions above to protect themselves from potential vulnerabilities.  The above updates apply to Windows and Macintosh. Security updates for Adobe Reader on the UNIX platform will be available on June 16, 2009; this Bulletin will be updated to reflect their availability on that date.</p></blockquote><p>Security conscious users might want to consider switching from Adobe Reader to a third party application like <a
href="http://www.ghacks.net/2008/04/26/foxit-reader-23/">Foxit Reader</a>, <a
href="http://www.ghacks.net/2008/03/01/goodbye-adobe-reader-hello-sumatra/">Sumatra PDF</a> or <a
href="http://www.tracker-software.com/product/pdf-xchange-viewer">PDF-Xchange Viewer</a>.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/06/11/adobe-reader-and-acrobat-security-updates/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Disable Adobe Updater</title><link>http://www.ghacks.net/2008/10/04/disable-adobe-updater/</link> <comments>http://www.ghacks.net/2008/10/04/disable-adobe-updater/#comments</comments> <pubDate>Sat, 04 Oct 2008 21:19:55 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Knowledge]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=7407</guid> <description><![CDATA[Adobe installs a software called Adobe Updater with many of its products. The updater will automatically connect to the Internet to check for updates for supported and installed Adobe products. Adobe Updater, that&#8217;s the official name of the application, will be installed in its own folder on the system. Most users probably do not mind [...]]]></description> <content:encoded><![CDATA[<p>Adobe installs a software called Adobe Updater with many of its products. The updater will automatically connect to the Internet to check for updates for supported and installed Adobe products. Adobe Updater, that&#8217;s the official name of the application, will be installed in its own folder on the system.</p><p>Most users probably do not mind the regular automatic update checks but some might prefer to update Adobe software products manually. This is important in business environments where patches are extensively tested before applied to client machines.</p><p>It is actually not a big problem to disable Adobe Updater if an Internet connection is available. All that needs to be done is to execute the Adobe_Updater.exe file that is located in the Program Files\Common Files\Adobe\Updater6 directory on the hard drive. The application will perform an update check and notify the user about updates. The updates won&#8217;t be installed however until the user clicks on the Download And Install Updates button.</p><p><span
id="more-7407"></span><img
src="http://www.ghacks.net/wp-content/uploads/2008/10/disable_adobe_updater-500x455.jpg" alt="disable adobe updater" title="disable adobe updater" width="500" height="455" class="alignnone size-medium wp-image-7408" /></p><p>A click on Preferences will load the configuration screen shown in the above screenshot. Unchecking the &#8220;Automatically check for Adobe updates&#8221; box will do the trick. Mac OSX users can basically do the same. The location of the Adobe Updater program on their system is /Applications/Utilities/Adobe Utilities/Adobe Updater5/.</p><p>Update: Adobe Updater is available as a separate download <a
href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=4509">from the</a> Adobe website. The program has not been updated since 2009, which may indicate that the program is either no longer used by Adobe, or integrated into their software programs by default to make external installations unnecessary.</p><p>The updater, according to the product page, fixes &#8220;networking problems, &#8220;speed and cpu problems&#8221;, &#8220;stability problems&#8221; and some Internet Explorer related issues.</p><p>The program available for download is only compatible with Adobe Creative Suite 4 software or Creative Suite 4 components. Other Adobe products that are not part of the Suite are not supported.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/10/04/disable-adobe-updater/feed/</wfw:commentRss> <slash:comments>22</slash:comments> </item> <item><title>Adobe Reader and Acrobat Critical Security Update</title><link>http://www.ghacks.net/2008/06/25/adobe-reader-and-acrobat-critical-security-update/</link> <comments>http://www.ghacks.net/2008/06/25/adobe-reader-and-acrobat-critical-security-update/#comments</comments> <pubDate>Wed, 25 Jun 2008 13:48:51 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[adobe vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=5107</guid> <description><![CDATA[Adobe has released a security update for its products Adobe Reader and Adobe Acrobat for both Microsoft Windows and Apple Macintosh that closes one critical security vulnerability. Affected versions are Adobe Reader 8.0 through 8.1.2, Adobe Reader 7.0.9 and earlier, Adobe Acrobat Professional, 3D and Standard 8.0 through 8.1.2 and Adobe Acrobat Professional, 3D and [...]]]></description> <content:encoded><![CDATA[<p>Adobe has released a security update for its products Adobe Reader and Adobe Acrobat for both Microsoft Windows and Apple Macintosh that closes one critical security vulnerability. Affected versions are Adobe Reader 8.0 through 8.1.2, Adobe Reader 7.0.9 and earlier, Adobe Acrobat Professional, 3D and Standard 8.0 through 8.1.2 and Adobe Acrobat Professional, 3D and Standard 7.0.9 and earlier.</p><p>Adobe Reader 9 and Acrobat 9 as well as Adobe Reader 7.1.0 and Acrobat 7.1.0 are not affected by the security vulnerability. The vulnerability causes the applications to crash which can allow an attacker to take control of the host system.</p><p>Downloads are available that fix the security vulnerability in Adobe Reader 8 for <a
href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3967">Windows</a> and <a
href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3966">Macintosh</a> computers. Take a look at the security bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb08-15.html">issued</a> by Adobe if you are using Adobe Acrobat or a previous version of one of the products to find the links pointing to updates for your product.</p><p><span
id="more-5107"></span></p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/06/25/adobe-reader-and-acrobat-critical-security-update/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> </channel> </rss>
