Adobe patches critical flaws

Powered by SC Magazine
 

No immediate risk to some users.

Adobe has released an emergency patch to address critical vulnerabilities in its Acrobat and Reader products.

A vulnerability was identified in Adobe Reader 9.4.6 on Windows.

The patch addresses vulnerabilities in Adobe Reader and Acrobat 9.x for Windows, and it recommended users of Adobe Reader 9.4.6 and earlier 9.x versions for Windows to update to Adobe Reader 9.4.7, and users of Adobe Acrobat 9.4.6 and earlier 9.x versions for Windows update to Adobe Acrobat 9.4.7.

Adobe said there was no immediate risk to users of Adobe Reader and Acrobat X for Windows with Protected Mode or Protected View enabled, or for Adobe Reader and Acrobat X or earlier versions for Macintosh, and Adobe Reader 9.x for UNIX based on the current exploits and historical attack patterns.

However, Adobe planned to address these issues in Adobe Reader X and Acrobat X for Windows with the next quarterly security update for Adobe Reader and Acrobat, currently scheduled for 10 January 2012.

An update to address these issues in Adobe Reader 9.x for UNIX is planned for the same date.

"The flaw is actively being used in targeted attacks and can be used to take full control of the targeted machine," Wolfgang Kandek, CTO of Qualys said.

“Adobe Reader X contains the same flaw, but the current attack is neutralised due its additional sandbox. While this does not mean that Adobe Reader X users are completely safe, it is a remarkable illustration of the effectiveness of the additional security features that newer products have been enhanced with.”

Lumension security and forensic analyst Paul Henry said Adobe released 121 bulletins this year.

This article originally appeared at scmagazineuk.com

Copyright © SC Magazine, UK edition


Adobe patches critical flaws
Tags
 
 
 
Top Stories
First look: Microsoft Outlook for iOS
[Update] Office productivity suite for iOS completed with Outlook.
 
NewSat defaults on $26m in overdue Lockheed payments
Jabiru-1 satellite build hits further hurdles.
 
IBM denies plans to cut 112k jobs
But admits to further restructuring.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  36%
 
Your insurance company
  5%
 
A technology company (Google, Facebook et al)
  9%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  4%
 
A Federal Government agency (ATO, Centrelink etc)
  18%
 
An Australian law enforcement agency (AFP, ASIO et al)
  14%
 
A State Government agency (Health dept, etc)
  7%
TOTAL VOTES: 3120

Vote
Do you support the abolition of the Office of the Information Commissioner?

   |   View results
I support shutting down the OAIC.
  27%
 
I DON'T support shutting the OAIC.
  73%
TOTAL VOTES: 1001

Vote