PDFZone Ziff-Davis Enterprise
Authoring | Utilities | Content Management | Document Management | Mobile | DRM | Other Formats | Tips
Home arrow Utilities arrow Adobe Plugs Code Execution Holes
Adobe Plugs Code Execution Holes
By Ryan Naraine

Rate This Article:
Add This Article To:
Users of the ubiquitous Adobe Acrobat and Adobe Reader software are at risk of code execution attacks.

A buffer overflow vulnerability in the widely used Adobe Acrobat and Adobe Reader programs could put millions of computer users at risk of code execution attacks.

According to an advisory from Adobe Systems Inc., a malicious hacker could exploit the flaw to crash the application or launch executable code on a vulnerable system.

ADVERTISEMENT

"The identified vulnerability is a buffer overflow within a core application plug-in, which is part of Adobe Acrobat and Adobe Reader. If a malicious file were opened it could trigger a buffer overflow as the file is being loaded into Adobe Acrobat and Adobe Reader," the company warned.

Because Adobe Reader is installed on most Windows computers to handle PDF (portable document format) files, security exporters are flagging the flaw as "highly critical."

Alerts aggregator Secunia Inc. is strongly recommending that users apply the vendor supplied patches at the earliest opportunity.

Read more here about patches for a file detection flaw in Reader and Acrobat.

Affected versions include Adobe Reader (Windows, Mac OS, Linux and Solaris) and Adobe Acrobat (Windows and Mac OS).

Adobe Reader is the de facto standard used to displays and print PDF files. Formerly known as Acrobat Reader, it is available for free for Windows, Mac, OS/2 and various versions of Unix.

Acrobat is a document exchange software that allows documents to be displayed and printed the same on every computer. The Acrobat system created the PDF standard, which is widely used in commercial printing and on the Web.

In its advisory, Adobe urged Windows and Mac OS users to upgrade to version 7.0.3 via the Adobe Reader's automatic update utility. The program's default installation configuration runs automatic updates on a regular schedule, and can be manually activated by choosing Help > Check For Updates Now.

The patch can also be manually downloaded and installed from the company's support Web site.


Discuss Adobe Plugs Code Execution Holes
 
>>> Be the FIRST to comment on this article!
 

 
 
>>> More Utilities Articles          >>> More By Ryan Naraine
 



FREE ZIFF DAVIS ENTERPRISE ESEMINARS AT ESEMINARSLIVE.COM
  • Dec 5, 2 p.m. ET
    Case Studies in MSP Profitability: 10 Processes to Automate to Achieve 2008 Goals
    with Michael Krieger. Sponsored by Autotask
  • Dec 6, 12:30 p.m. ET
    The State of the Great Windows Vista Migration
    with Aaron Goldberg. Sponsored by Dell & Microsoft
  • Dec 6, 2 p.m. ET
    Three Best Practices for Securing Microsoft Exchange
    with Michael Krieger. Sponsored by Entrust
  • Dec 6, 3 p.m. ET
    Simplify Your World, part 2: A Virtual Desktops Case Study
    with Joel Shore. Sponsored by EqualLogic
  • 12-19 VTS LOGO for BotMod
    Join us on Dec. 19 for Discovering Value in Stored Data & Reducing Business Risk. Join this interactive day-long event to learn how your enterprise can cost-effectively manage stored data while keeping it secure, compliant and accessible. Disorganized storage can prevent your enterprise from extracting the maximum value from information assets. Learn how to organize enterprise data so vital information assets can help your business thrive. Explore policies, strategies and tactics from creation through deletion. Attend live or on-demand with complimentary registration!
    FEATURED CONTENT

    Sponsored by Ziff Davis Enterprise Group


    DOWNLOADABLE ROI CALCULATORS & TOOLS FROM BASELINE
      Calculate Cost and ROI of Spam, VOIP, RFID, Sarbanes-Oxley and more...


    Featured Calculators:

     



    See More Tools!
    By Category| Planners |Calculators | Quizzes

     

    Special Report


    PDFzone Special Report: Making the Perfect PDF
    The Perfect PDF
    PDFzone shows you how to shine and polish your PDF by adding the reader-friendly touches your audience desires.

    Special Report


    PDFzone Special Report: Microsoft's PDF Play
    Microsoft's PDF Play
    Microsoft planned to offer a "Save to PDF" function in Office 2007, but the threat of legal action from Adobe may have them reconsidering.

    Special Report


    PDF conversion
    PDF Conversion Central
    Convert anything and everything to PDf and back again. Word docs, RSS, AutoCAD and more.
    ADVERTISEMENT