<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; adobe reader</title> <atom:link href="http://www.ghacks.net/tag/adobe-reader/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Fri, 10 Feb 2012 20:51:26 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Adobe Patch Day Brings Fixes For Flash, Shockwave And Adobe Reader</title><link>http://www.ghacks.net/2011/06/15/adobe-patch-day-brings-fixes-for-flash-shockwave-and-adobe-reader/</link> <comments>http://www.ghacks.net/2011/06/15/adobe-patch-day-brings-fixes-for-flash-shockwave-and-adobe-reader/#comments</comments> <pubDate>Wed, 15 Jun 2011 07:42:39 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[companies]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[patch day]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=46489</guid> <description><![CDATA[Microsoft had a huge patch day yesterday with 16 security bulletins for the Windows operating system, Microsoft Office, Internet Explorer and other Microsoft software. Adobe, the company behind popular technologies such as Flash Player, Shockwave or Adobe Reader released five security bulletins on the same day after teaming up with Microsoft to coordinate security releases.. [...]]]></description> <content:encoded><![CDATA[<p>Microsoft had a huge <a
href="http://www.ghacks.net/2011/06/14/microsoft-patch-day-june-2011-overview/">patch day</a> yesterday with 16 security bulletins for the Windows operating system, Microsoft Office, Internet Explorer and other Microsoft software.</p><p>Adobe, the company behind popular technologies such as Flash Player, Shockwave or Adobe Reader released five security bulletins on the same day after <a
href="http://www.ghacks.net/2010/07/29/adobe-microsoft-to-team-up-on-vulnerability-sharing/">teaming up with Microsoft</a> to coordinate security releases.. Of the five, three may be affecting end users as they address vulnerabilities in Adobe Reader and Acrobat, Shockwave Player and Flash Player. All three have received a maximum severity rating of critical, the highest possible rating.</p><p>The bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb11-16.html">APSB11-16</a> describes a critical vulnerability in Adobe Reader X 10.0.3 and earlier on Windows, and Adobe Reader X 10.0.3 and earlier on Macintosh, as well as earlier versions of Adobe Reader 9 and 8, and Adobe Acrobat 9 and 8. The vulnerability could be exploited by attackers to crash the application to take control of the computer system Adobe Reader X is running on.</p><p>Adobe recommends to update the software product to the latest available version. For Adobe Reader X that would mean to update to version 10.1, for users of Adobe Reader 9.4.4 and earlier to update to version 9.4.5.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/06/adobe-reader-x.png" alt="adobe-reader-x" title="adobe-reader-x" width="600" height="449" class="alignnone size-full wp-image-46493" /></p><p>Adobe Reader and Acrobat users can check for updates in the program interface. This is done via Help > Check for Updates. Updates can also be downloaded from the following locations.</p><ul><li><a
href="http://www.adobe.com/support/downloads/product.jsp?product=10&#038;platform=Windows.">Adobe Reader Windows</a></li><li><a
href="http://www.adobe.com/support/downloads/product.jsp?product=10&#038;platform=Macintosh.">Adobe Reader Macintosh</a></li></ul><p>You can also check out <a
href="http://www.ghacks.net/2010/11/22/adobe-reader-x-offline-installers/">Adobe Reader X Offline Installers</a></p><p>Security Bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb11-17.html">APSB11-17</a> describes vulnerabilities in Adobe Shockwave Player 11.5.9.620 and earlier on the Windows and Macintosh platform. Attackers who successfully exploit the vulnerabilities could run malicious code on the computer system. Adobe recommends to update Shockwave Player to version 11.6.0.626 to protect the system from possible exploits.</p><p>Windows and Mac users who run Shockwave Player on their system can download the latest version <a
href="http://get.adobe.com/shockwave/">at the official</a> download site.</p><p>Bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb11-18.html">APSB11-18</a> finally describes a vulnerability in Adobe Flash Player that affects Adobe Flash Player 10.3.181.23 and earlier on Windows, Macintosh, Linux and Solaris, as well as Flash Player 10.3.185.23 and earlier for Android.</p><p>The vulnerability could be exploited to cause a crash which could allow the attacker to gain control over the affected system. Adobe has confirmed reports that the vulnerability is exploited in the wild in the form of targeted attacks on specifically prepared websites.</p><p>Adobe recommends to update Flash Player to Adobe Flash Player 10.3.181.26 on desktop operating systems. Android users will receive a patch before week&#8217;s end.</p><p>Users can verify their installed version of Flash Player by visiting the <a
href="http://www.adobe.com/products/flash/about/">About Flash Player</a> page at Adobe.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/06/flash-player-version.png" alt="flash player version" title="flash player version" width="600" height="512" class="alignnone size-full wp-image-46490" /></p><p>Adobe lists the latest version for all supported operating systems on the page, so that users only need to compare their installed version with the latest available version to see if they need to update.</p><p>The latest versions can be downloaded from <a
href="http://get.adobe.com/flashplayer/">Adobe&#8217;s Flash Player Download Center</a>.  Users who do not want to use the download manager can check out this guide D<a
href="http://www.ghacks.net/2010/02/27/download-adobe-flash-without-adobe-download-manager/">ownload Adobe Flash Without Adobe Download Manager</a>.</p><p>Google Chrome users can check for updates in Chrome to get the latest version. This is done by clicking on the wrench icon and selecting About Google Chrome.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/06/15/adobe-patch-day-brings-fixes-for-flash-shockwave-and-adobe-reader/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Reformat PDF Documents Before Printing</title><link>http://www.ghacks.net/2011/05/08/reformat-pdf-documents-before-printing/</link> <comments>http://www.ghacks.net/2011/05/08/reformat-pdf-documents-before-printing/#comments</comments> <pubDate>Sun, 08 May 2011 04:59:44 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Software]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[pdf]]></category> <category><![CDATA[pdf documents]]></category> <category><![CDATA[print pdf]]></category> <category><![CDATA[printing]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=44869</guid> <description><![CDATA[Some say that printer ink is more expensive than gold. I&#8217;m not sure if this is still true with gold breaking one all-time high after the other. Still, printer ink is pretty expensive, especially if you buy official ink. One way to save ink is to print multiple pages on one sheet of paper. That [...]]]></description> <content:encoded><![CDATA[<p>Some say that printer ink is more expensive than gold. I&#8217;m not sure if this is still true with gold breaking one all-time high after the other. Still, printer ink is pretty expensive, especially if you buy official ink. One way to save ink is to print multiple pages on one sheet of paper. That can be done in some, but not all, pdf readers out there. Adobe Reader can print multiple pages per sheet for instance.</p><p>Govert&#8217;s Simple Imposition Tool is a free standalone software that can reformat pdf documents before printing. It is not only useful for users whose pdf readers cannot print multiple pages though, as it offers more than just that.</p><p>When you open the program for the first time, you notice a one-page layout where everything is configured. You load a pdf document at the top. The properties of the document are shown below, including the document&#8217;s size, pages and rotation.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/05/simple-imposition-tool.png" alt="simple imposition tool" title="simple imposition tool" width="495" height="348" class="alignnone size-full wp-image-44870" /></p><p>Four formatting options and five optional settings are available under the Impose for section. You have the following formatting options:</p><ul><li>Booklet printing &#8211; Orders the pages automatically so that you get a booklet when you print and fold the printout. Optional foldmark can be added, which can be read by automatic folding machines.</li><li>2-up printing &#8211; Odd and even pages are printed side by side on one sheet of paper. Page Separation lines can be optionally added.</li><li>Duplicate side-by-side &#8211; Print the same page twice on one sheet of paper. Cutmarks can be added to define where the document should be cut in half.</li><li>2x 1/2n &#8211; Places first half of multipage document side by side with second half. Duplex printing and cutmarks optional.</li></ul><p>A click on the Action button launches a file save window where you can enter a name for the new pdf document. And that&#8217;s basically it.</p><p>If you compare the options to Adobe Reader, you notice that some are supported by Adobe&#8217;s product as well. You can use Adobe Reader to print multiple pages on one sheet and in booklet format. What&#8217;s not supported is the ability to print the same page multiple times on a sheet, and the option to place the first half of the document side by side with the second half.</p><p>The <a
href="http://www.noliturbare.com/pdf-tools/simple-imposition">Simple Imposition Tool</a> is available for Windows PCs. It requires the Microsoft .NET Framework 2.0. The program was tested under a 64-bit edition of Windows 7 Professional. It worked without flaws.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/05/08/reformat-pdf-documents-before-printing/feed/</wfw:commentRss> <slash:comments>7</slash:comments> </item> <item><title>Here We Go Again: Yet Another Flash 0-day Vulnerability Emerges</title><link>http://www.ghacks.net/2011/04/12/here-we-go-again-yet-another-flash-0-day-vulnerability-emerges/</link> <comments>http://www.ghacks.net/2011/04/12/here-we-go-again-yet-another-flash-0-day-vulnerability-emerges/#comments</comments> <pubDate>Tue, 12 Apr 2011 09:05:30 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe flash]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[flash vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=43815</guid> <description><![CDATA[Flash player users, which is the majority of Internet users, do not come to rest in past years. There is seldom a month passing by without another Flash vulnerability. Adobe today released a security advisory warning for all Flash users that describes a critical security vulnerability in the popular software. Affected are more or less [...]]]></description> <content:encoded><![CDATA[<p>Flash player users, which is the majority of Internet users, do not come to rest in past years. There is seldom a month passing by without another Flash vulnerability. Adobe today released a security advisory warning for all Flash users that describes a critical security vulnerability in the popular software.</p><p>Affected are more or less all Flash users. This includes Flash installations on Windows, Mac and Linux, the built-in Flash Player of the Google Chrome browser, Flash on Android and Flash in Adobe Reader and Acrobat.</p><ul><li>Flash Player 10.2.153.1 and earlier versions on Windows, Mac, Linux, Solaris</li><li>Adobe Flash Player 10.2.154.25 and earlier for Chrome</li><li>Adobe Flash Player 10.2.156.12 and earlier versions for Android</li><li>Adobe Reader and Acrobat X (10.0.2) and earlier 10.x and 9.x versions for Windows and Macintosh operating systems</li></ul><p>Adobe confirmed reports that the vulnerability is actively exploited. The vulnerability uses embedded Flash files in Microsoft Word documents to exploit the issue. According to Adobe&#8217;s information those are delivered as email attachments and targeting the Windows platform.</p><p>Adobe Reader and Acrobat do not appear to be targeted right now. Adobe Reader X users are protected from this exploit by the program&#8217;s Protected Mode.</p><p>Adobe is currently finalizing a schedule for delivering updates for all affected versions of Flash Player except for Adobe Reader X which will receive the update on the next quarterly security update on June 14, 2011.</p><p>How can users protect their system from these kind of attacks? You should be cautious when you receive document attachments, especially if they come from unknown senders. Probably the best option in this case is to save those attachments to the computer, and open them in an online viewer such as Google Docs.</p><p>You could alternatively use a third party document viewer that does not support Flash, but the safest bet is an online viewer.</p><p>Interested users find <a
href="http://www.adobe.com/support/security/advisories/apsa11-02.html">additional information</a> about the newly discovered Flash vulnerability at the Adobe Security Bulletin.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/04/12/here-we-go-again-yet-another-flash-0-day-vulnerability-emerges/feed/</wfw:commentRss> <slash:comments>10</slash:comments> </item> <item><title>How To Search Multiple PDF Documents At Once</title><link>http://www.ghacks.net/2011/04/02/how-to-search-multiple-pdf-documents-at-once/</link> <comments>http://www.ghacks.net/2011/04/02/how-to-search-multiple-pdf-documents-at-once/#comments</comments> <pubDate>Sat, 02 Apr 2011 14:28:08 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Software]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[foxit reader]]></category> <category><![CDATA[pdf]]></category> <category><![CDATA[pdf search]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=43396</guid> <description><![CDATA[Most pdf readers provide you with a built-in search to find words or phrases in the active pdf document. But what if you want to search for a specific text or phrase in multiple documents? Sure, you could make use of Windows Search or another desktop search application to find what you are looking for; [...]]]></description> <content:encoded><![CDATA[<p>Most pdf readers provide you with a built-in search to find words or phrases in the active pdf document. But what if you want to search for a specific text or phrase in multiple documents? Sure, you could make use of Windows Search or another desktop search application to find what you are looking for; Or, you could use the advanced search capabilities of Adobe Reader or Foxit Reader to search multiple pdfs at once.</p><p>You can initiate a standard search by pressing Ctrl-f, or<br
/> selecting the Edit > Search option from the menu. Advanced Search on the other hand is triggered with the shortcut Shift-Ctrl-f or via the Edit > Advanced Search menu.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/04/adobe-reader-advanced-search.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/04/adobe-reader-advanced-search.png" alt="adobe reader advanced search" title="adobe reader advanced search" width="289" height="400" class="alignnone size-full wp-image-43398" /></a></p><p><a
href="http://get.adobe.com/reader/">Adobe Reader</a> is not the only pdf reader that can find text in multiple pdf documents. <a
href="http://www.foxitsoftware.com/pdf/reader/">Foxit Reader</a>, a free pdf reading alternative, offers similar options. Foxit Reader users can use the shortcut Ctrl-Shift-f or select Tools > Search to open the search form of the program in a sidebar.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/04/foxit-reader-search.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/04/foxit-reader-search.png" alt="foxit reader search" title="foxit reader search" width="484" height="345" class="alignnone size-full wp-image-43399" /></a></p><p>Adobe Reader opens the advanced search options in a new window. Here it is possible to switch from searching the current document to searching all pdfs in a folder on the hard drive. The folder is freely selectable, with My Documents being suggested by default.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/04/search-multiple-pdfs.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/04/search-multiple-pdfs.png" alt="search multiple pdfs" title="search multiple pdfs" width="488" height="479" class="alignnone size-full wp-image-43400" /></a></p><p>A word or phrase needs to be entered into the search configuration form window. Expert users click on the Show More Options link at the bottom to display additional search filters and options.</p><p>Here it is then possible to include comments, attachments and bookmarks in the search, or search for whole words or case sensitive words only.</p><p>The more options page can be used to add additional search criteria, for instance to only search documents that have been created before or after a certain date, that have been written by a specific author or that contain object data or images.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/04/advanced-pdf-search.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/04/advanced-pdf-search.png" alt="advanced pdf search" title="advanced pdf search" width="472" height="462" class="alignnone size-full wp-image-43401" /></a></p><p>It may take a while to scan the contents of all pdf documents that match the criteria. Adobe Reader displays the results in the same window. Results are sorted by document, and every instance of the word or phrase is shown on a separate line. A click on a line opens the containing page in the main Adobe Reader window.</p><p>Foxit Reader&#8217;s multi-pdf search options are limited in comparison. Here it is only possible to enter a search word or phrase, a directory that contains the pdf documents and a whole word and case sensitive filter.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/04/foxit-reader-search-pdfs.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/04/foxit-reader-search-pdfs.png" alt="foxit reader search pdfs" title="foxit reader search pdfs" width="243" height="295" class="alignnone size-full wp-image-43402" /></a></p><p>Search results are displayed in a sidebar in the application window, a click puts the focus on the containing page. The search terms are highlighted by both applications on the pdf page.</p><p>Both programs are capable of finding text in multiple pdf documents. Users who need the additional filtering options find Adobe Reader&#8217;s pdf search more suitable as it offers more advanced options.</p><p>Are you using a different program or service to search for contents  in multiple pdf documents? Let me know in the comments.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/04/02/how-to-search-multiple-pdf-documents-at-once/feed/</wfw:commentRss> <slash:comments>13</slash:comments> </item> <item><title>Adobe Security Updates For Flash, Adobe Reader</title><link>http://www.ghacks.net/2011/03/22/adobe-security-updates-for-flash-adobe-reader/</link> <comments>http://www.ghacks.net/2011/03/22/adobe-security-updates-for-flash-adobe-reader/#comments</comments> <pubDate>Tue, 22 Mar 2011 09:33:04 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe flash]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=42914</guid> <description><![CDATA[Adobe has released updates for their popular Adobe Flash Player, Adobe Reader and Adobe Acrobat applications. The updates address a critical security vulnerability that was discoveredearlier this month. The critical vulnerability affects Adobe Flash, and since Adobe implemented Flash technology in Adobe Reader and Acrobat, those products as well. The Flash vulnerability affects all Adobe [...]]]></description> <content:encoded><![CDATA[<p>Adobe has released updates for their popular Adobe Flash Player, Adobe Reader and Adobe Acrobat applications. The updates address a critical security vulnerability that <a
href="http://www.ghacks.net/2011/03/14/new-critical-0-day-flash-vulnerability-exploited-via-excel-attachments/">was discovered</a>earlier this month.</p><p>The critical vulnerability affects Adobe Flash, and since Adobe implemented Flash technology in Adobe Reader and Acrobat, those products as well.</p><p>The Flash vulnerability affects all Adobe Flash Player 10.2.152.33 and earlier versions on all supported operating systems, as well as Flash Player 10.2.154.18 and earlier for Chrome, Flash Player 10.1.106.16 and earlier for Android and Adobe AIR 2.5 and earlier. Google recently pushed an update that resolved the vulnerability for Chrome.</p><p>Attackers can exploit the vulnerability to cause a crash which could allow them to take control over the affected system. We already mentioned in our first report on March 14 that the issue was actively exploited by attackers in the form of embedded Flash files in Microsoft Excel documents that were delivered as email attachments.</p><p>The Flash Player update <a
href="http://www.adobe.com/support/security/bulletins/apsb11-05.html">is available</a> on the official Flash download page over at Adobe. Google Chrome users with automatic updates enabled do not need to download the update as Google has already pushed an update to all Chrome users that updated Flash to the latest version.</p><p>The new Flash version is 10.2.153.1 for all supported desktop PCs, 10.2.156.12 for Android and 10.2.154.25 for Google Chrome.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/03/adobe-flash-player.png" alt="adobe flash player" title="adobe flash player" width="335" height="108" class="alignnone size-full wp-image-42917" /></p><p>Adobe AIR users can download the new version of the application <a
href="http://get.adobe.com/air/">from the</a> official Adobe AIR download center, the new Adobe Air version is 2.6.</p><p>Users <a
href="http://www.adobe.com/software/flash/about/">can verify</a> their version of Adobe Flash by visiting the About Adobe Flash Player page.</p><p>The Security Bulletin that lists additional information is accessible <a
href="http://www.adobe.com/support/security/bulletins/apsb11-05.html">here</a>.</p><p>Adobe has released an update for Adobe Reader and Acrobat as well to address the same critical security vulnerability. Adobe Reader and Acrobat X, 10.x and 9.x are affected on Windows and Macintosh systems.</p><p>Existing Adobe Reader and Adobe Acrobat users can use the built-in updating functionality to update the software to the latest version. They need to open Adobe Reader and select Help > Check for Updates from the menu to initiate that process.</p><p>It needs to be noted that Adobe is not supplying an update for Adobe Reader X at this point in time. The reasoning is that Adobe Reader X is using Protected Mode which &#8220;would prevent an exploit of this kind from executing&#8221;. The update will be addressed on the coming quarterly security update which is scheduled for June 14.</p><p>The security bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb11-06.html">lists</a> additional information about the vulnerability, and download links that point to the latest program versions of affected applications.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/03/22/adobe-security-updates-for-flash-adobe-reader/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>New Critical 0-day Flash Vulnerability Exploited Via Excel Attachments</title><link>http://www.ghacks.net/2011/03/14/new-critical-0-day-flash-vulnerability-exploited-via-excel-attachments/</link> <comments>http://www.ghacks.net/2011/03/14/new-critical-0-day-flash-vulnerability-exploited-via-excel-attachments/#comments</comments> <pubDate>Mon, 14 Mar 2011 19:46:36 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe flash]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[security vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=42506</guid> <description><![CDATA[Adobe today has released a new security advisory for Adobe Flash Player, Adobe Reader and Acrobat. All three applications are affected by a critical 0-day vulnerability that is exploited via Excel email attachments. Vulnerable versions are Adobe Flash Player 10.2.154.33 and earlier for all supported desktop operating systems, Adobe Flash Player 10.1.106.16 and earlier for [...]]]></description> <content:encoded><![CDATA[<p>Adobe today has released a new security advisory for Adobe Flash Player, Adobe Reader and Acrobat. All three applications are affected by a critical 0-day vulnerability that is exploited via Excel email attachments. Vulnerable versions are Adobe Flash Player 10.2.154.33 and earlier for all supported desktop operating systems, Adobe Flash Player 10.1.106.16 and earlier for Android and Adobe Reader and Acrobat X, 10.x and 9.x for Windows and Macintosh.</p><p>Adobe has confirmed reports that the vulnerability is actively exploited via swf files that are embedded in Microsoft Excel files that are delivered via email attachments. A successful exploit causes a crash of the application and could give an attacker control over the computer system.</p><p>A security fix is in the final stages of development, and Adobe estimates that it can be distributed during the next week. Computer users for now should be very cautious when they receive emails with Excel attachments, especially if the sender is unknown. It may be a good idea to open the documents online, for instance via Google Docs instead of a desktop client to block potential attacks.</p><p>Protected Mode of Adobe Reader X mitigates the issue according to Adobe, so that the security fix for that version will be delivered with the quarterly security update that is scheduled for June 14.</p><p>In short:</p><ul><li>All Flash Player versions 10 are affected for all supported desktop and mobile operating systems.</li><li>All versions of Adobe Reader and Acrobat X, 10 and 9 are affected</li><li>The vulnerability is exploited via Excel email attachments that have a Flash file embedded.</li><li>A patch will be delivered in the next week</li></ul><p>Additional information are available at the <a
href="http://www.adobe.com/support/security/advisories/apsa11-01.html">Security Advisory</a> over at Adobe&#8217;s website.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/03/14/new-critical-0-day-flash-vulnerability-exploited-via-excel-attachments/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Adobe Security Bulletin Summary Feburary 2011</title><link>http://www.ghacks.net/2011/02/09/adobe-security-bulletin-summary-feburary-2011/</link> <comments>http://www.ghacks.net/2011/02/09/adobe-security-bulletin-summary-feburary-2011/#comments</comments> <pubDate>Wed, 09 Feb 2011 08:23:40 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe flash player]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=39719</guid> <description><![CDATA[Adobe Software yesterday released updates for some of its popular software applications, including updates for Adobe Reader, Acrobat and the Adobe Flash Player. The updates address critical security issues in the products making them mandatory updates for all users of said products. The security update for Adobe Flash Player fixes several critical vulnerability in Flash [...]]]></description> <content:encoded><![CDATA[<p>Adobe Software yesterday released updates for some of its popular software applications, including updates for Adobe Reader, Acrobat and the Adobe Flash Player. The updates address critical security issues in the products making them mandatory updates for all users of said products.</p><p>The security update for Adobe Flash Player fixes several critical vulnerability in Flash Player 10.1.102.64 and earlier on Windows, Macintosh, Linux and Solaris. Successful exploits could &#8220;cause the application to crash and could potentially allow an attacker to take control of the affected system&#8221;.</p><p>The update increases the version of the application to Adobe Flash Player 10.2.152.26 on all affected systems.</p><p>The update can be downloaded <a
href="http://get.adobe.com/flashplayer/">directly</a> from Adobe.</p><p>More information about the update are <a
href="http://www.adobe.com/support/security/bulletins/apsb11-02.html">available</a> on Adobe&#8217;s Security Bulletin page.</p><h3>Adobe Reader, Acrobat</h3><p>Critical vulnerabilities have also been identified in Adobe Reader and Acrobat. Affected versions include Adobe Reader X, Adobe Reader 9.4.1 for Windows, Macintosh and Unix, and Adobe Acrobat X and earlier for Windows and Macintosh. Please note that the update incorporates the Adobe Flash Player update.</p><p>The vulnerabilities &#8220;could cause the application to crash and potentially allow an attacker to take control of the affected system. Risk for Adobe Reader X users is significantly lower, as none of these issues bypass Protected Mode mitigations&#8221;.</p><p>Updates are available to increase the version of Adobe Reader X to 10.0.1, Adobe Reader 9.4.1 to 9.4.2 and Adobe Acrobat X to 10.0.1.</p><p>Download links for all affected applications are <a
href="http://www.adobe.com/support/security/bulletins/apsb11-03.html">posted</a> on the security bulletin page over at Adobe.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/02/09/adobe-security-bulletin-summary-feburary-2011/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Microsoft, Adobe Post February 2011 Patch Day Information</title><link>http://www.ghacks.net/2011/02/05/microsoft-adobe-post-february-2011-patch-day-information/</link> <comments>http://www.ghacks.net/2011/02/05/microsoft-adobe-post-february-2011-patch-day-information/#comments</comments> <pubDate>Sat, 05 Feb 2011 09:46:32 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Microsoft]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[patch tuesday]]></category> <category><![CDATA[windows patches]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=39608</guid> <description><![CDATA[Patch Tuesday is coming up and Microsoft has released an advanced notification about the upcoming security patches. Patch Tuesday refers to the second Tuesday of each month on which security patches are released to the public. The Microsoft Security Bulletin Advance Notification for February 2011 details the upcoming patches. A total of 12 security bulletins [...]]]></description> <content:encoded><![CDATA[<p>Patch Tuesday is coming up and Microsoft has released an advanced notification about the upcoming security patches. Patch Tuesday refers to the second Tuesday of each month on which security patches are released to the public.</p><p>The Microsoft Security Bulletin Advance Notification for February 2011 details the upcoming patches. A total of 12 security bulletins are released next Tuesday of which all but one fix issues in the Microsoft Windows operating system. The remaining patch fixes a vulnerability in Microsoft Office.</p><p>Three of the security vulnerabilities have received a maximum severity rating of critical, the highest available rating, the remaining nine a severity rating of important.</p><ul><li>Microsoft&#8217;s newest operating system Windows 7 is affected by seven of the twelve issues. Of those, two are rated critical and the remaining five as important.</li><li>Windows Vista is affected by six vulnerabilities with three rated as critical and the remaining three as important.</li><li>Windows XP is affected by eight vulnerabilities with two being rated as critical and six as important.</li><li>Windows Server 2003 is affected by 10 vulnerabilities of which one is critical, eight are important and one is moderate.</li><li>Windows Server 2008 is affected in the same way as the Vista operating system, with the exception that one of the critical vulnerabilities is only rated as moderate here.</li><li>Windows Server 2008 R2 finally is affected the same way as Windows 7, again with the exception of two vulnerabilities that are rated as moderate instead of critical and important.</li></ul><p>The remaining vulnerabiliy affected Microsoft Visio 2002 Service Pack 2, Visio 2003 Service Pack 3 and Visio 2007 Service Pack 2. It is rated as important.</p><p>The advanced notifications are accessible <a
href="http://www.microsoft.com/technet/security/bulletin/ms11-feb.mspx">here</a>.</p><h3>Adobe</h3><p>Adobe has <a
href="http://www.adobe.com/support/security/bulletins/apsb11-03.html">released</a> a Prenotification Security Advisory for Adobe Reader and Acrobat.</p><blockquote><p>Adobe is planning to release updates for Adobe Reader X (10.0) for Windows and Macintosh, Adobe Reader 9.4.1 and earlier versions for Windows, Macintosh and UNIX, Adobe Acrobat X (10.0) for Windows and Macintosh, and Adobe Acrobat 9.4.1 and earlier versions for Windows and Macintosh to resolve critical security issues. Adobe expects to make updates for Windows and Macintosh available on Tuesday, February 8, 2011. An update for UNIX is expected to be available by the week of February 28, 2011.</p></blockquote><p>Expect lots of patching next Tuesday. We will post detailed information once the patches are released by Microsoft and Adobe.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/02/05/microsoft-adobe-post-february-2011-patch-day-information/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Adobe Reader X Offline Installers</title><link>http://www.ghacks.net/2010/11/22/adobe-reader-x-offline-installers/</link> <comments>http://www.ghacks.net/2010/11/22/adobe-reader-x-offline-installers/#comments</comments> <pubDate>Mon, 22 Nov 2010 09:13:23 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[offline]]></category> <category><![CDATA[pdf reader]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=37161</guid> <description><![CDATA[If you do not like Adobe&#8217;s Download Manager, or want to distribute Adobe Reader to computer systems without direct Internet connection, then you may want to use or even need the Adobe Reader offline installers to do so. This guide explains where those offline installers of Adobe&#8217;s pdf reader can be downloaded. I&#8217;ll also include [...]]]></description> <content:encoded><![CDATA[<p>If you do not like Adobe&#8217;s Download Manager, or want to distribute Adobe Reader to computer systems without direct Internet connection, then you may want to use or even need the Adobe Reader offline installers to do so.</p><p>This guide explains where those offline installers of Adobe&#8217;s pdf reader can be downloaded. I&#8217;ll also include an explanation where future offline installers can be found at, to make this method foolproof with future Adobe Reader updates.</p><h2>Adobe Reader X Offline Installers Windows</h2><ul><li>Adobe Reader X French Offline Installer [<a
href="ftp://ftp.adobe.com/pub/adobe/reader/win/10.x/10.0.0/fr_FR/AdbeRdr1000_fr_FR.exe">link</a>]</li><li>Adobe Reader X German Offline Installer [<a
href="ftp://ftp.adobe.com/pub/adobe/reader/win/10.x/10.0.0/de_DE/AdbeRdr1000_de_DE.exe">link</a>]</li><li>Adobe Reader X Japanese Offline Installer [<a
href="ftp://ftp.adobe.com/pub/adobe/reader/win/10.x/10.0.0/ja_JP/AdbeRdr1000_ja_JP.exe">link</a>]</li><li>Adobe Reader X US-English Offline Installer [<a
href="ftp://ftp.adobe.com/pub/adobe/reader/win/10.x/10.0.0/en_US/AdbeRdr1000_en_US.exe">link</a>]</li></ul><h2>Adobe Reader X Offline Installers Mac</h2><ul><li>Adobe Reader X French Offline Installer [<a
href="ftp://ftp.adobe.com/pub/adobe/reader/mac/10.x/10.0.0/fr_FR/AdbeRdr1000_fr_FR.dmg">link</a>]</li><li>Adobe Reader X German Offline Installer [<a
href="ftp://ftp.adobe.com/pub/adobe/reader/mac/10.x/10.0.0/de_DE/AdbeRdr1000_de_DE.dmg">link</a>]</li><li>Adobe Reader X Japanese Offline Installer [<a
href="ftp://ftp.adobe.com/pub/adobe/reader/mac/10.x/10.0.0/ja_JP/AdbeRdr1000_ja_JP.dmg">link</a>]</li><li>Adobe Reader X US-English Offline Installer [<a
href="ftp://ftp.adobe.com/pub/adobe/reader/mac/10.x/10.0.0/en_US/AdbeRdr1000_en_US.dmg">link</a>]</li></ul><h2>Adobe Reader X Offline Installers Linux</h2><p><strong>Not yet available, expected to be released at the end of this month.</strong></p><h3>How To Find Future Adobe Reader Offline Installer Packages</h3><p>Adobe loads offline installers on their public ftp server. All you need to do to download a new offline installer after an update of Adobe Reader is to visit the following ftp directories on Adobe&#8217;s ftp server. You need to follow the path to the latest version.</p><p>Just open <a
href="ftp://ftp.adobe.com/pub/adobe/reader/">this</a> ftp directory in a browser or ftp server and navigate to the release of Adobe Reader that you need. It begins with the selection of the operating system (Win for Windows, Mac for Apple Macintosh and Unix for all Linux variants).</p><p>The major release versions are then displayed in the subdirectory. Just select the highest version (in this case it would be 10.x) and follow the lead. After that the supported languages are displayed. Pick your language, this leads to direct downloads of Adobe Reader offline installers in the selected language.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/11/22/adobe-reader-x-offline-installers/feed/</wfw:commentRss> <slash:comments>17</slash:comments> </item> <item><title>Adobe Reader X Download Available</title><link>http://www.ghacks.net/2010/11/19/adobe-reader-x-download-available/</link> <comments>http://www.ghacks.net/2010/11/19/adobe-reader-x-download-available/#comments</comments> <pubDate>Fri, 19 Nov 2010 08:11:43 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[pdf reader]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=37036</guid> <description><![CDATA[Adobe&#8217;s latest pdf reader Adobe Reader x has been released yesterday. Wait X? Why did Adobe move to Roman numerals? Maybe they have switched numerals to visualize the cut, or the beginning of a new era, for their product. Maybe it is just because they thing the X is cooler than the 10. Whatever the [...]]]></description> <content:encoded><![CDATA[<p>Adobe&#8217;s latest pdf reader Adobe Reader x has been released yesterday. Wait X? Why did Adobe move to Roman numerals? Maybe they have switched numerals to visualize the cut, or the beginning of a new era, for their product. Maybe it is just because they thing the X is cooler than the 10. Whatever the reason, it will be interesting to see how the following Adobe Reader releases will be named (Adobe Reader XI for 11 and Adobe Reader XIX for 19, do not sound right). Chance is Adobe will switch back to Adobe Reader 11 when the time comes.</p><p>But what makes Adobe Reader x different from previous releases of the pdf reader?</p><blockquote><p>Reader X for desktop enables an even greater level of interaction with the ability to share feedback through the use of Sticky Notes and Highlighter tools, as well as view a larger variety of content types including drawings, email messages, spreadsheets, videos, and other multimedia elements. You can also take advantage of the added security of Protected Mode in Reader X, which helps ensure safer viewing of PDF files.</p></blockquote><p>It is rather strange that the announcement <a
href="http://blogs.adobe.com/adobereader/2010/11/adobe-reader-x-now-available.html">by</a> Steve Gottwals over at Adobe lists the feature that I would consider the most important at the end of the new feature description.</p><p>So what&#8217;s Adobe Reader Protected Mode?</p><blockquote><p>[..] Protected Mode is a sandboxing technology based on Microsoft’s Practical Windows Sandboxing technique. It is similar to the Google Chrome sandbox and Microsoft Office 2010 Protected Viewing Mode. [..] With Adobe Reader Protected Mode enabled (it will be by default), all operations required by Adobe Reader to display the PDF file to the user are run in a very restricted manner inside a confined environment, the “sandbox.” Should Adobe Reader need to perform an action that is not permitted in the sandboxed environment, such as writing to the user’s temporary folder or launching an attachment inside a PDF file using an external application (e.g. Microsoft Word), those requests are funneled through a “broker process,” which has a strict set of policies for what is allowed and disallowed to prevent access to dangerous functionality. (<a
href="http://blogs.adobe.com/asset/2010/07/introducing-adobe-reader-protected-mode.html">via</a>)</p></blockquote><p>Adobe Reader X comes with protected mode enabled by default. That&#8217;s great for users who felt that to many security vulnerabilities were discovered for Adobe&#8217;s pdf reader.</p><p>The main purpose of the sandbox is to mitigate attacks, so that the impact on the system is negligible.</p><p>The initial release of protected mode does is not a feature complete release.</p><blockquote><p> This first release will sandbox all “write” calls on Windows 7, Windows Vista, Windows XP, Windows Server 2008, and Windows Server 2003. This will mitigate the risk of exploits seeking to install malware on the user’s computer or otherwise change the computer’s file system or registry</p></blockquote><p>Adobe plans to extend the sandbox by including read-only activities &#8221; to protect against attackers seeking to read sensitive information on the user’s computer&#8221;.</p><p>Adobe Reader X is <a
href="http://get.adobe.com/reader/">available</a> for download at the official Adobe website.</p><p>Users who prefer to download Adobe Reader X directly can download it from Adobe&#8217;s ftp site instead:</p><ul><li>Adobe Reader X Windows Download: ftp://ftp.adobe.com/pub/adobe/reader/win/10.x/10.0.0/</li><li>Adobe Reader X Linux Download:ftp://ftp.adobe.com/pub/adobe/reader/unix/</li><li>Adobe Reader X Mac Download: ftp://ftp.adobe.com/pub/adobe/reader/mac/</li></ul> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/11/19/adobe-reader-x-download-available/feed/</wfw:commentRss> <slash:comments>14</slash:comments> </item> <item><title>Adobe Patches, And Reports New Vulnerabilities</title><link>http://www.ghacks.net/2010/11/05/adobe-patches-and-reports-new-vulnerabilities/</link> <comments>http://www.ghacks.net/2010/11/05/adobe-patches-and-reports-new-vulnerabilities/#comments</comments> <pubDate>Fri, 05 Nov 2010 11:31:41 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[flash player]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=36568</guid> <description><![CDATA[Adobe&#8217;s Flash Player was updated yesterday fixing several security vulnerabilities in the process. The patch was initially slated for a November 9 release but released in advance yesterday. But Adobe Flash was not the only vulnerable Adobe product. Adobe has scheduled an update for their popular pdf readers Adobe Reader and Adobe Acrobat on November [...]]]></description> <content:encoded><![CDATA[<p>Adobe&#8217;s Flash Player was updated yesterday fixing several security vulnerabilities in the process. The patch was initially slated for a November 9 release but released in advance yesterday. But Adobe Flash was not the only vulnerable Adobe product. Adobe has scheduled an update for their popular pdf readers Adobe Reader and Adobe Acrobat on November 15 to fix an actively exploited vulnerability.</p><p>To make matters worse, a new vulnerability has been confirmed by Adobe affecting Adobe Reader 9.2 or later and Adobe Reader 8.1.7 or later. A &#8220;proof-of-concept file demonstrating a Denial of Service was published&#8221; already that crashes the pdf reader.  The exploit does not demonstrate arbitrary code execution, but Adobe is not eliminating the possibility at this point in time. It has to be noted that Adobe Acrobat is not affected by the security vulnerability.</p><p>The blog post <a
href="http://blogs.adobe.com/psirt/2010/11/potential-issue-in-adobe-reader.html">of the</a> Security and Response team offers instructions on how to protect the computer system from this vulnerability.</p><blockquote><p>Adobe Reader 9.2 and later and Adobe Reader 8.1.7 and later – Windows</p><p>On Windows, the JavaScript Blacklist can be in two locations. Please review the following options and then create the registry key of your choice:</p><p>Enterprise list: This blacklist helps enterprises roll out policies that block exploitable API(s) from executing in their environment. Populating the blacklist in this location is the responsibility of the enterprise. Adobe patches never modify this registry location.<br
/> To create the registry key:<br
/> HKLM\SOFTWARE\Policies\Adobe\&lt;product&gt;\&lt;version&gt;\FeatureLockDown\cJavaScriptPerms\tBlackList</p><p>Adobe’s update/patch list: The Adobe blacklist is modified by Adobe Reader patches whenever an API is deemed vulnerable. APIs are also removed from the blacklist whenever a fix for a vulnerability is provided by the current patch.<br
/> To create the registry key:<br
/> HKLM\SOFTWARE\Adobe\&lt;product&gt;\&lt;version&gt;\JavaScriptPerms\tBlackList</p><p> On a 64 bit Windows system, the path is:<br
/> HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Adobe</p><p>->To prevent this particular issue, add the following value to the registry key created in the previous step (case sensitive):<br
/> Doc.printSeps</p><p>->Exit and restart the application</p><p>Adobe Reader 9.2 and later and Adobe Reader 8.1.7 and later – Macintosh</p><p> On your Macintosh computer, go to the Applications folder or to the location where you have Adobe Reader installed.<br
/> Right-click on Adobe Reader<br
/> Click on Show Package Contents<br
/> Expand Contents<br
/> Expand MacOS<br
/> Expand Preferences<br
/> Create a backup of the FeatureLockDown file.<br
/> Right-click on FeatureLockDown.<br
/> Open With TextEdit.<br
/> Just before the last >> add the following line to the FeatureLockDown file (case sensitive):<br
/> /JavaScriptPerms [ /c &lt;&lt; /BlackList [ /t (Doc.printSeps) ] &gt;&gt; ]<br
/> Save the file<br
/> Restart Adobe Reader</p><p>Adobe Reader 9.2 and later – UNIX</p><p> Go to the Global Prefs file at:<br
/> /Reader/GlobalPrefs/reader_prefs<br
/> Add the following line to the file:<br
/> /JavaScriptPerms [/c << /BlackList [/t (Doc.printSeps) ] >> ]</p></blockquote><p>There you have it. Make sure you protect your version of Adobe Reader from the vulnerability by following the instructions posted above. The posting does not offer any information on the consequences of protecting the pdf reader from the vulnerability. It is also not clear if Adobe will be able to include the patch for this vulnerability in the upcoming update.</p><p>As if that was not enough, there is <a
href="http://secunia.com/advisories/42112/">also a new</a> vulnerability in Adobe Shockwave Player.</p><blockquote><p>Krystian Kloskowski has discovered a vulnerability in Shockwave Player, which can be exploited by malicious people to compromise a user&#8217;s system.</p><p>The vulnerability is caused due to a use-after-free error in an automatically installed compatibility component as a function in an unloaded library may be called.</p><p>Successful exploitation allows execution of arbitrary code, but requires that a user is tricked into opening the &#8220;Shockwave Settings&#8221; window when viewing a web page.</p><p>The vulnerability is confirmed in version 11.5.9.615. Other versions may also be affected.</p></blockquote><p>The description makes it clear that systems are only vulnerable to this attack if the user opens the Shockwave Settings window on a specially prepared website.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/11/05/adobe-patches-and-reports-new-vulnerabilities/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>New 0-day Adobe Vulnerabilities</title><link>http://www.ghacks.net/2010/10/29/new-0-day-adobe-vulnerabilities/</link> <comments>http://www.ghacks.net/2010/10/29/new-0-day-adobe-vulnerabilities/#comments</comments> <pubDate>Fri, 29 Oct 2010 08:12:15 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe flash security]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <category><![CDATA[flash player]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=36334</guid> <description><![CDATA[It has been a bad year for Adobe&#8217;s security team, as Adobe products where hit with many critical security vulnerabilities in that time. The latest was just announced yesterday in a security advisory over at Adobe. The critical vulnerability affects both Adobe Flash Player versions 10.1.85.3 and earlier on all supported operating systems (that&#8217;s Windows, [...]]]></description> <content:encoded><![CDATA[<p>It has been a bad year for Adobe&#8217;s security team, as Adobe products where hit with many critical security vulnerabilities in that time. The latest was just announced yesterday in a security advisory over at Adobe. The critical vulnerability affects both Adobe Flash Player versions 10.1.85.3 and earlier on all supported operating systems (that&#8217;s Windows, Mac, Linux, Solaris and Android [gasp]) and Adobe Reader 9.4 and earlier 9.x versions on Windows, Mac and Unix.</p><p>Basically, both Flash Player and Adobe Reader / Acrobat are affected by the security vulnerability. According to Adobe&#8217;s security bulletin, the issue is actively exploited against Adobe Reader and Acrobat on Windows.</p><p><a
href="http://www.adobe.com/support/security/advisories/apsa10-05.html">Adobe</a> is currently working on patches and aims to release the Flash Player patch on November 9, 2010 and the Adobe Reader / Acrobat patch on November 15, 2010. That&#8217;s puzzling considering that the company has admitted that the issue is actively exploited against Adobe Reader and Acrobat.</p><p>Mitigations were posted to protect the computer system.</p><blockquote><p>Deleting, renaming, or removing access to the authplay.dll file that ships with Adobe Reader and Acrobat 9.x mitigates the threat for those products, but users will experience a non-exploitable crash or error message when opening a PDF file that contains Flash (SWF) content. The authplay.dll that ships with Adobe Reader and Acrobat 9.x for Windows is typically located at C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll for Adobe Reader or C:\Program Files\Adobe\Acrobat 9.0\Acrobat\authplay.dll for Acrobat.</p></blockquote><p>No mitigating factors were offered for the Flash vulnerability. The only ones that are known to work are to either disable Adobe Flash in the browser, or to use a flash blocking script such as NoScript for Firefox.</p><p><a
href="http://www.theregister.co.uk/2010/10/28/adobe_reader_critical_vuln/">The Register</a> has additional information about the pdf exploit. According to their information, attackers &#8220;install a nasty trojan known as Wisp, which according to Microsoft, steals sensitive user data and installs a backdoor on compromised systems.&#8221;</p><p>With patches as far away as two weeks, it is recommended to disable authplay.dll in Adobe Reader or Acrobat, and disable or block the Flash plugin in the web browser to protect the computer system against these attacks.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/10/29/new-0-day-adobe-vulnerabilities/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Adobe Reader 9.4 Download Available</title><link>http://www.ghacks.net/2010/10/06/adobe-reader-9-4-download-available/</link> <comments>http://www.ghacks.net/2010/10/06/adobe-reader-9-4-download-available/#comments</comments> <pubDate>Wed, 06 Oct 2010 08:25:29 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader update]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[pdf reader]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=35618</guid> <description><![CDATA[Adobe has just released an update for their popular pdf reader Adobe Reader and Adobe Acrobat, raising versions of the two programs to 9.4. Both program updates fix critical security vulnerabilities identified in Adobe Reader 9.3.4 and earlier, as well as Acrobat 9.3.4 and earlier. Vulnerabilities affect all supported operating systems, and users are encouraged [...]]]></description> <content:encoded><![CDATA[<p>Adobe has just released an update for their popular pdf reader Adobe Reader and Adobe Acrobat, raising versions of the two programs to 9.4. Both program updates fix critical security vulnerabilities identified in Adobe Reader 9.3.4 and earlier, as well as Acrobat 9.3.4 and earlier. Vulnerabilities affect all supported operating systems, and users are encouraged to upgrade their version as soon as possible to protect their computer system from exploits.</p><p>The rushed state of the release indicates that the issue gets actively exploited which is confirmed in Adobe&#8217;s Security Bulletin that mentions that the issue is being actively exploited in the wild. Attackers may be able to crash the application on the computer and take control of the affected system in the process. Upgrading is the only way of protecting the computer from those vulnerabilities.</p><blockquote><p>Adobe recommends users of Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX update to Adobe Reader 9.4. (For Adobe Reader users on Windows and Macintosh,<br
/> who cannot update to Adobe Reader 9.4, Adobe has provided the Adobe Reader 8.2.5 update.) Adobe recommends users of Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh update to Adobe Acrobat 9.4. Adobe recommends users of Adobe Acrobat 8.2.4 and earlier versions for Windows and Macintosh update to Adobe Acrobat 8.2.5.</p></blockquote><p>This accelerated patch breaks Adobe&#8217;s quarterly patch day that is set for every second Tuesday of each quarter of the year to fall in line with Microsoft&#8217;s Patch Tuesday. Interested users can take a closer look at the <a
