<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; adobe reader vulnerability</title> <atom:link href="http://www.ghacks.net/tag/adobe-reader-vulnerability/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 09:52:46 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>New 0-day Adobe Vulnerabilities</title><link>http://www.ghacks.net/2010/10/29/new-0-day-adobe-vulnerabilities/</link> <comments>http://www.ghacks.net/2010/10/29/new-0-day-adobe-vulnerabilities/#comments</comments> <pubDate>Fri, 29 Oct 2010 08:12:15 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe flash security]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <category><![CDATA[flash player]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=36334</guid> <description><![CDATA[It has been a bad year for Adobe&#8217;s security team, as Adobe products where hit with many critical security vulnerabilities in that time. The latest was just announced yesterday in a security advisory over at Adobe. The critical vulnerability affects both Adobe Flash Player versions 10.1.85.3 and earlier on all supported operating systems (that&#8217;s Windows, [...]]]></description> <content:encoded><![CDATA[<p>It has been a bad year for Adobe&#8217;s security team, as Adobe products where hit with many critical security vulnerabilities in that time. The latest was just announced yesterday in a security advisory over at Adobe. The critical vulnerability affects both Adobe Flash Player versions 10.1.85.3 and earlier on all supported operating systems (that&#8217;s Windows, Mac, Linux, Solaris and Android [gasp]) and Adobe Reader 9.4 and earlier 9.x versions on Windows, Mac and Unix.</p><p>Basically, both Flash Player and Adobe Reader / Acrobat are affected by the security vulnerability. According to Adobe&#8217;s security bulletin, the issue is actively exploited against Adobe Reader and Acrobat on Windows.</p><p><a
href="http://www.adobe.com/support/security/advisories/apsa10-05.html">Adobe</a> is currently working on patches and aims to release the Flash Player patch on November 9, 2010 and the Adobe Reader / Acrobat patch on November 15, 2010. That&#8217;s puzzling considering that the company has admitted that the issue is actively exploited against Adobe Reader and Acrobat.</p><p>Mitigations were posted to protect the computer system.</p><blockquote><p>Deleting, renaming, or removing access to the authplay.dll file that ships with Adobe Reader and Acrobat 9.x mitigates the threat for those products, but users will experience a non-exploitable crash or error message when opening a PDF file that contains Flash (SWF) content. The authplay.dll that ships with Adobe Reader and Acrobat 9.x for Windows is typically located at C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll for Adobe Reader or C:\Program Files\Adobe\Acrobat 9.0\Acrobat\authplay.dll for Acrobat.</p></blockquote><p>No mitigating factors were offered for the Flash vulnerability. The only ones that are known to work are to either disable Adobe Flash in the browser, or to use a flash blocking script such as NoScript for Firefox.</p><p><a
href="http://www.theregister.co.uk/2010/10/28/adobe_reader_critical_vuln/">The Register</a> has additional information about the pdf exploit. According to their information, attackers &#8220;install a nasty trojan known as Wisp, which according to Microsoft, steals sensitive user data and installs a backdoor on compromised systems.&#8221;</p><p>With patches as far away as two weeks, it is recommended to disable authplay.dll in Adobe Reader or Acrobat, and disable or block the Flash plugin in the web browser to protect the computer system against these attacks.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/10/29/new-0-day-adobe-vulnerabilities/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Another Adobe Reader Zero-Day Vulnerability Emerges</title><link>http://www.ghacks.net/2010/08/06/another-adobe-reader-zero-day-vulnerability-emerges/</link> <comments>http://www.ghacks.net/2010/08/06/another-adobe-reader-zero-day-vulnerability-emerges/#comments</comments> <pubDate>Fri, 06 Aug 2010 08:08:51 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <category><![CDATA[pdf]]></category> <category><![CDATA[pdf reader]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=32092</guid> <description><![CDATA[What is it with Adobe Reader and vulnerabilities? It feels like new security vulnerabilities are found in the software at an accelerated pace this year. Adobe yesterday released a security advisory for Adobe Reader and Acrobat, to announce to the world that critical security vulnerabilities have been found &#8211; once again &#8211; in Adobe Reader [...]]]></description> <content:encoded><![CDATA[<p>What is it with Adobe Reader and vulnerabilities? It feels like new security vulnerabilities are found in the software at an accelerated pace this year. Adobe yesterday released a security advisory for Adobe Reader and Acrobat, to announce to the world that critical security vulnerabilities have been found &#8211; once again &#8211; in Adobe Reader and Adobe Acrobat.</p><p>Adobe expects to make the updates &#8220;available during the week of August 16, 2010&#8243;, which does mean that millions of computer systems running either Adobe Reader or Adobe Acrobat are left vulnerable for the time being.</p><p><span
id="more-32092"></span><br
/><blockquote>Adobe is planning to release updates for Adobe Reader 9.3.3 for Windows, Macintosh and UNIX, Adobe Acrobat 9.3.3 for Windows and Macintosh, and Adobe Reader 8.2.3 and Acrobat 8.2.3 for Windows and Macintosh to resolve critical security issues, including CVE-2010-2862 which was discussed at the Black Hat USA 2010 security conference on Wednesday, July 28, 2010. Adobe expects to make these updates available during the week of August 16, 2010</p></blockquote><p><a
href="http://www.adobe.com/support/security/bulletins/apsb10-17.html">The</a> security advisory does not reveal information about the vulnerabilities, only that one was discussed at last month&#8217;s Black Hat USA 2010 security conference, that all platforms are affected, and that Adobe Reader 9.3.3 and earlier, and Adobe Acrobat 9.3.3 and earlier are affected.</p><p>The advisory over at <a
href="http://secunia.com/advisories/40766">Secunia</a> reveals additional details about the vulnerability discussed at the Black Hat conference. The Adobe Reader / Acrobat Font Parsing Integer Overflow Vulnerability has been rated as highly critical, the second highest possible rating.</p><blockquote><p>The vulnerability is caused due to an integer overflow error in CoolType.dll when parsing the &#8220;maxCompositePoints&#8221; field value in the &#8220;maxp&#8221; (Maximum Profile) table of a TrueType font. This can be exploited to corrupt memory via a PDF file containing a specially crafted TrueType font.</p></blockquote><p>Successful exploits may allow remote code execution on the targeted system.</p><p>Users with Adobe Reader or Adobe Acrobat installed may want to consider switching to another pdf reader for the time being, to protect their computer system from those vulnerabilities. Alternatives are listed on our <a
href="http://www.ghacks.net/2010/07/02/pdf-reader-rendering-quality-comparison-which-is-the-best/">pdf reader comparison</a> page.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/08/06/another-adobe-reader-zero-day-vulnerability-emerges/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Adobe Reader 9.3.3 Released, Fixes Critical Security Issues</title><link>http://www.ghacks.net/2010/06/29/adobe-reader-9-3-3-released-fixes-critical-security-issues/</link> <comments>http://www.ghacks.net/2010/06/29/adobe-reader-9-3-3-released-fixes-critical-security-issues/#comments</comments> <pubDate>Tue, 29 Jun 2010 18:54:05 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader update]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <category><![CDATA[pdf]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=27615</guid> <description><![CDATA[Adobe today has released a new version of their pdf readers Adobe Reader and Acrobat raising the versions of said products to 9.3.3 respectively 9.3.3. Affected by the vulnerabilities are Adobe Reader 9.3.2 and earlier for Windows, Macintosh and Unix as well as Adobe Acrobat 9.3.2 and earlier for Windows and Macintosh. The security bulletin [...]]]></description> <content:encoded><![CDATA[<p>Adobe today has released a new version of their pdf readers Adobe Reader and Acrobat raising the versions of said products to 9.3.3 respectively 9.3.3. Affected by the vulnerabilities are Adobe Reader 9.3.2 and earlier for Windows, Macintosh and Unix as well as Adobe Acrobat 9.3.2 and earlier for Windows and Macintosh.</p><p>The security bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb10-15.html">sheds</a> some light on the security issues that have been fixed in the release. A total of 17 different vulnerabilities have been fixed in Adobe Reader 9.3.3. Adobe has categorized the update as critical and recommends that users apply the latest updates immediately to protect their computer systems.</p><p>Exploits of any security vulnerability that has been patched in the update can lead to code execution on the affected system.</p><p><span
id="more-27615"></span>Adobe confirmed that at least one of the security vulnerabilities is actively exploited in the wild.</p><blockquote><p>This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-1297).<br
/> Note: There are reports that this issue is being actively exploited in the wild.</p><p>This update mitigates a social engineering attack that could lead to code execution (CVE-2010-1240).</p><p>This update resolves an invalid pointer vulnerability that could lead to code execution (CVE-2010-1285).</p><p>This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-1295).</p><p>This update resolves an invalid pointer vulnerability that could lead to code execution (CVE-2010-2168).</p><p>This update resolves an invalid pointer vulnerability that could lead to code execution (CVE-2010-2201).</p><p>This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2202).</p><p>This update resolves a UNIX-only memory corruption vulnerability that could lead to code execution (CVE-2010-2203).</p><p>This update resolves a denial of service vulnerability; arbitrary code execution has not been demonstrated, but may be possible (CVE-2010-2204).</p><p>This update resolves an uninitialized memory vulnerability that could lead to code execution (CVE-2010-2205).</p><p>This update resolves an array-indexing error vulnerability that could lead to code execution (CVE-2010-2206).</p><p>This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2207).</p><p>This update resolves a dereference deleted heap object vulnerability that could lead to code execution (CVE-2010-2208).</p><p>This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2209).</p><p>This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2210).</p><p>This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2211).</p><p>This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2212).</p></blockquote><p>Adobe Reader 9.3.3 and Acrobat 9.3.3 are available for <a
href="http://www.adobe.com/support/security/bulletins/apsb10-15.html">download</a> at the Adobe website. Also available are Adobe Reader 8.2.3 and Adobe Acrobat 8.2.3 which both fix the security issues as well.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/06/29/adobe-reader-9-3-3-released-fixes-critical-security-issues/feed/</wfw:commentRss> <slash:comments>9</slash:comments> </item> <item><title>Critical Adobe Reader And Flash Vulnerabilities Emerge</title><link>http://www.ghacks.net/2010/06/05/critical-adobe-reader-and-flash-vulnerabilities-emerge/</link> <comments>http://www.ghacks.net/2010/06/05/critical-adobe-reader-and-flash-vulnerabilities-emerge/#comments</comments> <pubDate>Sat, 05 Jun 2010 20:39:03 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[flash player vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=26221</guid> <description><![CDATA[Two new vulnerabilities affecting the Adobe products Adobe Reader and Adobe Flash were reported by Secunia earlier this day. They have in common that they have been both rated as extremely critical, the highest available severity rating for vulnerabilities posted at Secunia. Highly critical is a rating for &#8220;remotely exploitable vulnerabilities that can lead to [...]]]></description> <content:encoded><![CDATA[<p>Two new vulnerabilities affecting the Adobe products Adobe Reader and Adobe Flash were reported by <a
href="http://secunia.com/">Secunia</a> earlier this day. They have in common that they have been both rated as extremely critical, the highest available severity rating for vulnerabilities posted at Secunia.</p><p>Highly critical is a rating for &#8220;remotely exploitable vulnerabilities that can lead to system compromise&#8221; that usually do not &#8220;require any interaction&#8221; and where exploits are already in the wild.</p><p>The Adobe Flash vulnerability that has been reported is affecting Adobe Flash Player 10.x and Adobe Flash Player 9.x.</p><p><span
id="more-26221"></span><br
/><blockquote>A vulnerability has been reported in Adobe Flash Player, which can be exploited by malicious people to compromise a user&#8217;s system.</p><p>The vulnerability is caused due to an unspecified error. No more information is currently available.</p><p>Successful exploitation allows execution of arbitrary code.</p><p>The vulnerability is reported in version 10.0.45.2 and prior 10.0.x and 9.0.x versions for Windows, Macintosh, Linux, and Solaris.</p><p>NOTE: The vulnerability is reportedly being actively exploited.</p></blockquote><p>The release candidate of the upcoming Adobe Flash Player 10.1 does not seem to be affected by the vulnerability according to the information <a
href="http://secunia.com/advisories/40026">at</a> the Secunia website.</p><p>Users who want to protect their computer system from being exploited by the vulnerability can either disable Adobe Flash for the time being or <a
href="http://labs.adobe.com/downloads/flashplayer10.html">update to</a> the Adobe Flash Player 10.1 Release Candidate. Additional information about the vulnerability are posted in a Security Bulletin <a
href="http://www.adobe.com/support/security/advisories/apsa10-01.html">at the</a> Adobe website.</p><p>The Adobe Reader and Adobe Acrobat vulnerability might be related to the Adobe Flash vulnerability. The <a
href="http://secunia.com/advisories/40034">Secunia Advisory</a> lists Adobe Reader 9 versions for Windows, Macintosh and Linux as affected by the vulnerability.</p><blockquote><p>The vulnerability is caused due to a vulnerable bundled version of Flash Player (authplay.dll).Successful exploitation allows execution of arbitrary code.</p><p>The vulnerability is reported in version 9.3.2 and earlier 9.x versions for Windows, Macintosh, and UNIX.</p><p>NOTE: The vulnerability is currently being actively exploited.</p></blockquote><p>The temporary solution to protect the computer system from the exploits is to delete, rename or remove access to autoplay.dll to prevent Flash content from being executed in Adobe Reader and Acrobat.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/06/05/critical-adobe-reader-and-flash-vulnerabilities-emerge/feed/</wfw:commentRss> <slash:comments>7</slash:comments> </item> <item><title>Adobe Reader And Acrobat Get Yet Another Security Update</title><link>http://www.ghacks.net/2010/02/17/adobe-reader-and-acrobat-get-yet-another-security-update/</link> <comments>http://www.ghacks.net/2010/02/17/adobe-reader-and-acrobat-get-yet-another-security-update/#comments</comments> <pubDate>Tue, 16 Feb 2010 22:12:58 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader update]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=23123</guid> <description><![CDATA[Adobe Reader and Adobe Flash seem to be two of the most targeted software programs by malicious software and hackers besides the Microsoft Windows operating system and Internet Explorer. It is rare that a month passes by without yet another update that fixes a security vulnerability in Adobe Reader or Acrobat. Today a critical vulnerability [...]]]></description> <content:encoded><![CDATA[<p>Adobe Reader and Adobe Flash seem to be two of the most targeted software programs by malicious software and hackers besides the Microsoft Windows operating system and Internet Explorer. It is rare that a month passes by without yet another update that fixes a security vulnerability in Adobe Reader or Acrobat.</p><p>Today a critical vulnerability was disclosed that is affecting all Adobe Reader 9.3 and earlier and Adobe Acrobat 9.3 and earlier versions on Windows and Macintosh. The Adobe Reader 9.3 or earlier Unix versions are also vulnerable.</p><p><span
id="more-23123"></span><br
/><blockquote>As described in Security Bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb10-06.html">APSB10-06</a>, this vulnerability (CVE-2010-0186) could subvert the domain sandbox and make unauthorized cross-domain requests. In addition, a critical vulnerability (CVE-2010-0188) has been identified that could cause the application to crash and could potentially allow an attacker to take control of the affected system.</p><p>In addition, a critical vulnerability (CVE-2010-0188) has been identified that could cause the application to crash and could potentially allow an attacker to take control of the affected system.</p></blockquote><p>Adobe has reacted promptly this time as updates for Adobe Reader and Acrobat are already available for download and installation. It is suggested to download the new releases as soon as possible to protect the computer system from the security vulnerability.</p><p>The security bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb10-07.html">posted</a> at the Adobe website contains download links for all supported operating systems.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/02/17/adobe-reader-and-acrobat-get-yet-another-security-update/feed/</wfw:commentRss> <slash:comments>7</slash:comments> </item> <item><title>Adobe Reader Security Vulnerabilities</title><link>http://www.ghacks.net/2009/10/08/adobe-reader-security-vulnerabilities/</link> <comments>http://www.ghacks.net/2009/10/08/adobe-reader-security-vulnerabilities/#comments</comments> <pubDate>Thu, 08 Oct 2009 20:06:39 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <category><![CDATA[pdf]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=17088</guid> <description><![CDATA[Adobe has posted information about a known critical security vulnerability affecting Adobe Reader and Adobe Acrobat on Windows, Mac and Unix operating systems. According to Adobe there are reports about a limited attack on the Windows versions of Adobe Reader and Adobe Acrobat 9.1.3 (and most likely earlier). A patch that is fixing the issue [...]]]></description> <content:encoded><![CDATA[<p>Adobe has posted information about a known critical security vulnerability affecting Adobe Reader and Adobe Acrobat on Windows, Mac and Unix operating systems. According to Adobe there are reports about a limited attack on the Windows versions of Adobe Reader and Adobe Acrobat 9.1.3 (and most likely earlier). A patch that is fixing the issue will be released by Adobe on October 13 for all operating systems as part of the Adobe Reader and Acrobat quarterly security update.</p><p>Windows Vista and Windows 7 who have DEP enabled (that&#8217;s Data Execution Prevention) are protected from the exploit. Users who work with different operating systems are encouraged to disable JavaScript to protect against the specific known exploit. Adobe mentions that it is on the other hand possible to create an exploit that does not rely on JavaScript.</p><p><span
id="more-17088"></span><br
/><blockquote>Adobe plans to resolve this issue as part of the upcoming Adobe Reader and Acrobat quarterly security update, scheduled for release on October 13. Adobe Reader and Acrobat 9.1.3 customers with DEP enabled on Windows Vista will be protected from this exploit. Disabling JavaScript also mitigates against this specific exploit, although a variant that does not rely on JavaScript could be possible. In the meantime, Adobe is also in contact with Antivirus and Security vendors regarding the issue and recommends users keep their anti-virus definitions up to date.</p></blockquote><p>Probably the best protection at this point is to uninstall Adobe Reader and Adobe Acrobat and install a third party pdf viewer like <a
href="http://www.ghacks.net/2008/04/26/foxit-reader-23/">Foxit Reader</a>, <a
href="http://www.ghacks.net/2009/09/20/fastest-pdf-file-viewer/">muPDF</a> or <a
href="http://www.ghacks.net/2008/07/17/stdu-viewer-for-tiff-pdf-and-djvu-documents/">STDU Viewer</a>. Additional <a
href="http://www.adobe.com/support/security/bulletins/apsb09-15.html">information</a> are available at the Adobe website.</p><p><strong>Update:</strong> New versions of Adobe Reader and Adobe Acrobat have been released by Adobe Software. The new versions are available for download at Adobe, or via the program&#8217;s internal update mechanism. Users who upgrade to the latest version are no longer vulnerable to this particular exploit.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/10/08/adobe-reader-security-vulnerabilities/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Adobe Reader, Acrobat and Flash Player Zero Day Vulnerability</title><link>http://www.ghacks.net/2009/07/24/adobe-reader-acrobat-and-flash-player-zero-day-vulnerability/</link> <comments>http://www.ghacks.net/2009/07/24/adobe-reader-acrobat-and-flash-player-zero-day-vulnerability/#comments</comments> <pubDate>Fri, 24 Jul 2009 14:08:36 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[acrobat]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <category><![CDATA[adobe vulnerability]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[flash player vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=14724</guid> <description><![CDATA[Adobe has issued a security advisory that describes a critical vulnerability in the current versions of Adobe Reader, Acrobat and Flash Player. The vulnerability &#8220;could cause a crash and potentially allow an attacker to take control of the affected system&#8221;. Adobe&#8217;s Flash Player seems to be affected completely while the file authplay.dll is the reason [...]]]></description> <content:encoded><![CDATA[<p><img
src="http://www.ghacks.net/wp-content/uploads/2009/05/adobe.jpg" alt="adobe" title="adobe" width="100" height="100" class="alignleft size-full wp-image-13093" />Adobe has issued a security advisory <a
href="http://www.adobe.com/support/security/advisories/apsa09-03.html">that</a> describes a critical vulnerability in the current versions of Adobe Reader, Acrobat and Flash Player. The vulnerability &#8220;could cause a crash and potentially allow an attacker to take control of the affected system&#8221;. Adobe&#8217;s Flash Player seems to be affected completely while the file authplay.dll is the reason for the vulnerability affecting Adobe Reader and Acrobat as well. Adobe mentioned that the vulnerability is already exploited in the wild via targeted attacks against users running a Windows operating system and Adobe Reader 9.</p><p>Apple Mac and Unix systems are affected by the vulnerability as well but the exploit that is currently in the wild is only affecting Windows. Adobe suggests to enable UAC in Windows Vista (and Windows 7). Windows XP users should consider moving or deleting authplay.dll to protect their computer system from the threat against Adobe Reader and Acrobat &#8220;but users will experience a non-exploitable crash or error message when opening a PDF that contains SWF content&#8221;.</p><p><span
id="more-14724"></span>An alternative would be to uninstall Adobe Reader or Acrobat and install one of the available third party pdf readers like <a
href="http://www.ghacks.net/2008/04/26/foxit-reader-23/">Foxit Reader</a> or <a
href="http://www.ghacks.net/2008/03/01/goodbye-adobe-reader-hello-sumatra/">Sumatra</a>.</p><p>Adobe does not offer any advise on the Flash Player vulnerability. The only viable option seems to be to disable or even uninstall Flash and wait for the patch which is expected to be released on July 30 and July 31.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/07/24/adobe-reader-acrobat-and-flash-player-zero-day-vulnerability/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Adobe Reader and Acrobat Security Updates</title><link>http://www.ghacks.net/2009/06/11/adobe-reader-and-acrobat-security-updates/</link> <comments>http://www.ghacks.net/2009/06/11/adobe-reader-and-acrobat-security-updates/#comments</comments> <pubDate>Thu, 11 Jun 2009 12:48:30 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[acrobat]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <category><![CDATA[adobe security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=13448</guid> <description><![CDATA[Adobe has released a set of security updates for their Adobe Reader and Adobe Acrobat software products that fix a variety of security vulnerabilities that could be used to crash the Adobe application and allow the attacker to take control of the computer system. The security vulnerabilities have been rated as critical and Adobe users [...]]]></description> <content:encoded><![CDATA[<p><img
src="http://www.ghacks.net/wp-content/uploads/2009/05/adobe.jpg" alt="adobe" title="adobe" width="100" height="100" class="alignleft size-full wp-image-13093" />Adobe has released a set of security updates for their Adobe Reader and Adobe Acrobat software products that fix a variety of security vulnerabilities that could be used to crash the Adobe application and allow the attacker to take control of the computer system. The security vulnerabilities have been rated as critical and Adobe users are encouraged to update their versions of Adobe Reader and Adobe Acrobat as soon as possible.</p><p>The security updates are provided for Adobe Reader and Adobe Acrobat software products running on both Microsoft Windows and Apple Macintosh operating systems. The security bulletin that was issued yesterday contains <a
href="http://www.adobe.com/support/security/bulletins/apsb09-07.html">links</a> that point to downloads for all affected programs and operating systems.</p><p><span
id="more-13448"></span>The affected programs are:</p><ul><li>Adobe Reader 9.1.1 and earlier versions</li><li>Adobe Acrobat Standard, Pro, and Pro Extended 9.1.1 and earlier versions</li></ul><blockquote><p>Adobe recommends users of Adobe Reader and Acrobat update their product installations to versions 9.1.2, 8.1.6, or 7.1.3 using the instructions above to protect themselves from potential vulnerabilities.  The above updates apply to Windows and Macintosh. Security updates for Adobe Reader on the UNIX platform will be available on June 16, 2009; this Bulletin will be updated to reflect their availability on that date.</p></blockquote><p>Security conscious users might want to consider switching from Adobe Reader to a third party application like <a
href="http://www.ghacks.net/2008/04/26/foxit-reader-23/">Foxit Reader</a>, <a
href="http://www.ghacks.net/2008/03/01/goodbye-adobe-reader-hello-sumatra/">Sumatra PDF</a> or <a
href="http://www.tracker-software.com/product/pdf-xchange-viewer">PDF-Xchange Viewer</a>.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/06/11/adobe-reader-and-acrobat-security-updates/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Unofficial Adobe Reader Patch Released</title><link>http://www.ghacks.net/2009/02/24/unofficial-adobe-reader-patch-released/</link> <comments>http://www.ghacks.net/2009/02/24/unofficial-adobe-reader-patch-released/#comments</comments> <pubDate>Tue, 24 Feb 2009 14:22:29 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <category><![CDATA[pdf]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=10734</guid> <description><![CDATA[You might have read about a new vulnerability in Adobe Reader 9 and previous versions that is affecting all platforms and rated with a critical severity by Adobe. The vulnerability can be used to crash an application to allow an attacker to take control of the attacked computer system. Adobe announced plans to release the [...]]]