[Computer security] Adobe Reader/Acrobat zero-day vulnerability *PATCH AVAILABLE*

mechBgon

Enlightened
Joined
Nov 3, 2007
Messages
567
Update, March 11th: Adobe now has a patch for Adobe Reader 9.x and Adobe Acrobat 9.x. If you use an older family such as Adobe Reader 8.x, Adobe does not have a patch ready yet.

  • Linux: keep waiting, because Adobe does not have a patch ready yet :sigh:

If you have the full-on Adobe Acrobat software (the paid version that can create PDF files, not the freebie reader), then start your Adobe software and run the Adobe Updater by clicking Help > Check For Updates.






Update: Secunia reports that it's possible to exploit Adobe's vulnerability even with JavaScript disabled. Their top suggestion: don't open PDF files if you're not sure they're trustworthy.


The bad guys have begun exploiting a vulnerability in Adobe Reader/Acrobat software. This is a cross-platform vulnerability (Windows, Linux and Mac). In the past, PDF vulnerabilities have been reached via "malvertisements" sneaked onto legit websites. Direct email of malicious PDF files is another possible attack vector.

Adobe says they'll have a patch available ~March 11th to fix it. In the meantime, if you have Adobe Reader and/or Acrobat installed, disable JavaScript.

1) start Reader (and Acrobat if you have it)

2) click Edit > Preferences

3) in the Preferences, click Javascript and uncheck the box for JavaScript.

Reader.png

disable JavaScript to prevent easy exploitation

Windows XP and Windows Vista users can also fully enable Data Execution Prevention to help prevent this type of attack.

enable_DEP.gif

Fully enable the Data Execution Prevention (WinXP/Vista/7)
 
Last edited:

NA8

Flashlight Enthusiast
Joined
Jun 4, 2007
Messages
1,565
Re: [Computer security] Adobe Reader/Acrobat zero-day vulnerability *UPDATED*

Is it just Acrobat or is the Foxit reader a problem too ?
 

Marlite

Enlightened
Joined
Jan 7, 2006
Messages
257
Location
YVR
Re: [Computer security] Adobe Reader/Acrobat zero-day vulnerability *UPDATED*

Thanks again Mech Begon for keeping us safe.

Re: Secunia each time I start up my computer a Secunia dialog balloon says to download latest update. Is this to be done each time? Most of the time it does not show any updates. Are we to ignore the balloon or should it be clicked on or removed from the quick launch bar?

Thanks for any clarification.
marlite
 

mechBgon

Enlightened
Joined
Nov 3, 2007
Messages
567
Re: [Computer security] Adobe Reader/Acrobat zero-day vulnerability *UPDATED*

Thanks again Mech Begon for keeping us safe.

Re: Secunia each time I start up my computer a Secunia dialog balloon says to download latest update. Is this to be done each time? Most of the time it does not show any updates. Are we to ignore the balloon or should it be clicked on or removed from the quick launch bar?

Thanks for any clarification.
marlite

If I understand correctly, Secunia is asking you to update to the latest sub-release of Secunia's program, currently 1.0.0.3, is that correct? If so, it isn't strictly necessary. They make minor tweaks and bugfixes, but if it's working as-is, an older version like 1.0.0.1 should still do what it's supposed to do.
 

Marlite

Enlightened
Joined
Jan 7, 2006
Messages
257
Location
YVR
Re: [Computer security] Adobe Reader/Acrobat zero-day vulnerability *UPDATED*

If I understand correctly, Secunia is asking you to update to the latest sub-release of Secunia's program, currently 1.0.0.3, is that correct? If so, it isn't strictly necessary. They make minor tweaks and bugfixes, but if it's working as-is, an older version like 1.0.0.1 should still do what it's supposed to do.


Hi Mech Begon

Thank you for the great service you provide. The timely warnings are most appreciated. I will check and update regularly.

marlite
 

mechBgon

Enlightened
Joined
Nov 3, 2007
Messages
567
Re: [Computer security] Adobe Reader/Acrobat zero-day vulnerability *UPDATED*

Glad to help. Original post updated with some patch-availability info :)
 

Latest posts

Top