<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; adobe security</title> <atom:link href="http://www.ghacks.net/tag/adobe-security/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Fri, 10 Feb 2012 20:51:26 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Adobe Patch Day Brings Fixes For Flash, Shockwave And Adobe Reader</title><link>http://www.ghacks.net/2011/06/15/adobe-patch-day-brings-fixes-for-flash-shockwave-and-adobe-reader/</link> <comments>http://www.ghacks.net/2011/06/15/adobe-patch-day-brings-fixes-for-flash-shockwave-and-adobe-reader/#comments</comments> <pubDate>Wed, 15 Jun 2011 07:42:39 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[companies]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[patch day]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=46489</guid> <description><![CDATA[Microsoft had a huge patch day yesterday with 16 security bulletins for the Windows operating system, Microsoft Office, Internet Explorer and other Microsoft software. Adobe, the company behind popular technologies such as Flash Player, Shockwave or Adobe Reader released five security bulletins on the same day after teaming up with Microsoft to coordinate security releases.. [...]]]></description> <content:encoded><![CDATA[<p>Microsoft had a huge <a
href="http://www.ghacks.net/2011/06/14/microsoft-patch-day-june-2011-overview/">patch day</a> yesterday with 16 security bulletins for the Windows operating system, Microsoft Office, Internet Explorer and other Microsoft software.</p><p>Adobe, the company behind popular technologies such as Flash Player, Shockwave or Adobe Reader released five security bulletins on the same day after <a
href="http://www.ghacks.net/2010/07/29/adobe-microsoft-to-team-up-on-vulnerability-sharing/">teaming up with Microsoft</a> to coordinate security releases.. Of the five, three may be affecting end users as they address vulnerabilities in Adobe Reader and Acrobat, Shockwave Player and Flash Player. All three have received a maximum severity rating of critical, the highest possible rating.</p><p>The bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb11-16.html">APSB11-16</a> describes a critical vulnerability in Adobe Reader X 10.0.3 and earlier on Windows, and Adobe Reader X 10.0.3 and earlier on Macintosh, as well as earlier versions of Adobe Reader 9 and 8, and Adobe Acrobat 9 and 8. The vulnerability could be exploited by attackers to crash the application to take control of the computer system Adobe Reader X is running on.</p><p>Adobe recommends to update the software product to the latest available version. For Adobe Reader X that would mean to update to version 10.1, for users of Adobe Reader 9.4.4 and earlier to update to version 9.4.5.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/06/adobe-reader-x.png" alt="adobe-reader-x" title="adobe-reader-x" width="600" height="449" class="alignnone size-full wp-image-46493" /></p><p>Adobe Reader and Acrobat users can check for updates in the program interface. This is done via Help > Check for Updates. Updates can also be downloaded from the following locations.</p><ul><li><a
href="http://www.adobe.com/support/downloads/product.jsp?product=10&#038;platform=Windows.">Adobe Reader Windows</a></li><li><a
href="http://www.adobe.com/support/downloads/product.jsp?product=10&#038;platform=Macintosh.">Adobe Reader Macintosh</a></li></ul><p>You can also check out <a
href="http://www.ghacks.net/2010/11/22/adobe-reader-x-offline-installers/">Adobe Reader X Offline Installers</a></p><p>Security Bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb11-17.html">APSB11-17</a> describes vulnerabilities in Adobe Shockwave Player 11.5.9.620 and earlier on the Windows and Macintosh platform. Attackers who successfully exploit the vulnerabilities could run malicious code on the computer system. Adobe recommends to update Shockwave Player to version 11.6.0.626 to protect the system from possible exploits.</p><p>Windows and Mac users who run Shockwave Player on their system can download the latest version <a
href="http://get.adobe.com/shockwave/">at the official</a> download site.</p><p>Bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb11-18.html">APSB11-18</a> finally describes a vulnerability in Adobe Flash Player that affects Adobe Flash Player 10.3.181.23 and earlier on Windows, Macintosh, Linux and Solaris, as well as Flash Player 10.3.185.23 and earlier for Android.</p><p>The vulnerability could be exploited to cause a crash which could allow the attacker to gain control over the affected system. Adobe has confirmed reports that the vulnerability is exploited in the wild in the form of targeted attacks on specifically prepared websites.</p><p>Adobe recommends to update Flash Player to Adobe Flash Player 10.3.181.26 on desktop operating systems. Android users will receive a patch before week&#8217;s end.</p><p>Users can verify their installed version of Flash Player by visiting the <a
href="http://www.adobe.com/products/flash/about/">About Flash Player</a> page at Adobe.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/06/flash-player-version.png" alt="flash player version" title="flash player version" width="600" height="512" class="alignnone size-full wp-image-46490" /></p><p>Adobe lists the latest version for all supported operating systems on the page, so that users only need to compare their installed version with the latest available version to see if they need to update.</p><p>The latest versions can be downloaded from <a
href="http://get.adobe.com/flashplayer/">Adobe&#8217;s Flash Player Download Center</a>.  Users who do not want to use the download manager can check out this guide D<a
href="http://www.ghacks.net/2010/02/27/download-adobe-flash-without-adobe-download-manager/">ownload Adobe Flash Without Adobe Download Manager</a>.</p><p>Google Chrome users can check for updates in Chrome to get the latest version. This is done by clicking on the wrench icon and selecting About Google Chrome.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/06/15/adobe-patch-day-brings-fixes-for-flash-shockwave-and-adobe-reader/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Adobe Security Updates For Flash, Adobe Reader</title><link>http://www.ghacks.net/2011/03/22/adobe-security-updates-for-flash-adobe-reader/</link> <comments>http://www.ghacks.net/2011/03/22/adobe-security-updates-for-flash-adobe-reader/#comments</comments> <pubDate>Tue, 22 Mar 2011 09:33:04 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe flash]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=42914</guid> <description><![CDATA[Adobe has released updates for their popular Adobe Flash Player, Adobe Reader and Adobe Acrobat applications. The updates address a critical security vulnerability that was discoveredearlier this month. The critical vulnerability affects Adobe Flash, and since Adobe implemented Flash technology in Adobe Reader and Acrobat, those products as well. The Flash vulnerability affects all Adobe [...]]]></description> <content:encoded><![CDATA[<p>Adobe has released updates for their popular Adobe Flash Player, Adobe Reader and Adobe Acrobat applications. The updates address a critical security vulnerability that <a
href="http://www.ghacks.net/2011/03/14/new-critical-0-day-flash-vulnerability-exploited-via-excel-attachments/">was discovered</a>earlier this month.</p><p>The critical vulnerability affects Adobe Flash, and since Adobe implemented Flash technology in Adobe Reader and Acrobat, those products as well.</p><p>The Flash vulnerability affects all Adobe Flash Player 10.2.152.33 and earlier versions on all supported operating systems, as well as Flash Player 10.2.154.18 and earlier for Chrome, Flash Player 10.1.106.16 and earlier for Android and Adobe AIR 2.5 and earlier. Google recently pushed an update that resolved the vulnerability for Chrome.</p><p>Attackers can exploit the vulnerability to cause a crash which could allow them to take control over the affected system. We already mentioned in our first report on March 14 that the issue was actively exploited by attackers in the form of embedded Flash files in Microsoft Excel documents that were delivered as email attachments.</p><p>The Flash Player update <a
href="http://www.adobe.com/support/security/bulletins/apsb11-05.html">is available</a> on the official Flash download page over at Adobe. Google Chrome users with automatic updates enabled do not need to download the update as Google has already pushed an update to all Chrome users that updated Flash to the latest version.</p><p>The new Flash version is 10.2.153.1 for all supported desktop PCs, 10.2.156.12 for Android and 10.2.154.25 for Google Chrome.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/03/adobe-flash-player.png" alt="adobe flash player" title="adobe flash player" width="335" height="108" class="alignnone size-full wp-image-42917" /></p><p>Adobe AIR users can download the new version of the application <a
href="http://get.adobe.com/air/">from the</a> official Adobe AIR download center, the new Adobe Air version is 2.6.</p><p>Users <a
href="http://www.adobe.com/software/flash/about/">can verify</a> their version of Adobe Flash by visiting the About Adobe Flash Player page.</p><p>The Security Bulletin that lists additional information is accessible <a
href="http://www.adobe.com/support/security/bulletins/apsb11-05.html">here</a>.</p><p>Adobe has released an update for Adobe Reader and Acrobat as well to address the same critical security vulnerability. Adobe Reader and Acrobat X, 10.x and 9.x are affected on Windows and Macintosh systems.</p><p>Existing Adobe Reader and Adobe Acrobat users can use the built-in updating functionality to update the software to the latest version. They need to open Adobe Reader and select Help > Check for Updates from the menu to initiate that process.</p><p>It needs to be noted that Adobe is not supplying an update for Adobe Reader X at this point in time. The reasoning is that Adobe Reader X is using Protected Mode which &#8220;would prevent an exploit of this kind from executing&#8221;. The update will be addressed on the coming quarterly security update which is scheduled for June 14.</p><p>The security bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb11-06.html">lists</a> additional information about the vulnerability, and download links that point to the latest program versions of affected applications.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/03/22/adobe-security-updates-for-flash-adobe-reader/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Adobe Security Bulletin Summary Feburary 2011</title><link>http://www.ghacks.net/2011/02/09/adobe-security-bulletin-summary-feburary-2011/</link> <comments>http://www.ghacks.net/2011/02/09/adobe-security-bulletin-summary-feburary-2011/#comments</comments> <pubDate>Wed, 09 Feb 2011 08:23:40 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe flash player]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=39719</guid> <description><![CDATA[Adobe Software yesterday released updates for some of its popular software applications, including updates for Adobe Reader, Acrobat and the Adobe Flash Player. The updates address critical security issues in the products making them mandatory updates for all users of said products. The security update for Adobe Flash Player fixes several critical vulnerability in Flash [...]]]></description> <content:encoded><![CDATA[<p>Adobe Software yesterday released updates for some of its popular software applications, including updates for Adobe Reader, Acrobat and the Adobe Flash Player. The updates address critical security issues in the products making them mandatory updates for all users of said products.</p><p>The security update for Adobe Flash Player fixes several critical vulnerability in Flash Player 10.1.102.64 and earlier on Windows, Macintosh, Linux and Solaris. Successful exploits could &#8220;cause the application to crash and could potentially allow an attacker to take control of the affected system&#8221;.</p><p>The update increases the version of the application to Adobe Flash Player 10.2.152.26 on all affected systems.</p><p>The update can be downloaded <a
href="http://get.adobe.com/flashplayer/">directly</a> from Adobe.</p><p>More information about the update are <a
href="http://www.adobe.com/support/security/bulletins/apsb11-02.html">available</a> on Adobe&#8217;s Security Bulletin page.</p><h3>Adobe Reader, Acrobat</h3><p>Critical vulnerabilities have also been identified in Adobe Reader and Acrobat. Affected versions include Adobe Reader X, Adobe Reader 9.4.1 for Windows, Macintosh and Unix, and Adobe Acrobat X and earlier for Windows and Macintosh. Please note that the update incorporates the Adobe Flash Player update.</p><p>The vulnerabilities &#8220;could cause the application to crash and potentially allow an attacker to take control of the affected system. Risk for Adobe Reader X users is significantly lower, as none of these issues bypass Protected Mode mitigations&#8221;.</p><p>Updates are available to increase the version of Adobe Reader X to 10.0.1, Adobe Reader 9.4.1 to 9.4.2 and Adobe Acrobat X to 10.0.1.</p><p>Download links for all affected applications are <a
href="http://www.adobe.com/support/security/bulletins/apsb11-03.html">posted</a> on the security bulletin page over at Adobe.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/02/09/adobe-security-bulletin-summary-feburary-2011/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Microsoft, Adobe Post February 2011 Patch Day Information</title><link>http://www.ghacks.net/2011/02/05/microsoft-adobe-post-february-2011-patch-day-information/</link> <comments>http://www.ghacks.net/2011/02/05/microsoft-adobe-post-february-2011-patch-day-information/#comments</comments> <pubDate>Sat, 05 Feb 2011 09:46:32 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Microsoft]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[patch tuesday]]></category> <category><![CDATA[windows patches]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=39608</guid> <description><![CDATA[Patch Tuesday is coming up and Microsoft has released an advanced notification about the upcoming security patches. Patch Tuesday refers to the second Tuesday of each month on which security patches are released to the public. The Microsoft Security Bulletin Advance Notification for February 2011 details the upcoming patches. A total of 12 security bulletins [...]]]></description> <content:encoded><![CDATA[<p>Patch Tuesday is coming up and Microsoft has released an advanced notification about the upcoming security patches. Patch Tuesday refers to the second Tuesday of each month on which security patches are released to the public.</p><p>The Microsoft Security Bulletin Advance Notification for February 2011 details the upcoming patches. A total of 12 security bulletins are released next Tuesday of which all but one fix issues in the Microsoft Windows operating system. The remaining patch fixes a vulnerability in Microsoft Office.</p><p>Three of the security vulnerabilities have received a maximum severity rating of critical, the highest available rating, the remaining nine a severity rating of important.</p><ul><li>Microsoft&#8217;s newest operating system Windows 7 is affected by seven of the twelve issues. Of those, two are rated critical and the remaining five as important.</li><li>Windows Vista is affected by six vulnerabilities with three rated as critical and the remaining three as important.</li><li>Windows XP is affected by eight vulnerabilities with two being rated as critical and six as important.</li><li>Windows Server 2003 is affected by 10 vulnerabilities of which one is critical, eight are important and one is moderate.</li><li>Windows Server 2008 is affected in the same way as the Vista operating system, with the exception that one of the critical vulnerabilities is only rated as moderate here.</li><li>Windows Server 2008 R2 finally is affected the same way as Windows 7, again with the exception of two vulnerabilities that are rated as moderate instead of critical and important.</li></ul><p>The remaining vulnerabiliy affected Microsoft Visio 2002 Service Pack 2, Visio 2003 Service Pack 3 and Visio 2007 Service Pack 2. It is rated as important.</p><p>The advanced notifications are accessible <a
href="http://www.microsoft.com/technet/security/bulletin/ms11-feb.mspx">here</a>.</p><h3>Adobe</h3><p>Adobe has <a
href="http://www.adobe.com/support/security/bulletins/apsb11-03.html">released</a> a Prenotification Security Advisory for Adobe Reader and Acrobat.</p><blockquote><p>Adobe is planning to release updates for Adobe Reader X (10.0) for Windows and Macintosh, Adobe Reader 9.4.1 and earlier versions for Windows, Macintosh and UNIX, Adobe Acrobat X (10.0) for Windows and Macintosh, and Adobe Acrobat 9.4.1 and earlier versions for Windows and Macintosh to resolve critical security issues. Adobe expects to make updates for Windows and Macintosh available on Tuesday, February 8, 2011. An update for UNIX is expected to be available by the week of February 28, 2011.</p></blockquote><p>Expect lots of patching next Tuesday. We will post detailed information once the patches are released by Microsoft and Adobe.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/02/05/microsoft-adobe-post-february-2011-patch-day-information/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Adobe Patches, And Reports New Vulnerabilities</title><link>http://www.ghacks.net/2010/11/05/adobe-patches-and-reports-new-vulnerabilities/</link> <comments>http://www.ghacks.net/2010/11/05/adobe-patches-and-reports-new-vulnerabilities/#comments</comments> <pubDate>Fri, 05 Nov 2010 11:31:41 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[flash player]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=36568</guid> <description><![CDATA[Adobe&#8217;s Flash Player was updated yesterday fixing several security vulnerabilities in the process. The patch was initially slated for a November 9 release but released in advance yesterday. But Adobe Flash was not the only vulnerable Adobe product. Adobe has scheduled an update for their popular pdf readers Adobe Reader and Adobe Acrobat on November [...]]]></description> <content:encoded><![CDATA[<p>Adobe&#8217;s Flash Player was updated yesterday fixing several security vulnerabilities in the process. The patch was initially slated for a November 9 release but released in advance yesterday. But Adobe Flash was not the only vulnerable Adobe product. Adobe has scheduled an update for their popular pdf readers Adobe Reader and Adobe Acrobat on November 15 to fix an actively exploited vulnerability.</p><p>To make matters worse, a new vulnerability has been confirmed by Adobe affecting Adobe Reader 9.2 or later and Adobe Reader 8.1.7 or later. A &#8220;proof-of-concept file demonstrating a Denial of Service was published&#8221; already that crashes the pdf reader.  The exploit does not demonstrate arbitrary code execution, but Adobe is not eliminating the possibility at this point in time. It has to be noted that Adobe Acrobat is not affected by the security vulnerability.</p><p>The blog post <a
href="http://blogs.adobe.com/psirt/2010/11/potential-issue-in-adobe-reader.html">of the</a> Security and Response team offers instructions on how to protect the computer system from this vulnerability.</p><blockquote><p>Adobe Reader 9.2 and later and Adobe Reader 8.1.7 and later – Windows</p><p>On Windows, the JavaScript Blacklist can be in two locations. Please review the following options and then create the registry key of your choice:</p><p>Enterprise list: This blacklist helps enterprises roll out policies that block exploitable API(s) from executing in their environment. Populating the blacklist in this location is the responsibility of the enterprise. Adobe patches never modify this registry location.<br
/> To create the registry key:<br
/> HKLM\SOFTWARE\Policies\Adobe\&lt;product&gt;\&lt;version&gt;\FeatureLockDown\cJavaScriptPerms\tBlackList</p><p>Adobe’s update/patch list: The Adobe blacklist is modified by Adobe Reader patches whenever an API is deemed vulnerable. APIs are also removed from the blacklist whenever a fix for a vulnerability is provided by the current patch.<br
/> To create the registry key:<br
/> HKLM\SOFTWARE\Adobe\&lt;product&gt;\&lt;version&gt;\JavaScriptPerms\tBlackList</p><p> On a 64 bit Windows system, the path is:<br
/> HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Adobe</p><p>->To prevent this particular issue, add the following value to the registry key created in the previous step (case sensitive):<br
/> Doc.printSeps</p><p>->Exit and restart the application</p><p>Adobe Reader 9.2 and later and Adobe Reader 8.1.7 and later – Macintosh</p><p> On your Macintosh computer, go to the Applications folder or to the location where you have Adobe Reader installed.<br
/> Right-click on Adobe Reader<br
/> Click on Show Package Contents<br
/> Expand Contents<br
/> Expand MacOS<br
/> Expand Preferences<br
/> Create a backup of the FeatureLockDown file.<br
/> Right-click on FeatureLockDown.<br
/> Open With TextEdit.<br
/> Just before the last >> add the following line to the FeatureLockDown file (case sensitive):<br
/> /JavaScriptPerms [ /c &lt;&lt; /BlackList [ /t (Doc.printSeps) ] &gt;&gt; ]<br
/> Save the file<br
/> Restart Adobe Reader</p><p>Adobe Reader 9.2 and later – UNIX</p><p> Go to the Global Prefs file at:<br
/> /Reader/GlobalPrefs/reader_prefs<br
/> Add the following line to the file:<br
/> /JavaScriptPerms [/c << /BlackList [/t (Doc.printSeps) ] >> ]</p></blockquote><p>There you have it. Make sure you protect your version of Adobe Reader from the vulnerability by following the instructions posted above. The posting does not offer any information on the consequences of protecting the pdf reader from the vulnerability. It is also not clear if Adobe will be able to include the patch for this vulnerability in the upcoming update.</p><p>As if that was not enough, there is <a
href="http://secunia.com/advisories/42112/">also a new</a> vulnerability in Adobe Shockwave Player.</p><blockquote><p>Krystian Kloskowski has discovered a vulnerability in Shockwave Player, which can be exploited by malicious people to compromise a user&#8217;s system.</p><p>The vulnerability is caused due to a use-after-free error in an automatically installed compatibility component as a function in an unloaded library may be called.</p><p>Successful exploitation allows execution of arbitrary code, but requires that a user is tricked into opening the &#8220;Shockwave Settings&#8221; window when viewing a web page.</p><p>The vulnerability is confirmed in version 11.5.9.615. Other versions may also be affected.</p></blockquote><p>The description makes it clear that systems are only vulnerable to this attack if the user opens the Shockwave Settings window on a specially prepared website.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/11/05/adobe-patches-and-reports-new-vulnerabilities/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Adobe Reader 9.4 Download Available</title><link>http://www.ghacks.net/2010/10/06/adobe-reader-9-4-download-available/</link> <comments>http://www.ghacks.net/2010/10/06/adobe-reader-9-4-download-available/#comments</comments> <pubDate>Wed, 06 Oct 2010 08:25:29 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader update]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[pdf reader]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=35618</guid> <description><![CDATA[Adobe has just released an update for their popular pdf reader Adobe Reader and Adobe Acrobat, raising versions of the two programs to 9.4. Both program updates fix critical security vulnerabilities identified in Adobe Reader 9.3.4 and earlier, as well as Acrobat 9.3.4 and earlier. Vulnerabilities affect all supported operating systems, and users are encouraged [...]]]></description> <content:encoded><![CDATA[<p>Adobe has just released an update for their popular pdf reader Adobe Reader and Adobe Acrobat, raising versions of the two programs to 9.4. Both program updates fix critical security vulnerabilities identified in Adobe Reader 9.3.4 and earlier, as well as Acrobat 9.3.4 and earlier. Vulnerabilities affect all supported operating systems, and users are encouraged to upgrade their version as soon as possible to protect their computer system from exploits.</p><p>The rushed state of the release indicates that the issue gets actively exploited which is confirmed in Adobe&#8217;s Security Bulletin that mentions that the issue is being actively exploited in the wild. Attackers may be able to crash the application on the computer and take control of the affected system in the process. Upgrading is the only way of protecting the computer from those vulnerabilities.</p><blockquote><p>Adobe recommends users of Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX update to Adobe Reader 9.4. (For Adobe Reader users on Windows and Macintosh,<br
/> who cannot update to Adobe Reader 9.4, Adobe has provided the Adobe Reader 8.2.5 update.) Adobe recommends users of Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh update to Adobe Acrobat 9.4. Adobe recommends users of Adobe Acrobat 8.2.4 and earlier versions for Windows and Macintosh update to Adobe Acrobat 8.2.5.</p></blockquote><p>This accelerated patch breaks Adobe&#8217;s quarterly patch day that is set for every second Tuesday of each quarter of the year to fall in line with Microsoft&#8217;s Patch Tuesday. Interested users can take a closer look at the <a
href="http://www.adobe.com/support/security/bulletins/apsb10-21.html">Security Bulletin</a>, or point their web browsers to <a
href="http://get.adobe.com/reader/">Get Adobe Reader</a> right away to download the latest version of the pdf reader. Updates are also available directly in the program (by clicking on Help > Check for Updates).</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/10/06/adobe-reader-9-4-download-available/feed/</wfw:commentRss> <slash:comments>7</slash:comments> </item> <item><title>Adobe Reader 9.3.2 Security Update Released</title><link>http://www.ghacks.net/2010/04/13/adobe-reader-9-3-2-security-update-released/</link> <comments>http://www.ghacks.net/2010/04/13/adobe-reader-9-3-2-security-update-released/#comments</comments> <pubDate>Tue, 13 Apr 2010 19:06:06 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader update]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[pdf reader]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=24522</guid> <description><![CDATA[Adobe, just like Microsoft, releases security updates on a schedule unless a vulnerability is actively exploited on a large scale and requires immediate attention. Updates for their pdf readers Adobe Reader and Acrobat have been released today that fix several security vulnerabilities. The critical vulnerabilities are affecting all operating systems that Adobe Reader is compatible [...]]]></description> <content:encoded><![CDATA[<p>Adobe, just like <a
href="http://www.ghacks.net/2010/04/13/microsoft-security-updates-april-2010/">Microsoft</a>, releases security updates on a schedule unless a vulnerability is actively exploited on a large scale and requires immediate attention. Updates for their pdf readers Adobe Reader and Acrobat have been released today that fix several security vulnerabilities.</p><p>The critical vulnerabilities are affecting all operating systems that Adobe Reader is compatible with (Microsoft Windows, Apple Macintosh and Unix based) and versions of Adobe Reader 9.3.1 and Adobe Acrobat 9.3.1 or earlier.</p><p>The critical nature of the vulnerabilities requires immediate attention from users who have affected software versions installed on their computer systems.</p><p><span
id="more-24522"></span>Adobe is offering the update through various channels. It is possible to check for updates from within the pdf readers by clicking on Help > Check for updates or to download the updates from the official Adobe website.</p><blockquote><p>Adobe Reader users on Windows can also find the appropriate update here:<br
/> http://www.adobe.com/support/downloads/product.jsp?product=10&#038;platform=Windows.</p><p>Adobe Reader users on Macintosh can also find the appropriate update here:<br
/> http://www.adobe.com/support/downloads/product.jsp?product=10&#038;platform=Macintosh.</p><p>Adobe Reader users on UNIX can find the appropriate update here:<br
/> ftp://ftp.adobe.com/pub/adobe/reader/unix/9.x/9.3.2/.</p></blockquote><p>The update is still separated from the full version of Adobe Reader that is offered on the Adobe homepage. There is still no full version of Adobe Reader 9.3.2 available on the Adobe homepage which still offers Adobe Reader 9.3.0 to visitors.</p><p>Users who want to find out more about the security vulnerabilities can <a
href="http://www.adobe.com/support/security/bulletins/apsb10-09.html">check out</a> the security bulletin that contains detailed information about the vulnerabilities that are closed with the new release.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/04/13/adobe-reader-9-3-2-security-update-released/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Adobe Fixes Adobe Download Manager Vulnerability</title><link>http://www.ghacks.net/2010/02/24/adobe-fixes-adobe-download-manager-vulnerability/</link> <comments>http://www.ghacks.net/2010/02/24/adobe-fixes-adobe-download-manager-vulnerability/#comments</comments> <pubDate>Wed, 24 Feb 2010 13:10:39 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe download manager]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[security vulnerability]]></category> <category><![CDATA[windows security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=23314</guid> <description><![CDATA[A security vulnerability in Adobe Download Manager was discovered this month besides the recently discovered security vulnerabilities in Adobe Reader, Adobe Acrobat and Adobe Flash which had also been discovered and fixed by Adobe. We have posted information about the security vulnerability in the forum but not here on the blog. Adobe has now updated [...]]]></description> <content:encoded><![CDATA[<p>A security vulnerability in Adobe Download Manager was discovered this month besides the recently discovered security vulnerabilities in Adobe Reader, Adobe Acrobat and Adobe Flash which had also been discovered and fixed by Adobe.</p><p>We have posted <a
href="http://www.ghacks.net/forum/security/adobe-download-manager-security-issue-256/">information</a> about the security vulnerability in the forum but not here on the blog. Adobe has now updated information about the security vulnerability which basically fixed the issue so that users who download and use the Adobe Download Manager from February 23 on do not download the vulnerable software.</p><p>Adobe has also posted instructions to verify that the vulnerable version of the Adobe Download Manager does not reside on the computer system if it has been downloaded prior to February 23.</p><p><span
id="more-23314"></span><br
/><blockquote>Ensure that the C:\Program Files\NOS\ folder and its contents (&#8220;NOS files&#8221;) are not present on your system. (If the folder is present, follow the steps below to remove).<br
/> Click &#8220;Start&#8221; > &#8220;Run&#8221; and type &#8220;services.msc&#8221;. Ensure that &#8220;getPlus(R) Helper&#8221; is not present in the list of services.<br
/> If the NOS files are found, the Adobe Download Manager issue can be mitigated by:</p><p>Navigating to Start > Control Panel > Add or Remove Programs > Adobe Download Manager, and selecting Remove to remove the Adobe Download Manager from your system.</p><p><strong>OR</strong></p><p>Clicking &#8220;Start&#8221; > &#8220;Run&#8221; and typing &#8220;services.msc&#8221;. Then deleting &#8220;getPlus(R) Helper&#8221; from the list of services.<br
/> Then delete the C:\Program Files\NOS\ folder and its contents.</p></blockquote><p>Probably the easiest way to handle the issue is to uninstall the Adobe Download Manager if it is listed in the list of installed programs. If it is it can be uninstalled easily which will remove the issue. The issue only affects Windows versions of the Adobe Download Manager.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/02/24/adobe-fixes-adobe-download-manager-vulnerability/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Microsoft and Adobe January 2010 Patch Day</title><link>http://www.ghacks.net/2010/01/13/microsoft-and-adobe-january-2010-patch-day/</link> <comments>http://www.ghacks.net/2010/01/13/microsoft-and-adobe-january-2010-patch-day/#comments</comments> <pubDate>Wed, 13 Jan 2010 16:43:46 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Microsoft]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[adobe update]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[microsoft update]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=22289</guid> <description><![CDATA[Microsoft and Adobe have released their regular security updates today. Microsoft has only released one patch for most of its operating system. The patch fixes a vulnerability in the embedded OpenType font engine that could allow remote code execution. The rating of this vulnerability is low for all operating systems but Microsoft Windows 2000 Service [...]]]></description> <content:encoded><![CDATA[<p>Microsoft and Adobe have released their regular security updates today. Microsoft has only released one patch for most of its operating system. The patch fixes a vulnerability in the embedded OpenType font engine that could allow remote code execution. The rating of this vulnerability is low for all operating systems but Microsoft Windows 2000 Service Pack 4.</p><ul><li>Microsoft Security Bulletin <a
href="http://www.microsoft.com/technet/security/Bulletin/MS10-001.mspx">MS10-001</a> &#8211; Critical  Vulnerability in the Embedded OpenType Font Engine Could Allow Remote Code Execution (972270) &#8211; This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user viewed content rendered in a specially crafted Embedded OpenType (EOT) font in client applications that can render EOT fonts, such as Microsoft Internet Explorer, Microsoft Office PowerPoint, or Microsoft Office Word. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs, view, change, or delete data, or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.<p>This security update is rated Critical for Microsoft Windows 2000, and is rated Low for Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2.</li></ul><p><span
id="more-22289"></span>Adobe <a
href="http://www.adobe.com/support/security/bulletins/apsb10-02.html">has</a> released security updates for Adobe Reader and Adobe Acrobat which patch critical vulnerability in Adobe Reader 9.2 and Adobe Acrobat 9.2 for Windows, Macintosh and Unix as well as Adobe Reader 8.1.7 and Acrobat 8.1.7 for Windows and Macintosh.</p><ul><li>These vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system. Adobe recommends users of Adobe Reader 9.2 and Acrobat 9.2 and earlier versions for Windows, Macintosh and UNIX update to Adobe Reader 9.3 and Acrobat 9.3. Adobe recommends users of Acrobat 8.1.7 and earlier versions for Windows and Macintosh update to Acrobat 8.2. For Adobe Reader users on Windows and Macintosh who cannot update to Adobe Reader 9.3, Adobe has provided the Adobe Reader 8.2 update. Updates apply to all platforms: Windows, Macintosh and UNIX.</li></ul> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/01/13/microsoft-and-adobe-january-2010-patch-day/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Another Adobe Reader Zero Day Vulnerability In The Wild</title><link>http://www.ghacks.net/2009/12/15/another-adobe-reader-zero-day-vulnerability-in-the-wild/</link> <comments>http://www.ghacks.net/2009/12/15/another-adobe-reader-zero-day-vulnerability-in-the-wild/#comments</comments> <pubDate>Tue, 15 Dec 2009 17:02:23 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[adobe vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=21459</guid> <description><![CDATA[Adobe Reader and Adobe Acrobat have been hit with yet another zero day vulnerability that is affecting all versions of both programs up to Adobe Reader and Adobe Acrobat 9.2. The vulnerability has been disclosed to the public by Adobe&#8217;s Security Response team who wrote in their blog that they &#8220;are currently investigating this issue [...]]]></description> <content:encoded><![CDATA[<p>Adobe Reader and Adobe Acrobat have been hit with yet another zero day vulnerability that is affecting all versions of both programs up to Adobe Reader and Adobe Acrobat 9.2. The vulnerability has been disclosed to the public by Adobe&#8217;s Security Response team <a
href="http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html">who</a> wrote in their blog that they &#8220;are currently investigating this issue and assessing the risk to [their] customers&#8221;.</p><p>Adobe itself did not reveal details about the exploit in the blog post but a post at the Shadowserver website which is run by security volunteers from around the world. According to information posted on <a
href="http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214">their</a> website the exploit has been in the wild since at least December 11. The number of attacks have been limited and targeted so far according to their information. They do expect the &#8220;exploit to become more wide spread in the next few weeks&#8221; with the potential to become fully public in the same timeframe.</p><p><span
id="more-21459"></span>The security researchers did not want to reveal all the information about the vulnerability but mentioned that it was found in the JavaScript function in Adobe Acrobat and Adobe Reader.</p><blockquote><p>With that said we can tell you that this vulnerability is actually in a JavaScript function within Adobe Acrobat [Reader] itself. Furthermore the vulnerable JavaScript is obfuscated inside a zlib stream making universal detection and intrusion detection signatures much more difficult. On the bright side though, there are some solutions to this problem.</p></blockquote><p>A temporary fix was also published on the same website.</p><blockquote><p>We have said it before and we will say it again: Disable JavaScript.</p><p>Disabling JavaScript is easy. This is how it can be done in Acrobat Reader:<br
/> Click: Edit -> Preferences -> JavaScript and uncheck Enable Acrobat JavaScript</p><p>We have not had time to fully test but enabling hardware DEP for systems that support it may also mitigate this issue.</p></blockquote><p>Adobe users are encouraged to disable JavaScript as soon as possible to block their version of the program from being vulnerable.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/12/15/another-adobe-reader-zero-day-vulnerability-in-the-wild/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Adobe Reader and Acrobat Security Updates</title><link>http://www.ghacks.net/2009/06/11/adobe-reader-and-acrobat-security-updates/</link> <comments>http://www.ghacks.net/2009/06/11/adobe-reader-and-acrobat-security-updates/#comments</comments> <pubDate>Thu, 11 Jun 2009 12:48:30 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[acrobat]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <category><![CDATA[adobe security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=13448</guid> <description><![CDATA[Adobe has released a set of security updates for their Adobe Reader and Adobe Acrobat software products that fix a variety of security vulnerabilities that could be used to crash the Adobe application and allow the attacker to take control of the computer system. The security vulnerabilities have been rated as critical and Adobe users [...]]]></description> <content:encoded><![CDATA[<p><img
src="http://www.ghacks.net/wp-content/uploads/2009/05/adobe.jpg" alt="adobe" title="adobe" width="100" height="100" class="alignleft size-full wp-image-13093" />Adobe has released a set of security updates for their Adobe Reader and Adobe Acrobat software products that fix a variety of security vulnerabilities that could be used to crash the Adobe application and allow the attacker to take control of the computer system. The security vulnerabilities have been rated as critical and Adobe users are encouraged to update their versions of Adobe Reader and Adobe Acrobat as soon as possible.</p><p>The security updates are provided for Adobe Reader and Adobe Acrobat software products running on both Microsoft Windows and Apple Macintosh operating systems. The security bulletin that was issued yesterday contains <a
href="http://www.adobe.com/support/security/bulletins/apsb09-07.html">links</a> that point to downloads for all affected programs and operating systems.</p><p><span
id="more-13448"></span>The affected programs are:</p><ul><li>Adobe Reader 9.1.1 and earlier versions</li><li>Adobe Acrobat Standard, Pro, and Pro Extended 9.1.1 and earlier versions</li></ul><blockquote><p>Adobe recommends users of Adobe Reader and Acrobat update their product installations to versions 9.1.2, 8.1.6, or 7.1.3 using the instructions above to protect themselves from potential vulnerabilities.  The above updates apply to Windows and Macintosh. Security updates for Adobe Reader on the UNIX platform will be available on June 16, 2009; this Bulletin will be updated to reflect their availability on that date.</p></blockquote><p>Security conscious users might want to consider switching from Adobe Reader to a third party application like <a
href="http://www.ghacks.net/2008/04/26/foxit-reader-23/">Foxit Reader</a>, <a
href="http://www.ghacks.net/2008/03/01/goodbye-adobe-reader-hello-sumatra/">Sumatra PDF</a> or <a
href="http://www.tracker-software.com/product/pdf-xchange-viewer">PDF-Xchange Viewer</a>.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/06/11/adobe-reader-and-acrobat-security-updates/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Adobe Reader and Acrobat Critical Security Update</title><link>http://www.ghacks.net/2008/06/25/adobe-reader-and-acrobat-critical-security-update/</link> <comments>http://www.ghacks.net/2008/06/25/adobe-reader-and-acrobat-critical-security-update/#comments</comments> <pubDate>Wed, 25 Jun 2008 13:48:51 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[adobe vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=5107</guid> <description><![CDATA[Adobe has released a security update for its products Adobe Reader and Adobe Acrobat for both Microsoft Windows and Apple Macintosh that closes one critical security vulnerability. Affected versions are Adobe Reader 8.0 through 8.1.2, Adobe Reader 7.0.9 and earlier, Adobe Acrobat Professional, 3D and Standard 8.0 through 8.1.2 and Adobe Acrobat Professional, 3D and [...]]]></description> <content:encoded><![CDATA[<p>Adobe has released a security update for its products Adobe Reader and Adobe Acrobat for both Microsoft Windows and Apple Macintosh that closes one critical security vulnerability. Affected versions are Adobe Reader 8.0 through 8.1.2, Adobe Reader 7.0.9 and earlier, Adobe Acrobat Professional, 3D and Standard 8.0 through 8.1.2 and Adobe Acrobat Professional, 3D and Standard 7.0.9 and earlier.</p><p>Adobe Reader 9 and Acrobat 9 as well as Adobe Reader 7.1.0 and Acrobat 7.1.0 are not affected by the security vulnerability. The vulnerability causes the applications to crash which can allow an attacker to take control of the host system.</p><p>Downloads are available that fix the security vulnerability in Adobe Reader 8 for <a
href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3967">Windows</a> and <a
href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3966">Macintosh</a> computers. Take a look at the security bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb08-15.html">issued</a> by Adobe if you are using Adobe Acrobat or a previous version of one of the products to find the links pointing to updates for your product.</p><p><span
id="more-5107"></span></p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/06/25/adobe-reader-and-acrobat-critical-security-update/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> </channel> </rss>
