Pixalo Photography Community  

Go Back   Pixalo Photography Community > Photography Forums > News
Register Search Today's Posts Mark Forums Read

News Discuss Acrobat version 8.1.1 and fixes vulnerability...Adobe is offering a software update to fix a security flaw in the Adobe Acrobat and free Adobe Reader product ...

Welcome to the Pixalo Photography Community. As a Guest you are free to browse the site, but see what extras you get as a Member here.


Reply
 
LinkBack Thread Tools Display Modes
Old 24-10-2007, 07:24   #1 (permalink)
Pixalo Crew
 
Steve's Avatar
 
Join Date: Jan 2005
Location: An Englishman living in Germany
Posts: 16,158
Steve is a jewel in the rough
Steve is a jewel in the roughSteve is a jewel in the rough

Image editing O.K.
User's Gallery
Users Camera Equipment List
Acrobat version 8.1.1 and fixes vulnerability

Adobe is offering a software update to fix a security flaw in the Adobe Acrobat and free Adobe Reader product which is used to read the popular PDF document format. The update, brings the latest versions of Adobe Reader and Acrobat to versions 8.1.1 and fixes a vulnerability that only affects Microsoft Windows XP and Windows Server 2003 users who use Internet Explorer 7.

Adobe says the flaw also exists in version 7.0.9 of Adobe Acrobat and Adobe Reader, but that a fix for that version will be released in a separate update.

Symantec Corp has said that a malicious PDF document that exploits bugs in the Acrobat software is already in the wild. "This mass mailing of exploit files may be an attempt to leverage the exposure window between patch release and widespread adoption of the fix," said Symantec in a warning to customers of its DeepSight threat intelligence network.

The rogue PDF document is attached to a spammed e-mail, and arrives with a filename such as YOUR_BILL.pdf or INVOICE.pdf, said Symantec. It exploits the "mailto:" protocol vulnerability disclosed more than a month ago by U.K.-based researcher Petko Petkov.

When recipients open an 'attacking' PDF, it launches a Trojan horse dubbed "Pidief.a" that knocks out the Windows firewall and then downloads anotherpiece of Malware to the compromised computer. That second piece of attack code is a dedicated downloader that can retrieve files from a remote server and, at the attacker's command, pull them onto the hacked PC.

The problem is related to a published vulnerability relating to URL Handling in Windows, which Microsoft has yet to address at source - and it has affected several types of third-party software of which Adobe has been the most recent to circumvent with its own fix.

If you use Windows XP and Internet Explorer 7, you should update Acrobat and Acrobat Reader without delay using the Adobe patch download link below.
You may also want to consider using an alternative program to read PDF files - as mentioned in the Washington Post article linked below.
-------------------------------------------------------------------------------------------------------------------

W E B L I N K S
Washington Post: Adobe Fixes Reader, Acrobat Vulnerabilities - Security Fix

Microsoft Advisory: Microsoft Security Advisory (943521): URL Handling Vulnerability in Windows XP and Windows Server 2003 with Windows Internet Explorer 7 Could Allow Remote Code Execution
Adobe Advisory: Adobe - Security Advisories : APSB07-18: Adobe Reader and Acrobat vulnerability
Adobe patch download: Adobe - Adobe Reader : For Windows : Adobe Reader 8.1.1 update - multiple languages
__________________
.......__o
.......\<,
....( )/ ( )
Steve is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Adobe Acrobat reader vulnerability Steve News 0 11-10-2007 15:25
Microsoft fixes 'critical' flaws Pixalo Computer hardware, software, networking and internet 0 11-04-2007 14:10
Microsoft fixes 20 security holes Pixalo Computer hardware, software, networking and internet 0 14-02-2007 11:50
Microsoft fixes flawed bug patch Pixalo Computer hardware, software, networking and internet 2 25-08-2006 12:10
Adobe Acrobat reader updates Steve Computer hardware, software, networking and internet 2 18-06-2006 07:28

All times are GMT +1. The time now is 05:36.


vBulletin Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
ReviewPost & PhotoPost vB3 Enhanced, Copyright 2003-2006 All Enthusiast, Inc.
Content Relevant URLs by vBSEO 3.1.0
Copyright © 2006 - 2008 Pixalo.com

Bleach 151 . Bleach 152 | Mbna | Car Insurance | Ringtone | Mortgages

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92