Email this article   Print article 

Adobe Warns Of Critical Flaw In Reader, Acrobat

By Stefanie Hoffman, CRN
October 09, 2009    7:18 PM ET

Adobe warned its users of active attacks exploiting a critical vulnerability in Adobe Reader and Acrobat 9.1.3 on Windows, Mac OS X and Unix.

Adobe says it will address the critical Reader and Acrobat vulnerability in a security update that it plans to release Oct. 13. Adobe maintains that thus far, the active exploits are limited to "targeted attacks" aimed at Reader and Acrobat 9.1.3 on Windows.

The upcoming Adobe patch is the second security update for both Reader and Acrobat this quarter.

While the vulnerability isn't dependent upon JavaScript, Adobe said in its security advisory that users might be able to mitigate the flaw by disabling the JavaScript function until a patch is released. Adobe also recommended that users keep antivirus products up to date. Meanwhile, Adobe Reader and Acrobat 9.1.3 customers with DEP enabled on Windows Vista are protected against attacks exploiting the vulnerability, Adobe said.

SANS Institute researcher Johannes Ullrich said in a blog that Adobe users could also "clean" PDF documents by converting them into an alternative format, such as PostScript, and then turning them back into a PDF.

"However, this is not 100 percent certain to remove the exploit and you may infect the machine that does the conversion, as it will likely still use the vulnerable libraries to convert the document. But the likelihood of this happening is quite low," Ullrich said.

Adobe said it is collaborating with several antivirus and security vendors in order to address the security vulnerabilities.

Until the issue is resolved, users can monitor the latest information on the Reader and Acrobat flaw at the Adobe Product Security Incident Response Team blog.


Email this article   Print article 

More Security

Recent Articles

Symantec's Code Red: The Law Enforcement/Anonymous E-Mail Exchange

Law enforcement officials negotiated via e-mail for more than two weeks with an Anonymous group member trying to extort $50,000 from Symantec to keep stolen product code off the Internet.

How To Sell IT Security Services To Your Customers

Cyberattacks can cost a business thousands, even millions, of dollars, and can deal a death blow to some. Here's how IT solution providers can help guard against malicious attacks.

Cybersecurity Experts: What They Know Could Scare You

A recent report based on interviews with security experts in government, business and academia finds more than half in agreement that a worldwide arms race is taking place in cyberspace.

  More Slide Shows




Related Videos
Loading...