Adobe grappling with another PDF vulnerability

Powered by SC Magazine
 

Adobe again is staring down a zero-day vulnerability in its popular Reader software, according to a new security advisory.

According to the alert this week from Security Focus, Adobe Reader contains a JavaScript flaw that can be exploited to execute arbitrary code or crash the application.

Versions 9.1 and 8.1.4 are vulnerable, though other builds also may be impacted, the advisory said.

David Lenoe, posting on the Adobe Product Security Incident Response Team blog, said that the company was investigating reports and plans to release an update once it has more information.

Earlier this year, Adobe faced the music over another PDF flaw, which was being targeted in active attacks but took the software giant weeks to patch. Some observers criticised the company for the delayed disclosure of the bug and the subsequent slow fix, while others recommended using alternative PDF readers, such as Foxit.

Adobe representatives defended their stance, saying they did not want to reveal too much information to the bad guys. The company advised users to disable JavaScript until it delivered a patch, which was issued in March.

See original article on scmagazineus.com

Copyright © SC Magazine, US edition


Adobe grappling with another PDF vulnerability
 
 
 
Top Stories
First look: Microsoft Outlook for iOS
[Update] Office productivity suite for iOS completed with Outlook.
 
NewSat defaults on $26m in overdue Lockheed payments
Jabiru-1 satellite build hits further hurdles.
 
IBM denies plans to cut 112k jobs
But admits to further restructuring.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  36%
 
Your insurance company
  5%
 
A technology company (Google, Facebook et al)
  9%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  4%
 
A Federal Government agency (ATO, Centrelink etc)
  18%
 
An Australian law enforcement agency (AFP, ASIO et al)
  14%
 
A State Government agency (Health dept, etc)
  7%
TOTAL VOTES: 3085

Vote
Do you support the abolition of the Office of the Information Commissioner?

   |   View results
I support shutting down the OAIC.
  27%
 
I DON'T support shutting the OAIC.
  73%
TOTAL VOTES: 982

Vote