Adobe Set To Plug PDF Flaws

Adobe Systems is planning to issue an out-of-band security update later this month to plug multiple security holes, including one discussed last week at the Black Hat security conference.

The update will cover critical bugs affecting Adobe Reader and Acrobat. Among them will be a flaw mentioned at Black Hat by Charles Miller, principal security analyst with consulting firm Independent Security Evaluators. The bug, which can be used by attackers to compromise a system, is due to an integer overflow error.

“We are planning to make available an out-of-band security update for Adobe Reader and Acrobat during the week of August 16, 2010,” an Adobe spokesperson told eWEEK. “This update will resolve critical security issues in Adobe Reader 9.3.3 for Windows, Macintosh and UNIX, Adobe Acrobat 9.3.3 for Windows and Macintosh, and Adobe Reader 8.2.3 and Acrobat 8.2.3 for Windows and Macintosh, including CVE-2010-2862 which was discussed at the Black Hat USA 2010 security conference on Wednesday, July 28, 2010.”

Memory Corruption

According to Secunia, the vulnerability uncovered by Miller can be exploited to corrupt memory via a PDF file containing a specially-crafted TrueType font, and affects Adobe Reader versions 8.2.3 and 9.3.3 as well as Acrobat 9.3.3. The company warned that earlier versions may be affected as well, and advised users not to open untrusted PDF files with the software.

The Adobe spokesperson said the company is currently unaware of any exploits in the wild targeting any of the issues slated to be covered in the update.

Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

Tesla Recalls 46,000 Cybertrucks Over ‘Crash Risk’ Faulty Trim

All Cybertrucks manufactured between November 2023 and February 2025 recalled over trim that can fall…

1 day ago

Elon Musk Issued Summons By SEC Over Failure To Disclose Twitter Stake

As Musk guts US federal agencies, SEC issues summons over Elon's failure to disclose ownership…

1 day ago

Alphabet Spins Out Taara To Challenge Musk’s Starlink

Moonshot project Taara spun out of Google, uses lasers and not satellites to provide internet…

2 days ago

Pebble Creator Debuts New Watches As ‘Labour Of Love’

Pebble creator launches two new PebbleOS-based smartwatches with 30-day battery life, e-ink screens after OS…

3 days ago

Amazon Loses Appeal To Record EU Privacy Fine

Amazon loses appeal in Luxembourg's administrative court over 746m euro GDPR fine related to use…

3 days ago

Nvidia, xAI Join BlackRock AI Infrastructure Project

Nvidia, xAI to participate in project backed by BlackRock, Microsoft to invest $100bn in AI…

3 days ago