></description> <content:encoded><![CDATA[<p>You might have read about a new vulnerability in Adobe Reader 9 and previous versions that is affecting all platforms and rated with a critical severity by Adobe. The vulnerability can be used to crash an application to allow an attacker to take control of the attacked computer system. Adobe announced plans to release the official patch for all affected products on March 11. That&#8217;s more than two weeks after the patch has been acknowledged by them and a serious problem considering that there are reports that the vulnerability is already exploited.</p><p><a
href="http://vrt-blog.snort.org/2009/02/homebrew-patch-for-adobe-acroreader-9.html">Lurene Grenier</a>, a security researcher at Sourcefire, has published an unofficial patch for Adobe Reader 9 that is installed on a computer running the Microsoft Windows operating system. The patch comes with no guarantees and involves the replacement of a dll file in the Adobe Reader directory. Users should make sure to backup the dll before replacing it to be prepared for eventualities. Windows users with previous Adobe Reader versions will have to upgrade to Adobe Reader 9 before they can apply the patch.</p><p>There is another recommendation (by <a
href="http://www.us-cert.gov/cas/techalerts/TA09-051A.html">US-CERT</a>)which is helpful for users of other operating systems or Windows users who do not like the idea of replacing a dll on the computer system:</p><p><span
id="more-10734"></span><ul><li>Disabling Javascript in Adobe Reader by going to Edit > Preferences > JavaScript and unchecking enable Acrobat JavaScript.</li><li>Preventing IE from automatically displaying PDFs. This can be done via a Registry tweak described on the US-CERT notification.</li><li>Disable rendering of PDFs within web pages. This can be done from the Edit-Preferences menu in Adobe Reader.</li></ul><p>It is recommended to act swiftly to prevent that the vulnerability can get exploited on the computer system. Users of third party PDF software programs are not affected by the vulnerability.</p><p><strong>Update</strong>: Adobe has patched all Adobe Reader products in the meantime. Users who have updated the pdf reader cannot be attacked anymore.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/02/24/unofficial-adobe-reader-patch-released/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Critical Adobe Reader Update</title><link>http://www.ghacks.net/2008/02/07/critical-adobe-reader-update/</link> <comments>http://www.ghacks.net/2008/02/07/critical-adobe-reader-update/#comments</comments> <pubDate>Thu, 07 Feb 2008 14:34:54 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Tools]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/2008/02/07/critical-adobe-reader-update/</guid> <description><![CDATA[Adobe has released the version 8.1.2 of Adobe Reader which is a critical update that patches a security vulnerability. Adobe recommends that users patch their version of Adobe Reader to the newest as soon as possible to close the security hole. The strange thing about this update is that only 26 of the 27 fixes of this update are listed in the release notes and that the security vulnerability that has been fixed is not listed on that page.]]></description> <content:encoded><![CDATA[<p>Adobe has released the version 8.1.2 of Adobe Reader which is a critical update that patches a security vulnerability. Adobe recommends that users patch their version of Adobe Reader to the newest as soon as possible to close the security hole. The strange thing about this update is that only 26 of the 27 fixes of <a
href="http://kb2.adobe.com/cps/403/kb403079.html">this</a> update are listed in the release notes and that the security vulnerability that has been fixed is not listed on that page.</p><p>Adobe just mentioned that &#8220;the Adobe Reader 8.1.2 update addresses a number of customer workflow issues and security vulnerabilities while providing more stability.&#8221; Either they have forgotten to include the information in the release notes or they did not want to publish them officially.</p><p>It does not really matter for us end users anyway. If you use Adobe Reader <a
href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3854">head</a> out now and download the latest version of Adobe Reader to be on the safe side.</p><p><span
id="more-3146"></span></p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/02/07/critical-adobe-reader-update/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> </channel> </rss>
