Adobe Patch Tuesday heads-up: Critical holes in PDF Reader
Summary: A pre-notification advisory from Adobe confirms that this patch batch will include a fix for CVE-2010-2883, which has already been exploited in zero day attacks.
As part of its scheduled quarterly update cycle, Adobe plans to release new versions of its PDF Reader/Acrobat software to gaping security holes that expose users to hacker attacks.
The patches will be released next Tuesday (October 5, 2010) for Windows, Mac and UNIX users.
[ New PDF zero-day under attack ]
A pre-notification advisory from Adobe confirms that this patch batch will include a fix for CVE-2010-2883, which has already been exploited in zero day attacks.
In those attacks, the vulnerability is being exploited via rigged PDF files sent to select business targets.
The October 5, 2010 updates represent an accelerated release of the next quarterly security update originally scheduled for October 12, 2010.
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.
Talkback
RE: Adobe Patch Tuesday heads-up: Critical holes in PDF Reader
RE: Adobe Patch Tuesday heads-up: Critical holes in PDF Reader
Simple Fix...
RE: Adobe Patch Tuesday heads-up: Critical holes in PDF Reader
RE: Adobe Patch Tuesday heads-up: Critical holes in PDF Reader
"Foxit reader. It's much lighter and totally secure."
While I, too, use Foxit reader, don't delude yourself that it is "totally secure". It is subject to some of the same vulnerabilities as Adobe, and you have to "Check for Updates" regularly to make sure you are protected. Fortunately, it is less known and less subject to directed hacking attacks.
some very uniformed comments here
RE: Adobe Patch Tuesday heads-up: Critical holes in PDF Reader
But of course I don't know much about the specific nature of the problem.
RE: Adobe Patch Tuesday heads-up: Critical holes in PDF Reader
Q: What are the risks of opening PDF files when using Preview in Mac OS X?
RE: Q: What are the risks of opening PDF files when using Preview in Mac OS
Different application. It shouldn't be effected.
RE: Adobe Patch Tuesday heads-up: Critical holes in PDF Reader
There is a patch for Both PC and Mac versions, so there is likely a problem with versions on both platforms
RE: Adobe Patch Tuesday heads-up: Critical holes in PDF Reader
RE: Adobe Patch Tuesday heads-up: Critical holes in PDF Reader
Adobe needs to redo Reader big time, to get rid of these holes.
RE: Adobe Patch Tuesday heads-up: Critical holes in PDF Reader
Or at least Adobe could start properly compiling all their DLLs to take advantage of DEP (data execute prevention), which is what EMET easily and externally enforces.<br><br>Why Adobe hasn't done this is at least a question of this hour. Perhaps over politics between Adobe and Redmond, who knows.