Data Storage Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Information for Data Storage Professionals
Monday, September 6th 
Home
Storage Hardware
Storage Software
Storage Networks
Storage Trends
Next-Gen Storage
Data Security
DST Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement
Data Security

Adobe Warns of PDF Woes, But Fix Is on the Way

Adobe Warns of PDF Woes, But Fix Is on the Way
October 9, 2009 2:42PM

Bookmark and Share
Adobe Reader and Adobe Acrobat seem to be the latest victims of the hacker and cracker set, with new vulnerabilities identified this week. Fortunately, Adobe seems to have a quick fix for the Reader and Acrobat security troubles, and will have an update available within days. In the meantime, experts warn businesses and users to beware.


Adobe issued a security advisory Thursday about vulnerabilities in its Adobe Reader and Acrobat products. The company labeled the vulnerabilities critical, reflecting the highest level of severity, and indicated that software updates will be available on Tuesday, Oct. 13.

A number of Adobe products and all platforms are involved. The update will cover Adobe Reader 9.1.3, Acrobat 9.1.3, Adobe Reader 8.1.6, and Acrobat 8.1.6 for Windows, Macintosh and UNIX. The updates also will cover Adobe Reader 7.1.3 and Acrobat 7.1.3 for Windows and Macintosh.

If unpatched, malicious code carried in downloaded PDF documents can be executed and damage can be caused by viruses, Trojans or other malware if the file is opened by the user. Attacks have been seen in the wild targeting Windows using Adobe Reader and Acrobat 9.1.3. The advisory said that computers with Data Execution Prevention (DEP) enabled on the Windows Vista operating system are not impacted.

The alert also said the variants observed in the field are neutralized if JavaScript is disabled. However, the company warned that the base vulnerability may be used for exploits that don't involve JavaScript.

So Far, Limited Impact

Brad Arkin, director of product security and privacy for Adobe, said the company has information Relevant Products/Services on "about a half-dozen" attacks. He said next Tuesday's security update is the second of two on the company's schedule. The first was released June 9. A response to the attacks has been folded into the second update, he said.

Ryan Naraine, a security evangelist for Kaspersky Labs, said the attacks seem to be aimed at corporate and business types. "This is a big deal for two reasons. One is that it is not patched yet, and two is that there already are attacks happening. That means that malicious hackers got hold of this vulnerability before Adobe did."

Targeting Adobe

Researchers agree that Adobe is a big target. Ben Greenbaum, senior research manager for Symantec Security Response, said Adobe is now squarely in the limelight, at least as far as crackers are concerned.

"I wouldn't say it is becoming a larger target, but it certainly has been a large target for a while. By that, I mean the past two or three years."

Naraine added that Adobe has had a busy year. "This is the fourth [attack] this year," he said. "That's not every week or every other week, but four times per year is considered a lot."

Greenbaum said there is no special protection against contaminated PDF documents. Best-practice security should be exercised, he said, including common sense, making sure that security software is up to date, and automatic updates are turned on. He joined the others in urging users to take advantage of the patch as soon as it becomes available on Tuesday.

Tell Us What You Think
Comment:

Name:

Advertisement



 Data Security
1. Consumer Watchdog Attacks Google
2. Spammers Take Over Apple's Ping
3. VMware Reinforces 'IT as a Service'
4. Hackers Invade iTunes Accounts
5. Security Threats a Record, IBM Says


advertisement


 Most Popular Articles
1. Dell Buys Virtualization Storage Provider 3PAR
2. Patch Fixes SMB Attack That Could Come from Within
3. Intel Will Acquire McAfee To Secure Online Computing
4. Apple Issues iOS Patch To Block Hacker Bonanza
5. Intel's Deal for 'Buggy Whip' Maker McAfee Will Impact IT

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  HP vs. Dell: Behind the Showdown
  Consumer Watchdog Attacks Google
  Spammers Take Over Apple's Ping
  HP Wins 3PAR at $2.4B as Dell Quits
  Data Storage Advances Are Looming

 Technology Marketplace
Compliance
Stand out from other IS Professionals and increase your earning potential.®.
Manage limitless content today—read EMC’s 15-minute guide to ECM.
 
Data Storage
Isilon scale-out storage is simple. Simple is smart.
 
Digital Life
IT PROS: Receive $10 in rewards to complete a 15 min. survey.
 
Enterprise I.T.
Stand out from other IS Professionals and increase your earning potential.®.
IT PROS: Receive $10 in rewards to complete a 15 min survey.
 
Enterprise Software
Manage limitless content today—read EMC’s 15-minute guide to ECM.
 
Mobile Gadgets
White Paper The Motorola ES400: Desktop power in a pocket-sized device
 
Mobile Industry News
The Motorola ES400: Desktop power in a pocket-sized device.
 
Mobile Phones
The Motorola ES400: Desktop power in a pocket-sized device.
 
Navigation
Data Storage Today
Home/Top News | Storage Hardware | Storage Software | Storage Networks | Storage Trends | Next-Gen Storage | Data Security
DST Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 Data Storage Today. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.