Adobe issues alert over Acrobat bug
- 18 August, 2005 07:15
- Comments
Acrobat and Acrobat Reader, two of the most widely used desktop applications, contain serious security flaws that could be used to take over a system, according to Adobe.
The company has urged users to update the software immediately.
Adobe Reader is Adobe's tool for reading PDF files, while Acrobat can also create PDF files and has other more advanced features. Affected are Reader and Acrobat versions 5.1, 6.0 to 6.0.3, and 7.0 to 7.0.2. Users can update to versions 5.2, 6.0.4 or 7.0.3 via the software's built-in automatic update or via a manual download from Adobe's site.
The bug is found in a core application plug-in found in both Acrobat and Reader, according to Adobe, and could be exploited by tricking the user into opening a malicious PDF file. Because PDFs can be embedded into Web pages, such an attack wouldn't necessarily require any user intervention.
"If a malicious file were opened it could trigger a buffer overflow as the file is being loaded into Adobe Acrobat and Adobe Reader," Adobe said in its advisory. "A buffer overflow can cause the application to crash and increase the risk of malicious code execution."
US-CERT, the US Computer Emergency Readiness Team, issued its own advisory on the flaw. FrSIRT, the French Security Incident Response Team, and independent security firm, Secunia, both assigned the bug highly critical ratings.
Network administrators may not have much leisure to patch - hackers have recently been taking less time to come up with worms that exploit known vulnerabilities in widely used software. A bug in Microsoft Windows Plug n Play, patched last Tuesday, quickly morphed into exploit code, and then into worms such as Zentob, which on Tuesday successfully disrupted systems at CNN, The New York Times, ABC and other large organisations in the US, Germany and Asia.
The bug went from disclosure to widespread worm attacks within a week, one of the fastest-developing security threats so far, security experts said.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- Magic Quadrant for Managed Print Services, Worldwide
- Advanced Malware Exposed - How advanced malware, zero-day and targeted APT attacks are evading today's network defences
- Seven SOA Practices to Unlock Business Value
- Best Practices for Implementing a Data Warehouse on the Oracle Exadata Database Machine
- Leveraging the Service Catalog to Scale Your MSP Business
-
The NBN, service providers and you... what could go wrong?
-
NBN build gaining momentum daily: Quigley
-
FTC chairman: Do-not-track law may not be needed
-
Kindle sales soar but Amazon mum on actual numbers
-
Wall Street Beat: IPOs, M&A, chip news stir tech optimism
-
Visio 2003 for Dummies
-
Office XP for Dummies Quick Reference
-
The Internet Gigabook for Dummies
-
Supporting Users and Troubleshooting a Microsoft Windows XP Operating System (70-271)
-
Improving Data Warehouse and Business Information Quality
-
Iphone 3Gs Portable Genius
-
Emerging Methods, Technologies, and Process Management in Software Engineering
-
Linux Sendmail Administration (Craig Hunt Linux Library)
-
Handbook of Usability Testing









Comments
Post new comment