• On TV.com: MEGAN FOX Photos
October 13, 2009 12:55 PM PDT

Adobe fixes 28 holes in Reader and Acrobat

by Elinor Mills
  • Font size
  • Print
  • 9 comments

Adobe on Tuesday released a security bulletin that includes fixes for 28 vulnerabilities in Adobe Reader and Acrobat, including a critical hole that has reportedly been exploited in the wild in limited attacks.

Affected software includes version 9.1.3 of Reader and Acrobat; Acrobat 8.1.6 for Windows, Macintosh, and Unix; and version 7.1.3 of Reader and Acrobat for Windows and Macintosh. The vulnerabilities could cause the applications to crash and could allow an attacker to take control of a user's computer.

Adobe recommends that people update to Adobe Reader 9.2 and Acrobat 9.2, or Acrobat 8.1.7 or Acrobat 7.1.4. For Adobe Reader users who cannot update to Adobe Reader 9.2, Adobe has provided the Adobe Reader 8.1.7 and Adobe Reader 7.1.4 updates.

One of the updates addresses a hole that Trend Micro says has been exploited by a Trojan horse that arrives as a PDF file containing malicious JavaScript. That exploit affects Microsoft Windows 98, ME, NT, 2000, XP, and Server 2003, according to Trend Micro.

"All users of Adobe Reader or Acrobat will need to update their software with today's release because these updates include fixes for the most critical kind of bugs," said Andrew Storms, director of security operations at nCircle.

This is Adobe's second quarterly security update for Adobe Reader and Acrobat.

Also on Tuesday, Microsoft issued a security advisory with a record number of bulletins, including the first fixes for critical holes in Windows 7.

Originally posted at InSecurity Complex
Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
Recent posts from Security
Log in with your face
See what's under McAfee's new interface
26 Windows, Office holes patched in 13 bulletins
McAfee: Spammers exploiting more news stories
Microsoft, Google split over browser bug bounty
Verizon temporarily blocks some 4chan sites
Security software maker Vitamin D exits beta
China breaks up Black Hawk hacking ring
Add a Comment (Log in or register) (9 Comments)
  • prev
  • next
by baconstang October 13, 2009 1:14 PM PDT
Not until the 4th paragraph is it mentioned that the exploits affect only Windows. Couldn't CNET move the part about what systems are affected to the first paragraph. You still get the page hits, but users of other systems wouldn't have to waste their time reading through the article.
Reply to this comment
by Perry_Clease October 13, 2009 1:46 PM PDT
To be fair I have read on several websites that there was potential for the exploit on other OSs. How much potential i don't know, I am an artist not a programmer. I am running Snow Leopard and my Adobe Updater is currently downloading updates to Acrobat and Reader 9.
by baconstang October 13, 2009 2:12 PM PDT
I was wrong, and just finished installing the update on my MacBook. <br />On many articles about exploits, my point still stands. Usually you have to click on the article and read well into it before it mentions that it only affects Windows.
by db32--2008 October 15, 2009 9:56 AM PDT
I'm not trying to be rude, but how valuable is 15 seconds of your time? You probably spent longer typing out your responses.
by baconstang October 13, 2009 1:18 PM PDT
My bad, missed the mention in the second paragraph. Sorry, I've got a horrible cold.
Reply to this comment
by Perry_Clease October 13, 2009 2:21 PM PDT
My wife is just getting over one, a cold and not the flu.<br /><br />Take care.
by db32--2008 October 15, 2009 9:58 AM PDT
I'm not trying to be rude, but how valuable is 15 seconds of your time? You probably spent longer typing out your responses.
Reply to this comment
by rashinal October 17, 2009 8:51 AM PDT
baconstang's comment may have been misplaced with regards to this particular article, but I agree.. a "news" article should convey the most important facts first.. right up front.. and this is often not the case in articles of this nature. What is most important about attacks, exploits, vulnerabilities, is what platforms and versions are affected. Then I know if I need to read on...
Reply to this comment
by deniceels October 18, 2009 12:45 AM PDT
I think being in the 3rd line of the article, abeit 2nd paragraph, is front enough to be upfront. Infact, after they introduced what was done, it went on to mention the platforms that are updated before going into details is there to read subsequently.
(9 Comments)
  • prev
  • next
advertisement

Google's social side aims for some Buzz

Facebook and Twitter are the darlings of the social-media world, not Google--which hopes to change that with Buzz, betting it can organize your online social life.

Watching the birth of a gaming start-up

Stewart Butterfield and his friends are back at it with a new company. CNET's Daniel Terdiman was given exclusive, behind-the-scenes access as they built it from scratch.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right