• On mySimon: Spiewak Durand Jacket
May 20, 2009 3:41 PM PDT

Adobe to release security updates a la Patch Tuesday

by Elinor Mills
  • Font size
  • Print
  • 2 comments

Correction 4:05 p.m. PDT: This post initially misstated how often the security updates will be. Adobe plans to issue updates quarterly.

Adobe said on Wednesday it will release quarterly security updates to coincide with Microsoft's Patch Tuesday as part of a new approach to product security for Adobe Reader and Acrobat.

The security updates will be delivered on a second Tuesday once a quarter, beginning this summer, Brad Arkin, director of product security and privacy, wrote in a blog post. Microsoft's Patch Tuesday updates are issued monthly on the second Tuesday.

Adobe security patches released on Patch Tuesdays March 10 and May 12 were coincidental, the post said.

The most recent patch fixed a hole in Flash Media Server 3.5.1 and earlier that could allow an attacker to execute remote procedures in Flash Media Interactive Server or Flash Media Streaming Server.

The March patch fixed a critical vulnerability in Adobe Reader 9 and Acrobat 9 that could allow an attacker to take complete control of a computer and for which exploits had been reportedly found in the wild for nearly two months.

The Adobe Reader issue sparked "a lot of conversation internally at Adobe from executives to testers and developers" and ultimately led to the permanent changes to Adobe's software security approach, Arkin said. "Everything from our security team's communications during an incident to our security update process to the code itself has been carefully reviewed," he wrote.

All new code and features for Adobe Reader and Acrobat have been put through a Secure product Lifecycle that is similar to Microsoft's much-touted Security Development Lifecycle, according to Arkin. Now, Adobe is working on hardening at-risk areas of its legacy code too, he added.

Arkin also promised that people outside the company "will see more timely communications regarding incidents, quicker turnaround times on patch releases, and simultaneous patches for more affected versions as we move forward."

Security issues with Adobe Reader prompted firm F-Secure to suggest that people should switch to an alternate PDF reader at the RSA security conference last month. Just last month another security hole surfaced in Adobe Reader.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
advertisement
Click Here
Recent posts from Security
Pub fined $13k for Wi-Fi copyright infringement
Tips for safe online shopping
Big changes in Security Starter Kit 2010
Confidential 9/11 pager messages disclosed
Microsoft warns of IE exploit code in the wild
Chrome OS security: 'Sandboxing' and auto updates
E-tailers snagged in marketing 'scam' blame customers
McAfee warns about '12 Scams of Christmas'
Add a Comment (Log in or register)
by Police_States_of_America May 20, 2009 4:06 PM PDT
and in tech news today the regularly scheduled update will occur
Reply to this comment
by Michichael May 20, 2009 5:38 PM PDT
Yay. Patch day. get ready for your msiexec /p everybody!
Reply to this comment
advertisement

The browser battles go on and on

roundup From Firefox to IE and from Chrome to Opera and Safari, there's no sitting still for browser makers looking to keep their products fresh and competitive.

3G wireless still holds promise

The next generation of 4G wireless may get all the headlines, but advanced 3G technology will likely dominate services for the next few years.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right