Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Security Fixes and Improvements

November 17th, 2010, 07:52 GMT · By

Critical Updates Released for Adobe Reader and Acrobat

SHARE:

Adjust text size:


Adobe Reader and Acrobat 9.4.1 released
Enlarge picture
Adobe has released updates for its Reader and Acrobat products in order to address several vulnerabilities that can be exploited to execute arbitrary code remotely.

The new 9.4.1 versions have only been released for Windows and Mac, the UNIX updates being scheduled to land on November 30.

Patched bugs include CVE-2010-4091, a memory corruption vulnerability disclosed as a zero-day at the beginning of the month.

Despite proof-of-concept exploit code being publicly available, no attacks exploiting this flaw have been detected in the wild so far.

There is reason to believe the issue was known in some hacking circles since November 2009, when details about it were published on Russian-language blogs.

Vulnerability research company VUPEN confirmed that in addition to triggering a denial of service condition the flaw can be exploited to execute arbitrary code on the target system.

A patch for CVE-2010-4091 was rushed into this out-of-band update as it was already being prepared for release in order to address an actively exploited Flash vulnerability.

Identified as CVE-2010-3654, the Flash issue was discovered in late October, when it began being exploited in the wild via maliciously crafted SWF content embedded in PDF documents.

The flaw affects Adobe Reader and Acrobat through the Flash interpreter integrated into the two products as a library called authplay.dll.

This latest release updates authplay.dll to the latest Flash Player version, released on November 5, which addresses a total of eighteen critical vulnerabilities.

Nevertheless, Adobe Reader 8.x users will remain vulnerable to CVE-2010-4091 until February 8, 2011, when the next quarterly updates are scheduled to land.

In order to protect themselves they can manually blacklist the vulnerable printSeps() JavaScript API. Detailed information on how to do this on Windows and Mac is provided on the Adobe Product Security Incident Response Team (PSIRT) Blog.

The latest version of Adobe Reader for Windows can be downloaded here.

The latest version of Adobe Reader for Mac can be downloaded here.


TELL US WHAT YOU THINK:

1,337 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Critical Adobe Reader and Acrobat Updates Scheduled for Tomorrow

Adobe Suggests Workaround for New Reader Zero-Day

Adobe Reader and Acrobat Hit by New Zero-Day

Unpatched Critical Flash Player Vulnerability Possibly Exploited in the Wild

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM