Adobe patches Reader, Acrobat and Flash

By Tim Conneally | Published November 6, 2008, 10:42 AM

On Tuesday, Adobe Systems Inc. issued patches for a five-month old vulnerability in Reader and Acrobat 8.1.2, and today, six critical patches were released for Flash Player 9.

JavaScript vulnerabilities in older versions of Acrobat and Reader could allow remote code execution if not properly patched. This is the fifth update to Reader this year that addresses JavaScript issues. NCircle security expert Andrew Storms told Computerworld in June that Adobe's repeated JavaScript bugs amounted to an epidemic. "Since JavaScript has been a target for so many years, why hasn't Adobe flushed out these vulnerabilities already?" he questioned.

This morning, Adobe issued critical patches for its ubiquitous Flash Player (v. 9.0.124.0), addressing issues that could lead to DNS rebinding attack, HTML injection, or potential information disclosure. Adobe has a page that tells users which version of Flash they're using, to simplify the security update process.

With all of the patches, Adobe recommends that users upgrade to the latest software versions: Adobe Reader 9, Acrobat 9, and Flash 10.

Comments

View comments by with a score of at least

Fortunately Vista x64 comes w/o flash :)

Score: 0

|

Why javascript is in a document viewer was a question I was asking years ago.

This security problem will never go away, and Adobe will have a nightmare on its hands.

Score: 0

|

No , Because Flash ten is ****ed.

Score: 0

|

It's the US vs. the EU over Oracle+Sun and the meaning of 'open source'

Now that the EU is a virtual country, the US Justice Dept. is taking a stand in favor of its view -- and against the EC's -- that MySQL will survive under Oracle.

Qualcomm: $1.3 billion Samsung licensing deal unrelated to fair trade violations

Samsung has come to a 15-year licensing deal with Qualcomm over 3G and 4G wireless technology.

Firefox turns five: Thanks for giving us a choice

Carmi Levy | Wide Angle Zoom: No longer the phoenix rising from the ashes, Mozilla has carried on more than just Netscape's legacy.

If Microsoft sites lead time online, pigs can fly

How can people spend more time at Microsoft sites, when the measure of success is Windows Live Messenger, which sits on the desktop?

European ministers approve watered-down 'neutral net' language

The latest provision in the EU's telecoms regulatory framework would let businesses cancel individuals' Internet access, if they go to court first.

Snow Leopard and Windows 7 still can't crack the netbook problem

Apple has killed Atom support in OS X 10.6.2 and Windows 7 Starter Edition is stripped of "basic" functionality.

Microsoft's Top 3 advances in Exchange Server 2010

The latest round of changes launched today will impact how admins deliver services to e-mail recipients, and how much companies will pay along the way.

Nokia's 'limited number' of recalled chargers exceeds 14 million

Today, the Finnish phone maker has begun a recall of mobile phone chargers that are a shock hazard.

Ubuntu 9.10 upgraders report frustration

For those Wine aficionados out there, beware of the remote possibility that your Linux system could be infected by Windows-seeking malware.

Supreme Court considers patentability of abstract methods today

Can software that executes a formula for a business process qualify for federal patents? An appeals court already said no, and inventors are making their case.

Thanks, iPhone: Google buys mobile advertiser AdMob for $750 million

AdMob came to thrive thanks to the iPhone's popularity, now Google has bought it.