Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Security Fixes and Improvements

September 16th, 2010, 17:55 GMT · By

Researchers Release Unofficial Patch for Actively Exploited Adobe Reader Bug

SHARE:

Adjust text size:


Third-party programmers patch Adobe Reader vulnerability
Enlarge picture
Experts from a penetration testing and security auditing firm have patched the Adobe Reader file, which contains a vulnerability currently exploited to infect users with malware.

The previously unknown flaw was discovered last week in the wild, where it was being exploited via malicious PDF documents.

Security researchers later revealed that the exploit uses advanced programming techniques in order to bypass the ASLR and DEP code execution prevention technologies included in Windows Vista and 7.

Two days ago Adobe announced that it will deliver its quarterly Adobe Reader and Acrobat patches, which will address this vulnerability, earlier.

Originally scheduled for October 12, the updates will now ship during the week of October 4, which unfortunately still leaves users exposed to attacks for three more weeks.

"We've decided to go on and patch this easy vulnerability and protect at least our customers and all other interested people," researchers from a security company called RamzAfzar, said.

"After initial analysis we've discovered that exploit exists in insecure strcat call located in CoolType.dll," they note.

RamzAfzar team's solution was to bypass the "strcat" function by redirecting calls to "strncat", a more secure alternative.

"We patched it without having source code in 2 hours and they need 20 days with code, looks odd to me!," one of the experts commented.

The explanation for this might come from the fact that Adobe doesn't one to release an out-of-band patch for this bug alone.

The October 4 updates will most likely also contain fixes for many other vulnerabilities, which the company is still working on.

In addition, before putting new packages out, the vendor has to thoroughly test them in order to make sure that they don't generate stability issues.

Interested users can download the CoolType.dll patched by RamzAfzar from here and copy it over the one in the Adobe Reader folder. However, It would be sensible to make a backup of the original one first.

TELL US WHAT YOU THINK:

1,284 hits · 2 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Patch Schedule Announced for Actively Exploited Adobe Reader Vulnerability

Flash Zero-Day Actively Exploited in the Wild

Zero-Day Adobe Reader Exploit Drops Digitally Signed Malware

Critical Adobe Reader Vulnerability Exploited in the Wild

Adobe's Products Lead in Number of Outdated Installations

READER COMMENTS:


Comment #1 by: fizzymynizzy on 16 Sep 2010, 22:47 UTC reply to this comment

When I try to go to that place for the patch I get this "The server's security certificate is revoked!
You attempted to reach www.rafzar.com, but the certificate that the server presented has been revoked by its issuer. This means that the security credentials the server presented absolutely should not be trusted. You may be communicating with an attacker. You should not proceed." on Chrome 7.0.517.5

Comment #1.1 by: Lucian Constantin on 18 Sep 2010, 07:37 GMT

Indeed it appears to be a problem with the certificate under Google Chrome and Internet Explorer. Add an exception if possible or try in Firefox, where it appears to be working.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM