Advertisement
Promo

Security threats Toolkit

Adobe patches zero-day bugs in Reader, Acrobat

Matthew Broersma ZDNet.co.uk

Published: 13 May 2009 17:51 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Adobe has updated Adobe Reader and Adobe Acrobat to fix a serious JavaScript flaw affecting Windows, Mac, Linux and Unix, after code to exploit the bug was released on the internet.

As promised, the company sent out a security advisory on Tuesday with fixes for the vulnerability, and also patched a second flaw affecting Unix only. Security firm Secunia gave the flaws a "highly critical" ranking.

Adobe acknowledged that proof-of-concept code was circulating for the flaws on 27 April. The code was first released on the Linux security website Packetstorm.

However, Adobe said in a blog post on Tuesday that it was not aware of any attacks actively exploiting the proof-of-concept code.

Both bugs could be exploited via a specially crafted PDF file to crash the affected applications or take control of a user's system, Adobe said in its advisory.

The first bug, affecting the broader range of platforms, involves the way Reader and Acrobat process calls to the JavaScript method "getAnnots()", and can be used to corrupt memory, according to Adobe.

The second bug, affecting only Unix, involves the way calls to the "customDictionaryOpen()" JavaScript method are processed.

The bugs affect Reader 9.1 and Acrobat 9.1, as well as earlier versions, Adobe said. The company has fixed the issues in Acrobat and Reader versions 9.1.1, 8.1.5 and 7.1.2. The updates are available via Adobe's advisory.

For those unable to update, the company recommended turning off JavaScript in the affected applications.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
4 out of 4 people found this useful


Company/Topic Alerts

Create a new alert from the list below:









Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

5 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters