Adobe Issues Security Update for Reader And Acrobat

Adobe Systems released a patch today to plug a security hole affecting Adobe Reader that is on the radar of attackers.

The update actually fixes two vulnerabilities, though only one is known to be under attack. That vulnerability – a flaw affecting Adobe Reader 9.4.1 and earlier 9.x versions for Windows, Unix and Mac OS X – had been targeted by attackers for the past few weeks.

Flash Rendering And Service Denial

The problem is actually in Reader’s authplay.dll component, which is used to render Flash content in PDF files. Adobe first warned users about the bug on October 28 and patched the vulnerability in Flash Player earlier this month.

The vulnerability, CVE-2010-3654, could be used to cause a crash and potentially allow an attacker to take control of the affected system, Adobe said in its advisory.

The other issue fixed in the update is a denial-of-service bug. An Adobe spokesperson said the company has not seen any exploit in the wild targeting the bug yet. However, proof of concept code was posted on the Full Disclosure mailing list.

“Adobe recommends users of Adobe Reader 9.4 and earlier versions for Windows and Macintosh update to Adobe Reader 9.4.1, available now,” the company said in the advisory. In addition, “Adobe recommends users of Adobe Reader 9.4 and earlier versions for Unix update to Adobe Reader 9.4.1, expected to be available on November 30, 2010 … [and] users of Adobe Acrobat 9.4 and earlier 9.x versions for Windows and Macintosh update to Adobe Acrobat 9.4.1.”

Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

Australia Rejects Elon Musk Claim About Social Media Ban For Under-16s

Government minister flatly rejects Elon Musk's “unsurprising” allegation that Australian government seeks control of Internet…

2 hours ago

Northvolt Files For Bankruptcy Protection In US

Northvolt files for Chapter 11 bankruptcy protection in the United States, and CEO and co-founder…

3 hours ago

UK’s CMA Readies Cloud Sector “Behavioural” Remedies – Report

Targetting AWS, Microsoft? British competition regulator soon to announce “behavioural” remedies for cloud sector

19 hours ago

Former Policy Boss At X Nick Pickles, Joins Sam Altman Venture

Move to Elon Musk rival. Former senior executive at X joins Sam Altman's venture formerly…

21 hours ago

Bitcoin Rises Above $96,000 Amid Trump Optimism

Bitcoin price rises towards $100,000, amid investor optimism of friendlier US regulatory landscape under Donald…

23 hours ago

FTX Co-Founder Gary Wang Spared Prison

Judge Kaplan praises former FTX CTO Gary Wang for his co-operation against Sam Bankman-Fried during…

23 hours ago