[ news_security_news ] Adobe Patches Several Reader Issues
David Utter Staff Writer
2008-02-11
Security News RSS Feed
Users of Adobe Reader or Acrobat likely witnessed updates arrive on their computers as Adobe pushed out security fixes.
Active exploits in the wild for stack-based buffer overflows prompted Adobe to issue updates for its Reader and Acrobat products. Improper input validation in several JavaScript methods received the blame for this, according to an advisory from iDefense.
Adobe said version 7.0.9 of Acrobat and Reader, and earlier versions, also suffer from the buffer overflow vulnerability. The company recommended updating to version 8.1.2 to mitigate the threat.
The 8.1.2 release also addressed a remote exploitation of an insecure method problem in a JavaScript library in Acrobat and Reader. A third fixed issue focused on potential remote exploitation of an unsafe library path.
"Adobe is planning to release an update to Adobe Reader and Acrobat 7 to resolve the relevant security issues," the company said in its advisory. "A security bulletin will be published on http://www.adobe.com/support/security as soon as that update is available."
About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.
More news_security_news Articles
Security News RSS Feed
|
|