href="http://www.adobe.com/support/security/bulletins/apsb10-21.html">Security Bulletin</a>, or point their web browsers to <a
href="http://get.adobe.com/reader/">Get Adobe Reader</a> right away to download the latest version of the pdf reader. Updates are also available directly in the program (by clicking on Help > Check for Updates).</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/10/06/adobe-reader-9-4-download-available/feed/</wfw:commentRss> <slash:comments>7</slash:comments> </item> <item><title>Adobe Hit By Yet Another Flash 0-day Exploit</title><link>http://www.ghacks.net/2010/09/14/adobe-hit-by-yet-another-flash-0-day-exploit/</link> <comments>http://www.ghacks.net/2010/09/14/adobe-hit-by-yet-another-flash-0-day-exploit/#comments</comments> <pubDate>Tue, 14 Sep 2010 09:07:18 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Browsing]]></category> <category><![CDATA[Firefox]]></category> <category><![CDATA[Google Chrome]]></category> <category><![CDATA[Internet Explorer]]></category> <category><![CDATA[Opera]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe flash]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[flash]]></category> <category><![CDATA[flash security]]></category> <category><![CDATA[flash vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=34415</guid> <description><![CDATA[Some time ago I made the decision to dump the two popular Adobe products Adobe Flash and Adobe Reader from my system. Since then, Adobe did not come to rest, as the company was hit by one 0-day exploit after the other. What made matters worse was the reaction time to fix the exploits, which [...]]]></description> <content:encoded><![CDATA[<p>Some time ago I made the decision to dump the two popular Adobe products Adobe Flash and Adobe Reader from my system. Since then, Adobe did not come to rest, as the company was hit by one 0-day exploit after the other. What made matters worse was the reaction time to fix the exploits, which usually were a week at best and often a month or more.</p><p>User systems in the meantime were susceptible to those attacks. The latest critical vulnerability in Flash was <a
href="http://www.adobe.com/support/security/advisories/apsa10-03.html">revealed</a> in a security advisory at the Adobe website.</p><p>The critical vulnerability in all Flash Player versions for all supported operating systems &#8211; yes even Android &#8211; impacts not only systems running Flash, but also systems running Adobe Reader 9.3.4 and Adobe Acrobat 9.3.4.</p><p>Adobe states that &#8220;this vulnerability could cause a crash and potentially allow an attacker to take control of the affected system&#8221; with reports that the vulnerability is already actively exploited in the wild &#8220;against Adobe Flash Player on Windows&#8221;.</p><p>Adobe expects to provide an update during the week of September 27 for Adobe Flash Player, and October 4 for Adobe Reader and Acrobat.</p><p>Until then, all users running Adobe Flash or Adobe Reader / Acrobat are vulnerable to the critical vulnerability. Make sure your security software detects the vulnerability and blocks it from execution.</p><p>One question that Chrome readers may have in mind: Is the build in Flash plugin also susceptible for attacks? In short, yes it is. The latest Chrome internal Flash Player plugin version is listed as 10.1.82.76, which is exactly the version that is vulnerable. The design of the browser may however mitigate the impact on the system, as may the out of process feature of the Firefox web browser.</p><p>We say may because we have no confirmation at this point.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/09/14/adobe-hit-by-yet-another-flash-0-day-exploit/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Adobe Reader 9.3.4 Released, Update Now</title><link>http://www.ghacks.net/2010/08/20/adobe-reader-9-3-4-released-update-now/</link> <comments>http://www.ghacks.net/2010/08/20/adobe-reader-9-3-4-released-update-now/#comments</comments> <pubDate>Fri, 20 Aug 2010 07:48:44 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader security]]></category> <category><![CDATA[adobe reader update]]></category> <category><![CDATA[pdf reader]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=33375</guid> <description><![CDATA[Adobe in a security advisory yesterday released new versions of their popular pdf reading applications Adobe Reader and Acrobat. Adobe Reader 9.3.3, which was released less than a month ago, is replaced by version 9.3.4. Adobe Reader and Acrobat 9.3.4 fix several critical security vulnerabilities in Adobe Reader 9.3.3 and earlier for Windows, Macintosh and [...]]]></description> <content:encoded><![CDATA[<p>Adobe in a security advisory yesterday released new versions of their popular pdf reading applications Adobe Reader and Acrobat. Adobe Reader 9.3.3, which was released less than a month ago, is replaced by version 9.3.4. Adobe Reader and Acrobat 9.3.4 fix several critical security vulnerabilities in Adobe Reader 9.3.3 and earlier for Windows, Macintosh and Unix.</p><p>The out-of-cycle update outlines the severity of the vulnerabilities that have been parched in the version, as Adobe usually releases updates in a three month cycle.</p><p>The updates address previously disclosed security vulnerabilities at the Black Hat USA 2010 conference on July 28, and furthermore incorporate the Adobe Flash Player update noted in the security bulletin released in July.</p><blockquote><p>Adobe recommends users of Adobe Reader 9.3.3 and earlier versions for Windows, Macintosh and UNIX update to Adobe Reader 9.3.4. (For Adobe Reader users on Windows and Macintosh, who cannot update to Adobe Reader 9.3.4, Adobe has provided the Adobe Reader 8.2.4 update.) Adobe recommends users of Adobe Acrobat 9.3.3 and earlier versions for Windows and Macintosh update to Adobe Acrobat 9.3.4. Adobe recommends users of Adobe Acrobat 8.2.3 and earlier versions for Windows and Macintosh update to Adobe Acrobat 8.2.4.</p></blockquote><p>Adobe Reader and Acrobat users are asked to update their pdf reader as soon as possible to protect their computer system from exploits that can lead to remote code execution.</p><blockquote><p>Adobe Reader<br
/> Users can utilize the product&#8217;s update mechanism. The default configuration is set to run automatic update checks on a regular schedule and can be manually activated by choosing Help > Check for Updates.</p><p>Adobe Reader users on Windows can also find the appropriate update here:<br
/> http://www.adobe.com/support/downloads/product.jsp?product=10&#038;platform=Windows.</p><p>Adobe Reader users on Macintosh can also find the appropriate update here:<br
/> http://www.adobe.com/support/downloads/product.jsp?product=10&#038;platform=Macintosh.</p><p>Adobe Reader users on UNIX can find the appropriate update here:<br
/> http://www.adobe.com/support/downloads/product.jsp?product=10&#038;platform=Unix.</p><p>Note: Adobe Reader 9.3.4 for Windows, Macintosh and UNIX will be available from the Adobe Reader Download Center at http://get.adobe.com/reader/ by August 31, 2010.</p><p>Adobe Acrobat<br
/> Users can utilize the product&#8217;s update mechanism. The default configuration is set to run automatic update checks on a regular schedule and can be manually activated by choosing Help > Check for Updates.</p><p>Acrobat Standard and Pro users on Windows can also find the appropriate update here:<br
/> http://www.adobe.com/support/downloads/product.jsp?product=1&#038;platform=Windows.</p><p>Acrobat Pro Extended users on Windows can also find the appropriate update here: http://www.adobe.com/support/downloads/product.jsp?product=158&#038;platform=Windows.</p><p>Acrobat 3D users on Windows can also find the appropriate update here:<br
/> http://www.adobe.com/support/downloads/product.jsp?product=112&#038;platform=Windows.</p><p>Acrobat Pro users on Macintosh can also find the appropriate update here:<br
/> http://www.adobe.com/support/downloads/product.jsp?product=1&#038;platform=Macintosh.</p></blockquote><p>More <a
href="http://www.adobe.com/support/security/bulletins/apsb10-17.html">information</a> available at Adobe&#8217;s Security Bulletin.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/08/20/adobe-reader-9-3-4-released-update-now/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Another Adobe Reader Zero-Day Vulnerability Emerges</title><link>http://www.ghacks.net/2010/08/06/another-adobe-reader-zero-day-vulnerability-emerges/</link> <comments>http://www.ghacks.net/2010/08/06/another-adobe-reader-zero-day-vulnerability-emerges/#comments</comments> <pubDate>Fri, 06 Aug 2010 08:08:51 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <category><![CDATA[pdf]]></category> <category><![CDATA[pdf reader]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=32092</guid> <description><![CDATA[What is it with Adobe Reader and vulnerabilities? It feels like new security vulnerabilities are found in the software at an accelerated pace this year. Adobe yesterday released a security advisory for Adobe Reader and Acrobat, to announce to the world that critical security vulnerabilities have been found &#8211; once again &#8211; in Adobe Reader [...]]]></description> <content:encoded><![CDATA[<p>What is it with Adobe Reader and vulnerabilities? It feels like new security vulnerabilities are found in the software at an accelerated pace this year. Adobe yesterday released a security advisory for Adobe Reader and Acrobat, to announce to the world that critical security vulnerabilities have been found &#8211; once again &#8211; in Adobe Reader and Adobe Acrobat.</p><p>Adobe expects to make the updates &#8220;available during the week of August 16, 2010&#8243;, which does mean that millions of computer systems running either Adobe Reader or Adobe Acrobat are left vulnerable for the time being.</p><p><span
id="more-32092"></span><br
/><blockquote>Adobe is planning to release updates for Adobe Reader 9.3.3 for Windows, Macintosh and UNIX, Adobe Acrobat 9.3.3 for Windows and Macintosh, and Adobe Reader 8.2.3 and Acrobat 8.2.3 for Windows and Macintosh to resolve critical security issues, including CVE-2010-2862 which was discussed at the Black Hat USA 2010 security conference on Wednesday, July 28, 2010. Adobe expects to make these updates available during the week of August 16, 2010</p></blockquote><p><a
href="http://www.adobe.com/support/security/bulletins/apsb10-17.html">The</a> security advisory does not reveal information about the vulnerabilities, only that one was discussed at last month&#8217;s Black Hat USA 2010 security conference, that all platforms are affected, and that Adobe Reader 9.3.3 and earlier, and Adobe Acrobat 9.3.3 and earlier are affected.</p><p>The advisory over at <a
href="http://secunia.com/advisories/40766">Secunia</a> reveals additional details about the vulnerability discussed at the Black Hat conference. The Adobe Reader / Acrobat Font Parsing Integer Overflow Vulnerability has been rated as highly critical, the second highest possible rating.</p><blockquote><p>The vulnerability is caused due to an integer overflow error in CoolType.dll when parsing the &#8220;maxCompositePoints&#8221; field value in the &#8220;maxp&#8221; (Maximum Profile) table of a TrueType font. This can be exploited to corrupt memory via a PDF file containing a specially crafted TrueType font.</p></blockquote><p>Successful exploits may allow remote code execution on the targeted system.</p><p>Users with Adobe Reader or Adobe Acrobat installed may want to consider switching to another pdf reader for the time being, to protect their computer system from those vulnerabilities. Alternatives are listed on our <a
href="http://www.ghacks.net/2010/07/02/pdf-reader-rendering-quality-comparison-which-is-the-best/">pdf reader comparison</a> page.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/08/06/another-adobe-reader-zero-day-vulnerability-emerges/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Adobe Offering Insecure Adobe Reader Version For Download, Beware</title><link>http://www.ghacks.net/2010/07/03/adobe-offering-insecure-adobe-reader-version-for-download-beware/</link> <comments>http://www.ghacks.net/2010/07/03/adobe-offering-insecure-adobe-reader-version-for-download-beware/#comments</comments> <pubDate>Sat, 03 Jul 2010 06:26:22 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobearm.exe]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=27877</guid> <description><![CDATA[Adobe just recently released updates to their pdf reader Adobe Reader, raising its version to 9.3.3. The update fixed several security issues of which at least one was actively exploited in the wild. Computer users who visit the Adobe website might notice that Adobe is not offering that version for download, anywhere on the page. [...]]]></description> <content:encoded><![CDATA[<p>Adobe just recently released updates to their pdf reader Adobe Reader, raising its version to 9.3.3. The update <a
href="http://www.ghacks.net/2010/06/29/adobe-reader-9-3-3-released-fixes-critical-security-issues/">fixed</a> several security issues of which at least one was actively exploited in the wild. Computer users who visit the Adobe website might notice that Adobe is not offering that version for download, anywhere on the page.</p><p>Instead they are still offering Adobe Reader 9.3 for download, a version that has been releases in January 2010, and updated three times since then to fix security vulnerabilities of which some are used in attacks.</p><p><span
id="more-27877"></span><div
id="attachment_27879" class="wp-caption alignnone" style="width: 457px"><img
src="http://www.ghacks.net/wp-content/uploads/2010/07/adobe-reader.png" alt="adobe reader" title="adobe reader" width="447" height="196" class="size-full wp-image-27879" /><p
class="wp-caption-text">adobe reader</p></div></p><p>This opens a can of worms and raises a question, how are Adobe Reader downloaders supposed to know that the version offered is not the latest? They apparently do not get that information on the Adobe Reader download page, nor are they informed about the insecure version on startup of the pdf reader.</p><p>Adobe seems to solely rely on the Adobe Reader and Acrobat Manager, <a
href="http://www.ghacks.net/2010/04/09/adobearm-exe-and-reader_sl-exe/">Adobearm</a> which is configured as a startup process to launch with the operating system. This in itself is problematic depending on the computer system. Adobe ARM does not get executed before the next startup, which means that systems that run 24/7 will be insecure for that time, unless the administrator updates the program manually.</p><p>It is also inefficient if the computer user decided to block the program from being started automatically with the operating system. That&#8217;s highly understandable considering that Adobe does not provide local information about the startup item. A quick search on the Internet confirms the confusion as many users thought that the process was for ARM processors only.</p><p>Lastly, users who do not allow automatic updates on their system will also be left with an insecure version of Adobe Reader.</p><h3>How to update Adobe Reader</h3><p>There are two possibilities to update Adobe Reader. The first is to use the Help > Check For Updates option in the program itself. That&#8217;s obviously only an option if the computer is connected to the Internet as it will query Adobe servers to retrieve the latest version.</p><div
id="attachment_27880" class="wp-caption alignnone" style="width: 510px"><img
src="http://www.ghacks.net/wp-content/uploads/2010/07/adobe-reader-update-500x362.png" alt="adobe reader update" title="adobe reader update" width="500" height="362" class="size-medium wp-image-27880" /><p
class="wp-caption-text">adobe reader update</p></div><p>The second option is to download the patches for Adobe Reader directly from the Adobe website.</p><p>Adobe Reader 9.3.1 <a
href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=4640">Windows</a>, <a
href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=4642">Mac</a> (Intel), <a
href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=4641">Mac</a>, <a
href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=4652">Unix</a><br
/> Adobe Reader 9.3.2 <a
href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=4660">Windows</a>, <a
href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=4659">Mac</a> (Intel), <a
href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=4658">Mac</a>, <a
href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=4671">Unix</a><br
/> Adobe Reader 9.3.3 <a
href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=4698">Windows</a>, <a
href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=4701">Mac</a> (Intel), <a
href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=4699">Mac</a>, <a
href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=4747">Unix</a></p><p>Product Update Pages: <a
href="http://www.adobe.com/support/downloads/product.jsp?product=10&#038;platform=Windows">Windows</a>, <a
href="http://www.adobe.com/support/downloads/product.jsp?product=10&#038;platform=Macintosh">Mac</a>, <a
href="http://www.adobe.com/support/downloads/product.jsp?product=10&#038;platform=Unix">Unix</a></p><p>Do you have Adobe Reader installed on your system? If so, which version is it?</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/07/03/adobe-offering-insecure-adobe-reader-version-for-download-beware/feed/</wfw:commentRss> <slash:comments>16</slash:comments> </item> <item><title>PDF Reader Rendering Quality Comparison, Which Is The Best?</title><link>http://www.ghacks.net/2010/07/02/pdf-reader-rendering-quality-comparison-which-is-the-best/</link> <comments>http://www.ghacks.net/2010/07/02/pdf-reader-rendering-quality-comparison-which-is-the-best/#comments</comments> <pubDate>Fri, 02 Jul 2010 18:26:55 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Software]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[foxit reader]]></category> <category><![CDATA[nitro pdf reader]]></category> <category><![CDATA[nuance]]></category> <category><![CDATA[pdf reader]]></category> <category><![CDATA[pdf reader quality]]></category> <category><![CDATA[STDU Viewer]]></category> <category><![CDATA[sumatra]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=27849</guid> <description><![CDATA[A question came up in the comments of the Foxit 4.0 release post here at Ghacks: How is the rendering quality of that pdf reader compared to that of Adobe Reader? I honestly could not tell at that time because I did not work much with pdf readers, and when I had to read a [...]]]></description> <content:encoded><![CDATA[<p>A question came up in the comments of the <a
href="http://www.ghacks.net/2010/06/30/foxit-reader-4-installation-read-carefully/">Foxit 4.0</a> release post here at Ghacks: How is the rendering quality of that pdf reader compared to that of Adobe Reader? I honestly could not tell at that time because I did not work much with pdf readers, and when I had to read a pdf I was not that much concerned about text rendering but the contents.</p><p>Still, it is a valid question. Do pdf readers render pdf documents differently, and if that&#8217;s the case, which one is the best of the pack?</p><p><span
id="more-27849"></span>Some rules had to be established for this test; All pdf readers should display the same page of the same pdf document in 100% and 200% view as well as a sample paragraph in 100%. Screenshot quality had to be the same to make it easier for anyone to spot possible quality differences in the text rendering engine.</p><p>I have also decided to only add free pdf viewers to the list.</p><h3>List of pdf readers:</h3><ul><li><a
href="http://get.adobe.com/uk/reader/otherversions/">Adobe Reader 9.3.3</a></li><li><a
href="http://www.foxitsoftware.com/pdf/reader/">Foxit Reader 4.0</a></li><li><a
href="http://www.nitroreader.com/">Nitro PDF Reader 1.1.1.13</a></li><li><a
href="http://blog.kowalczyk.info/software/sumatrapdf/free-pdf-reader.html">Sumatra PDF 1.1</a></li><li><a
href="http://www.tracker-software.com/product/pdf-xchange-viewer">PDF-XChange Viewer</a></li><li><a
href="http://www.stdutility.com/stduviewer.html">STDU Viewer</a></li><li><a
href="http://www.nuance.com/products/pdf-reader/index.htm">Nuance PDF Reader</a></li><li><a
href="http://projects.gnome.org/evince/">Evince</a></li></ul><h3>Test System:</h3><ul><li>Microsoft Windows 7 Professional 64-bit</li><li>8GB computer memory</li><li>Intel Core i7 860</li><li>HP w2408h widescreen monitor, 1920&#215;1200 resolution</li><li>Ati Radeon 4870, latest Catalyst drivers</li><li>Test Pdf</li></ul><h3>The screenshots:</h3><p>Thumbnails are displayed due to size limitations, click on a thumbnail to view the full sized image.</p><p><strong>Samples</strong></p><div
id="attachment_27851" class="wp-caption alignnone" style="width: 510px"><a
href="http://www.ghacks.net/wp-content/uploads/2010/07/pdf-reader-quality-samples.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2010/07/pdf-reader-quality-samples-500x312.jpg" alt="pdf reader quality samples" title="pdf reader quality samples" width="500" height="312" class="size-medium wp-image-27851" /></a><p
class="wp-caption-text">pdf reader quality samples</p></div><p>The first batch of samples shows that pdf readers display the same text in a different font sizes. Adobe Reader uses the largest font sizes while STDU Viewer the smallest, which offers a barely readable rendering of the text in that size. Quality obviously depends on a few factors that might differ from system to system.</p><p>What&#8217;s your favorite pdf reader? Let us know in the comments.</p><p><strong>The 100% sample screenshot comparison</strong></p><div
id="attachment_27864" class="wp-caption alignnone" style="width: 510px"><a
href="http://www.ghacks.net/wp-content/uploads/2010/07/pdf-reader-quality2.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/07/pdf-reader-quality2-500x341.png" alt="pdf reader quality" title="pdf reader quality" width="500" height="341" class="size-medium wp-image-27864" /></a><p
class="wp-caption-text">pdf reader quality</p></div><p><strong>Now the 200% samples of the eight pdf readers</strong></p><div
id="attachment_27861" class="wp-caption alignnone" style="width: 510px"><a
href="http://www.ghacks.net/wp-content/uploads/2010/07/pdf-reader-quality-200.png"><img
src="http://www.ghacks.net/wp-content/uploads/2010/07/pdf-reader-quality-200-500x193.png" alt="pdf reader quality 200" title="pdf reader quality 200" width="500" height="193" class="size-medium wp-image-27861" /></a><p
class="wp-caption-text">pdf reader quality 200</p></div><p>As you can see, rendering quality differs highly depending on which pdf reader has been used to display the pdf document. Adobe Reader followed by Sumatra provide a very good rendering quality. The pdf rendering quality obviously depends on a few factors that are influenced by computer hardware.</p><p>I would still recommend either Adobe Reader or Sumatra as they seem to provide the best rendering quality of all tested pdf readers. Sumatra especially for users who do not want anything to do with Adobe Reader.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/07/02/pdf-reader-rendering-quality-comparison-which-is-the-best/feed/</wfw:commentRss> <slash:comments>17</slash:comments> </item> <item><title>Adobe Reader 9.3.3 Released, Fixes Critical Security Issues</title><link>http://www.ghacks.net/2010/06/29/adobe-reader-9-3-3-released-fixes-critical-security-issues/</link> <comments>http://www.ghacks.net/2010/06/29/adobe-reader-9-3-3-released-fixes-critical-security-issues/#comments</comments> <pubDate>Tue, 29 Jun 2010 18:54:05 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader update]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <category><![CDATA[pdf]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=27615</guid> <description><![CDATA[Adobe today has released a new version of their pdf readers Adobe Reader and Acrobat raising the versions of said products to 9.3.3 respectively 9.3.3. Affected by the vulnerabilities are Adobe Reader 9.3.2 and earlier for Windows, Macintosh and Unix as well as Adobe Acrobat 9.3.2 and earlier for Windows and Macintosh. The security bulletin [...]]]></description> <content:encoded><![CDATA[<p>Adobe today has released a new version of their pdf readers Adobe Reader and Acrobat raising the versions of said products to 9.3.3 respectively 9.3.3. Affected by the vulnerabilities are Adobe Reader 9.3.2 and earlier for Windows, Macintosh and Unix as well as Adobe Acrobat 9.3.2 and earlier for Windows and Macintosh.</p><p>The security bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb10-15.html">sheds</a> some light on the security issues that have been fixed in the release. A total of 17 different vulnerabilities have been fixed in Adobe Reader 9.3.3. Adobe has categorized the update as critical and recommends that users apply the latest updates immediately to protect their computer systems.</p><p>Exploits of any security vulnerability that has been patched in the update can lead to code execution on the affected system.</p><p><span
id="more-27615"></span>Adobe confirmed that at least one of the security vulnerabilities is actively exploited in the wild.</p><blockquote><p>This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-1297).<br
/> Note: There are reports that this issue is being actively exploited in the wild.</p><p>This update mitigates a social engineering attack that could lead to code execution (CVE-2010-1240).</p><p>This update resolves an invalid pointer vulnerability that could lead to code execution (CVE-2010-1285).</p><p>This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-1295).</p><p>This update resolves an invalid pointer vulnerability that could lead to code execution (CVE-2010-2168).</p><p>This update resolves an invalid pointer vulnerability that could lead to code execution (CVE-2010-2201).</p><p>This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2202).</p><p>This update resolves a UNIX-only memory corruption vulnerability that could lead to code execution (CVE-2010-2203).</p><p>This update resolves a denial of service vulnerability; arbitrary code execution has not been demonstrated, but may be possible (CVE-2010-2204).</p><p>This update resolves an uninitialized memory vulnerability that could lead to code execution (CVE-2010-2205).</p><p>This update resolves an array-indexing error vulnerability that could lead to code execution (CVE-2010-2206).</p><p>This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2207).</p><p>This update resolves a dereference deleted heap object vulnerability that could lead to code execution (CVE-2010-2208).</p><p>This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2209).</p><p>This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2210).</p><p>This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2211).</p><p>This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2212).</p></blockquote><p>Adobe Reader 9.3.3 and Acrobat 9.3.3 are available for <a
href="http://www.adobe.com/support/security/bulletins/apsb10-15.html">download</a> at the Adobe website. Also available are Adobe Reader 8.2.3 and Adobe Acrobat 8.2.3 which both fix the security issues as well.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/06/29/adobe-reader-9-3-3-released-fixes-critical-security-issues/feed/</wfw:commentRss> <slash:comments>9</slash:comments> </item> <item><title>Adobe Updates Security Advisory, Promises Patches Soon</title><link>http://www.ghacks.net/2010/06/08/adobe-updates-security-advisory-promises-patches-soon/</link> <comments>http://www.ghacks.net/2010/06/08/adobe-updates-security-advisory-promises-patches-soon/#comments</comments> <pubDate>Tue, 08 Jun 2010 08:04:07 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe vulnerability]]></category> <category><![CDATA[flash player]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=26314</guid> <description><![CDATA[Critical vulnerabilities that affected Adobe&#8217;s flagship products Adobe Reader, Acrobat and Flash Player were revealed in a security advisory by the Adobe Product Incident Response Team. The vulnerability affects Flash Player 10 and 9 as well as Adobe Reader 9 and Acrobat 9 which covers the majority of the install base. The vulnerabilities received a [...]]]></description> <content:encoded><![CDATA[<p><a
href="http://www.ghacks.net/2010/06/05/critical-adobe-reader-and-flash-vulnerabilities-emerge/">Critical vulnerabilities</a> that affected Adobe&#8217;s flagship products Adobe Reader, Acrobat and Flash Player were revealed in a security advisory by the Adobe Product Incident Response Team. The vulnerability affects Flash Player 10 and 9 as well as Adobe Reader 9 and Acrobat 9 which covers the majority of the install base.</p><p>The vulnerabilities received a severity rating of highly critical, the highest possible rating, by Secunia since they were both actively exploited and would allow remote code execution on affected computer systems.</p><p><span
id="more-26314"></span>Adobe&#8217;s Response Team has <a
href="http://www.adobe.com/support/security/advisories/apsa10-01.html">updated</a> the security vulnerability with the planned schedule for a patch to resolve the issue.</p><p>According to those information a patch for Flash Player 10 will be released on June 10 while Adobe Reader and Acrobat 9 users have to wait until June 29 for the patch.</p><p>The patches will be made available for all supported operating systems with the exception of Flash Player for Solaris.</p><p>The delay until the page becomes available is bad news for Adobe Reader and Acrobat users who have to find ways to protect their systems from the security vulnerability in the meantime.</p><p>Adobe is offering mitigation instructions on their website for Windows, Unix and Macintosh.</p><p>Adobe Reader and Acrobat &#8211; Windows</p><blockquote><p>Deleting, renaming, or removing access to the authplay.dll file that ships with Adobe Reader 9.x and Acrobat 9.x mitigates the threat for those products, but users will experience a non-exploitable crash or error message when opening a PDF file that contains SWF content.</p><p>The authplay.dll that ships with Adobe Reader 9.x and Acrobat 9.x for Windows is typically located at C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll for Adobe Reader or C:\Program Files\Adobe\Acrobat 9.0\Acrobat\authplay.dll for Acrobat.</p></blockquote><p>Adobe Reader 9.x &#8211; Macintosh</p><blockquote><p>1) Go to the Applications->Adobe Reader 9 folder.<br
/> 2) Right Click on Adobe Reader<br
/> 3) Select Show Package Contents<br
/> 4) Go to the Contents->Frameworks folder<br
/> 5) Delete or move the AuthPlayLib.bundle file</p></blockquote><p>Acrobat Pro 9.x &#8211; Macintosh</p><blockquote><p>1) Go to the Applications->Adobe Acrobat 9 Pro folder.<br
/> 2) Right Click on Adobe Acrobat Pro<br
/> 3) Select Show Package Contents<br
/> 4) Go to the Contents->Frameworks folder<br
/> 5) Delete or move the AuthPlayLib.bundle file</p></blockquote><p>Adobe Reader 9.x- UNIX</p><blockquote><p>1) Go to installation location of Reader (typically a folder named Adobe)<br
/> 2) Within it browse to Reader9/Reader/intellinux/lib/ (for Linux) or Reader9/Reader/intelsolaris/lib/ (for Solaris)<br
/> 3) Remove the library named &#8220;libauthplay.so.0.0.0&#8243;</p></blockquote><p>It is recommended to either perform the operations on affected computer systems or switch to another pdf reader at least for the time until the vulnerability gets fixed.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/06/08/adobe-updates-security-advisory-promises-patches-soon/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> </channel> </rss>
