Advertisement
Promo

Security threats Toolkit

Adobe promises fixes for Reader and Acrobat

David Meyer ZDNet.co.uk

Published: 05 May 2009 17:31 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Adobe has said it will issue updates to its Reader and Acrobat products on Tuesday 12 May, in a bid to fix recently discovered critical vulnerabilities.

At the end of April, Adobe issued an advisory warning about a JavaScript flaw in all currently supported versions of Adobe Reader, its popular PDF-viewing software. The vulnerability could let an intruder remotely execute code on a user's machine, causing the application to crash and potentially allowing the attacker to take control of the affected system.

On Friday, David Lenoe from Adobe's Product Security Incident Response Team (PSIRT), blogged that the company was in the process of fixing the issue and said the relevant product updates are scheduled to appear by 12 May.

"Adobe plans to make available Windows updates for Adobe Reader versions 9.X, 8.X, and 7.X and Acrobat versions 9.X, 8.X and 7.X, Macintosh updates for Adobe Reader versions 9.X and 8.X and Acrobat versions 9.X and 8.X, as well as Adobe Reader for Unix versions 9.X and 8.X," Lenoe wrote.

The software maker has also confirmed the existence of another vulnerability, in Adobe Reader for Unix, Lenoe said. That flaw will also be remedied in the scheduled updates for Adobe Reader for Unix, he noted.

Lenoe advised users waiting for the updates to disable JavaScript in Reader and Acrobat in the meantime.

The vulnerabilities are the latest in a string of security flaws found in Adobe's products. In March, Adobe patched a zero-day flaw in Reader that had led to exploits in the wild, while in February it had to issue a patch for a critical vulnerability in the Flash player.

In his post on Friday, Lenoe said that Adobe's security team had been unable to "reproduce an exploitable scenario for Windows and Macintosh", but said it would continue to investigate the issue.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
4 out of 5 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

2 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters