New Reader, Acrobat from Adobe fixed for 23 flaws

By
Follow google news

Adobe closes a whopping 23 vulnerabilities in new release.

Adobe on Tuesday released updated versions of its flagship Reader and Acrobat products to close a whopping 23 vulnerabilities, including two publicly known issues.

New Reader, Acrobat from Adobe fixed for 23 flaws

The "critical" holes are plugged in Reader 9.4 for Windows, Macintosh and UNIX and Acrobat 9.4 for Windows and Mac. Users of Reader/Acrobat 8.2.4 are advised to upgrade to 8.2.5.

All but four of the flaws could lead to malicious code execution, according to an Adobe security bulletin.

The updates were due to be released Oct. 12, but moved up a week due to active exploits targeting a zero-day vulnerability confirmed by Adobe last month. That unpatched flaw, which garnered vulnerability tracking firm Secunia's most severe rating of "extremely critical," could be targeted to crash a user's machine or take complete control of it, according to a previous advisory from Adobe.

Five days after that disclosure, Adobe revealed another unpatched bug affecting Reader and Acrobat. However, unlike the other zero-day, Adobe said it is not aware of any in-the-wild attacks targeting the vulnerability.

Both Reader and Acrobat contain mechanisms to update to the latest versions, Adobe said. As an alternative, users can follow the instructions contained in Tuesday's bulletin.

The next quarterly updates for Adobe Reader and Acrobat are due Feb. 8, 2011.

See original article on scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Commercial spyware targeted Samsung Galaxy users for months

Commercial spyware targeted Samsung Galaxy users for months

Australia's AUKUS base to connect to subsea cables

Australia's AUKUS base to connect to subsea cables

Westpac factors post-quantum cryptography prep into "secure router" rollout

Westpac factors post-quantum cryptography prep into "secure router" rollout

Researcher trawls cybercrime sites, collects billions of stolen credentials

Researcher trawls cybercrime sites, collects billions of stolen credentials

Log In

  |  Forgot your password?