ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Adobe readies 'critical' PDF Reader Patch Tuesday

By | June 10, 2011, 6:19am PDT

Summary: The company will patch vulnerabilities that expose Windows and Mac OS X users to code execution attacks via rigged PDF files.

Adobe will join Microsoft’s Patch Tuesday train this month with plans to fix critical security vulnerabilities in the Adobe PDF Reader and Adobe Acrobat software products.

The vulnerabilities, which expose users to code execution attacks via rigged PDF files, affect both Windows and Mac OS X users.

Software versions affected by the vulnerabilities in this patch batch include:

  • Adobe Reader X (10.0.1) and earlier versions for Windows
  • follow Ryan Naraine on twitter

  • Adobe Reader X (10.0.3) and earlier versions for Macintosh
  • Adobe Reader 9.4.3 and earlier versions for Windows and Macintosh
  • Adobe Acrobat X (10.0.3) and earlier versions for Windows and Macintosh
  • Adobe Acrobat 9.4.3 and earlier versions for Windows and Macintosh

Adobe describes a critical security issue as a vulnerability that could be exploited to allow malicious native-code to execute, potentially without a user being aware.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

29
Comments

Join the conversation!

Just In

RE: Adobe readies 'critical' PDF Reader Patch Tuesday
FAULKNE 13th Oct
Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.
No mention of Adobe reader 9.4.2 for Linux! If wonder if that means it is safe or an oversight on the part of someone! Guess I wait till Tuesday and see if there s an update available.
0 Votes
+ -
It's safe
ScorpioBlue 10th Jun
Besides, who'd use crap from Adobe when there are tons of alternatives out there.
0 Votes
+ -
I Run AcroCrap under Microsoft EMET with max security settings
I run Sumatra PDF which starts almost instantly. The people at Sumatra do not assume that I have nothing better to do than restart my machine because they have come up with a newer version. No background tasks using my machine when I am not even running it either. It won't make the morning coffee, but it does everything I require of a PFD reader.
0 Votes
+ -
How long will it be, seriously, before Windows, MacOS and the rest have a native PDF reader? It should have happened by now.
@behindthe8ball
Os X has had a really nice, lightweight PDF readers since forever. It's called Preview. It also does some light photo preview and editing, and some other chores. I never have to use reader on a Mac.
@behindthe8ball I'm part of the "rest" with openSUSE Linux, and the KDE desktop environment installs with Okular as a default PDF reader - it also displays Postscript, DjVu, CHM, XPS, ePub and other formats, allows annotating and highlighting and also automatically bookmarks your location in every PDF file you view (which I love). It was one of the pleasant surprises when I switched to Linux 11 months ago. Having an archiver, flash and java out-of-the-box was nice, too. happy
0 Votes
+ -
errrrr
Gis Bun 10th Jun
You have to wonder. Unless you are picking up PDFs from questionable web sites [or dumb enough to get a scam email], I suspect getting any of these vulnerabilities are unlikely.
0 Votes
+ -
Message has been deleted.
HackerJ Updated - 12th Jun
0 Votes
+ -
Message has been deleted.
ScorpioBlue Updated - 14th Jun
@ScorpioBlue

I use windows and i am not a moron and i have to use acrobat reader for school.... and losedoze really?
sure your not just a freaking troll?
  • Flagged
0 Votes
+ -
Message has been deleted.
ScorpioBlue Updated - 14th Jun
  • Flagged
@ScorpioBlue Hey mate, I think the Army needs your services over in Afghanistan. Get yourself down the Recruiting Office first thing tomorrow morning - 0800. They are desperate for more Snipers...!
  • Flagged
0 Votes
+ -
RE: Adobe readies 'critical' PDF Reader Patch Tuesday
blind obedience Updated - 14th Jun
Wow @Knix96, I didn't know you were one of those.

lol... grin
0 Votes
+ -
@Up2Stokes

Woah buddy, time for you to do some down-strokes first.

lol... grin
@HackerJ

Quite a few people who still need a .pdf plugin to view things online, which NitroPDF doesn't come up and Foxit's plugin is crashy.
@Lerianis10

So the choice is "crashy" Foxit or security hole Adobe?

According to what you just said, it doesn't sound promising either way...
0 Votes
+ -
Message has been deleted.
Up2Stokes Updated - 14th Jun
  • Flagged
This is an excellent article. The following publish supplies genuinely high quality info. My spouse and i?meters bound to check in it. Truly extremely helpful points are given listed here. Many thanks a great deal. Carry on favorable functions. vintage snapback hats best solid state drive
This is a really good read for me. Must admit that you are one of the best bloggers I have ever read. Thanks for posting this informative article. baby gifts for boys baby gifts for girls
I like the article you wrote here; it is very informative and useful for the internet users like me. I will come back to read more blog posts on your website and I have bookmarked your website as well Thank You know style clothing store girls clothing stores online
I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate! nccma cooler
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post. this thread is amazing i like your work and i appreciate you that you have share a useful stuff thanks for sharing the i shop abatwa
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post.Bookmarking now thanks please consider a follow up post. power sa shop
I think the representation of this article is actually superb one. This is my first visit to your site. Thanks a lot and keep sharing the information. Keep updating the information for all of us. Thanks ZDNet Government was launched as the brand's first industry vertical, with a mission to cater to IT professionals in the public secto I agree with your post. However, do you have any sources I can cite for my paper wheel car com bury
Well welcome, hopefully you can become a vital member of the community and really help to push far ahead of google. Which Im sure the development team would love. This will of course earn you alot points too and get you on the leaders board. z d n e t t h a n k Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas.
This is my first visit to z d n e t site. Thanks a lot and keep sharing the information. Keep updating the information for all of us.how can i clean up, because i don???t know why it seems my skeen has to fat i get the glasses dirty every day.i search y a h o o Very good quality indeed. I surely recommend it. The template used in their site is also great.
Fantastic news about the new release.I positively enjoying each little bit of it and I have you b o o k m a r k e d to check out new stuff you weblog post.Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas
Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix