![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Computer Security News The Latest Computer Security News |
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Moderator/ Rangemaster TSF Academy; Analyst, Security Team; Oor Wullie; TSF Surgeon and Resident Comic
|
New security woe hits Adobe Reader
Reports are emerging that Adobe's PDF Reader contains a critical vulnerability, and the company has confirmed it is investigating.
A security researcher said that the bug is another in a long line of flaws in Adobe's implementation of JavaScript. The bug was first disclosed Monday on the SecurityFocus site, which posted a link to proof-of-concept attack code. "An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the application," said the advisory. According to SecurityFocus, the most up-to-date versions, Reader 9.1 and Reader 8.1.4, are vulnerable. The Linux versions definitely have the bug, and other platforms - Adobe also provides Reader for Windows and the Mac - may be at risk as well. For its part, Adobe's acknowledgement was brief. "Adobe is aware of reports of a potential vulnerability in Adobe Reader 9.1 and 8.1.4," said David Lenoe, the company's security program manager, in a security blog entry. "We are currently investigating, and will have an update once we get more information." An Adobe spokesman declined to answer questions about the bug, saying that all the company had to offer at the moment was Lenoe's comments. More information, he promised, would be published to the blog, or to Adobe's security advisory page. The short confirmation was reminiscent of Adobe's admission two months ago when it said Reader contained one or more bugs. In that incident, attackers had been exploiting the vulnerability for as many as six weeks, possibly more. Adobe patched that flaw, and several others, starting on 10 March, fixing first Reader 9, then working its way down to Reader 8 and even older versions at one-week intervals. "This is very similar to February," said Andrew Storms, director of security operations at nCircle Network Security. "They've had a long rash of problems with JavaScript, and again we're seeing what looks like a JavaScript vulnerability." http://www.techworld.com/security/ne...&NewsID=115135
__________________
Iain - Defender of the Haggis and all things Scottish. I don't help by PM - post in the Forums. ![]() ![]() PC Safety & Security::PC running a bit slow?::Donate::Photographers Corner |
|
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
![]() |
| Thread Tools | |
|
|