Just weeks after patching a critical flaw, Adobe Systems is rushing out another patch for its Reader and Acrobat software. The company also patched a critical issue in Flash Player Thursday.
The Flash Player flaw could be used by an attacker to trick a Web browser into doing things that it shouldn't, but it's not what is known as a remote-code execution flaw. This means it can't be used to directly install unauthorized software on a victim's computer, said Brad Arkin, Adobe's director of product security and privacy.
If the bug is exploited, "the attacker would be able to execute a general class of cross-site request forgery type of attacks," Arkin said. Adobe rates the issue as "critical."
Normally Adobe patches Reader and Acrobat in quarterly security updates, but Adobe is being forced to rush out next Tuesday's fix because these products are also susceptible to the Flash Player flaw, Arkin said. "We decided that we wanted to get the update for Flash Player out to users as soon as possible," he said. "We didn't want to wait any extra time to do a coordinated release."
In theory, hackers could learn about the bug by looking at the Flash Player patch and then use that information to attack Reader and Acrobat, but Adobe is giving them just a five-day window to complete this work. At present, Adobe isn't aware of any attacks that exploit this Flash Player bug, Arkin said.
Users who are worried about the Flash Player bug being exploited in Reader can mitigate the threat by opening documents outside of the browser, Arkin said.
Next week's Reader and Acrobat update will also patch another undisclosed issue in the PDF-reading software, he added.
The flaws affect Windows, Mac and Unix platforms.
Adobe's security has come under scrutiny over the past year as attackers have increasingly leveraged Reader and Acrobat flaws to hack into computers. Because Reader is installed on almost all desktop computers, a well-crafted Reader attack can affect more victims than one that targets Internet Explorer or Firefox.
Adobe's next scheduled Reader and Acrobat update is due April 13.
Also on Thursday, Adobe patched an "important" bug in its open-source BlazeDS messaging software.
Latest on Vulnerabilities
- Adobe to rush out another critical Reader patch
- Why traditional security doesn't work for SOA
- Google hack raises serious concerns, US says
- Adobe warns of Reader, Acrobat attack in the wild
- After code is released, Adobe Illustrator fix due Jan 8
- With new attack released, Adobe to patch next week
- Metasploit releases IE attack, but it's unreliable
- Attacks appear imminent as IE exploit is improved
- Microsoft issues security advisory on IE vulnerability
- New attack fells Internet Explorer
Security Essentials
- Good security in recessionary times
- Security ROI: Fact or Fiction?
- NetWitness releases free version of security software
- Study: critical infrastructure often under cyberattack
- Crooks can make $5M a year shilling fake security software
- Sun exec: IT security should follow business needs
- Clumsy staff more dangerous than hackers: survey
- When the watchdog is the underdog
- Mafiaboy grows up; a hacker seeks redemption
- Ouch! Security pros' worst mistakes
- Development Team Manager / Tech Lead17/02/2010
Information Technology and Internet
I.T. & T
Out of this world senior management career opp for a seasoned development manager/tech lead professional in a top 5 Sydney-based Digital Agency! - Enterprise Infrastructure Architect - Strategy focus17/02/2010
Other
I.T. & T
Infrastructure Architect - Melbourne CBD - strategic improvement phase - great team culture - Senior Business Analyst17/02/2010
Other
I.T. & T
Senior Business Analyst - Java Developer - up to 9 months contract! (F4)17/02/2010
Other
I.T. & T
Java Developer - up to 9 months contract! (F4) - Senior Business Analyst, Financial Services (S33)17/02/2010
Other
I.T. & T
Senior Business Analyst, Financial Services (S33) - SQL DBA - Sydney - Permanent17/02/2010
Other
I.T. & T
SQL DBA - Sydney - Permanent - Voice/Intel Consultant - Network Design Specialist - Leading IT Provid17/02/2010
Other
I.T. & T
Voice/Intel Consultant - Network Design Specialist - Leading IT Provid
Whitepapers
- A Solid Foundation for Service-Oriented Architecture
- Legacy Tools: Not Built for Today’s Helpdesk
- How Small Businesses Worldwide Use Communications to Thrive in the New Economy
- Computerworld Strategy Guide: Business Intelligence
- A Fundamental Failure | The legal risks of neglecting an IT security assessment
TechWorld Blogs
Recent blog posts
- Google goes for more markets: too much too quickly?
- Talk about mobile computing
- iPad arrives: can Apple crack the tablet?
- Linux.conf.au 2010 kicks off in New Zealand
- VMware jumps further into SaaS with Zimbra
- Amarok 2.2.2 released – rock on!
- Happy Nexus Year
- So long 2009, and thanks for another decade in tech
- KDE 4.4 enters beta, bring on mainstream computing
- Chromium OS source released: another way of thinking
Recent comments
- timiing
1 hour 18 min ago - whats an android phone?
3 hours 53 min ago - What a sludge mess
4 hours 10 min ago - New Phones
11 hours 16 min ago - wheresmyshow
1 day 4 hours ago - a sling "seems to be in
1 day 21 hours ago - SEO accounts for 70% of a websites' traffic
2 days 10 hours ago - Good news for X-box fans
2 days 20 hours ago - Windows7 Family Pack availability
2 days 21 hours ago - wow....
3 days 9 hours ago - HP NOTE BOOK dv 9000/ 9311
3 days 19 hours ago - The ad says that while toting
4 days 1 hour ago - about the new iphone
4 days 19 hours ago - target market, promotions, price etc
5 days 3 hours ago - I've heard people say that
5 days 5 hours ago - Virgin Mobile
5 days 9 hours ago - I agree with this...kyocera
5 days 10 hours ago - Great ..
5 days 17 hours ago - Open Broadcom?
6 days 2 hours ago - How this case pans out will
1 week 3 hours ago
Comments
Post new comment