Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

August 5th, 2010, 19:56 GMT · By

Adobe Prepares Out-of-Band Security Updates for Reader and Acrobat

SHARE:

Adjust text size:


Reader and Acrobat emergency patches to ship in two weeks
Enlarge picture
Adobe plans to deliver out-of-band security updates for its Reader and Acrobat products in two weeks. The new releases will contain emergency patches for several critical security issues including a zero-day vulnerability disclosed at the Black Hat security conference late last month.

"A Security Advisory has been posted in regards to upcoming Adobe Reader and Acrobat updates scheduled for the week of August 16, 2010. The updates will address critical security issues in the products, including CVE-2010-2862 which was discussed at the Black Hat USA 2010 security conference on Wednesday, July 28, 2010. These security updates will be made available for Windows, Macintosh and UNIX," a prenotification announcement
posted on the Adobe Product Security Incident Response Team (PSIRT) blog, reads.

CVE-2010-2862 refers to a zero-day vulnerability used as a test case by reputed security researcher Charlie Miller in his Black Hat talk on crash analysis. There are fears that ill-intent hackers could figure out the issue from Miller's presentation slides, which are now public and contain crash dump screenshots and other related information.

It is noted in the new advisory that updates will be made available for Adobe Reader 9.3.3 and earlier versions for Windows, Macintosh, and UNIX, as well as Adobe Acrobat 9.3.3 and earlier versions for Windows and Macintosh. These patches will break out of Adobe's quarterly security update cycle, according to which the next fixes are scheduled to land on October 12, 2010.

In fact, this will be the third time in a year when Adobe is forced to release updates out of band. Coupled with other push-backs to its scheduled releases, this makes one wonder if there's even any point in enforcing a quarterly update cycle, that is ultimately supposed to allow system administrators to plan patch deployment in advance.

There were rumors that because of the high number of critical bugs and their frequency, Adobe is considering switching to a monthly cycle. However, in July the company announced that the next major version of Reader will feature a sandbox mode enabled by default. This is expected to significantly lower the impact of vulnerabilities, so the quarterly update cycle concept might yet be saved.

You can follow the editor on Twitter @lconstantin

TELL US WHAT YOU THINK:

1,204 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Adobe Confirms New Adobe Reader Zero-Day Bug

Fix Available for Adobe Reader /Launch Patch Workaround

Adobe Investigates /Launch Fix Workaround

Adobe Finally Fixes /Launch Bug

Security Updates Available for Adobe Reader

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM