site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
1789
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
AuthorAll Replies


chachazz
Premium
join:2003-12-14
kudos:3
Reviews:
·TELUS

1 edit

Security Updates available for Adobe Reader and Acrobat

Release date: May 12, 2009
Vulnerability identifier: APSB09-06
CVE number: CVE-2009-1492, CVE-2009-1493
Platform: All Platforms

Summary
A critical vulnerability has been identified in Adobe Reader 9.1 and Acrobat 9.1 and earlier versions. This vulnerability (CVE-2009-1492) would cause the application to crash and could potentially allow an attacker to take control of the affected system. A second vulnerability has also been reported that appears to affect Adobe Reader for UNIX only (CVE-2009-1493).

Adobe recommends users of Adobe Reader 9.1 and Acrobat 9.1 and earlier versions update to Adobe Reader 9.1.1 and Acrobat 9.1.1. Adobe recommends users of Acrobat 8 update to Acrobat 8.1.5, and users of Acrobat 7 update to Acrobat 7.1.2. For Adobe Reader users who can’t update to Adobe Reader 9.1.1, Adobe has provided the Adobe Reader 8.1.5 and Adobe Reader 7.1.2 updates.

Affected software versions
Adobe Reader 9.1 and earlier versions.
Adobe Acrobat Standard, Pro, and Pro Extended 9.1 and earlier versions.

Solution
Adobe Reader
Adobe Reader users on Windows can find the appropriate update here:
»www.adobe.com/support/downloads/···=Windows.

Adobe Reader users on Macintosh can find the appropriate update here:
»www.adobe.com/support/downloads/···acintosh.

Adobe Reader users on UNIX can find the appropriate update here:
»www.adobe.com/support/downloads/···orm=Unix.

Acrobat
Acrobat Standard, Pro and Pro Extended users on Windows can find the appropriate update here:
»www.adobe.com/support/downloads/···=Windows

Acrobat 3D users on Windows can find the appropriate update here:
»www.adobe.com/support/downloads/···=Windows

Acrobat Pro users on Macintosh can find the appropriate update here:
»www.adobe.com/support/downloads/···acintosh

Severity rating
Adobe categorizes this as a critical update and recommends that users apply the update for their product installations.

A critical vulnerability has been identified in Adobe Reader 9.1 and Acrobat 9.1 and earlier versions. This vulnerability (CVE-2009-1492) would cause the application to crash and could potentially allow an attacker to take control of the affected system. A second vulnerability has also been reported that appears to affect Adobe Reader for UNIX only (CVE-2009-1493). These issues are remotely exploitable.

Adobe recommends users of Acrobat and Adobe Reader update their product installations to versions 9.1.1, 8.1.5, or 7.1.2 using the instructions above to protect themselves from potential vulnerabilities. Adobe expects to make available Adobe Reader 7 and Acrobat 7 updates for Macintosh before the end of June. This document will be updated to specify the expected date of these updates once available.

Link to this Security Bulletin
--
Gladiator Security Forum: www.gladiator-antivirus.com/

mysec
Premium
join:2005-11-29
kudos:4

As everyone who follows these things knows, this vulnerability has been unpatched for more than a week.

Adobe Reader/Acrobat Critical Vulnerability
»isc.sans.org/diary.html?storyid=6334
Published: 2009-05-04

Adobe expects to make available Windows updates ... Macintosh updates ... Unix updates by May 12th, 2009.

Quiz for the day:

QUESTION FOR WINDOWS USERS

What are the four ways a user with the Adobe Reader was protected even though the vulnerability was unpatched?

ANSWER

If the user has any one of these four protections in place, the exploit fails:

• Javascript disabled

• Acrobat Plugin disabled, or "Show PDF file in browser" unchecked in the Reader Preferences

• Firewall with outbound protection

• Execution Prevention to block the installation of the malware.


REFERENCE

»www.urs2.net/rsj/computing/tests/pdf

EXTRA CREDIT

I used Firefox to demonstrate the success of the attack. Does this mean that it is a Firefox exploit? Why?

----
rich


trparky
Apple... YUM
Premium,MVM
join:2000-05-24
Cleveland, OH
kudos:1

It works via Firefox because Firefox is loading the Acrobat DLL into itself to display the PDF and since the PDF was crafted to exploit Acrobat... well you get the idea.
--
Tom



iam x
Sungazer
Premium
join:2005-02-23

reply to chachazz
im glad im using nitropdf and foxit pdf reader.



Its a Secret
Please speak into the microphone
Premium
join:2008-02-23
Da wet coast
kudos:3

reply to chachazz
FYI, I've just updated it and every setting remains the same; nothing was broken. YMMV.



tux789

@anonymouse.org

reply to mysec

said by mysec:

QUESTION FOR WINDOWS USERS

What are the four ways a user with the Adobe Reader was protected even though the vulnerability was unpatched?
this question is valid for Linux, too

Jrb2
Premium
join:2001-08-31
kudos:3

reply to chachazz
Thanks chachazz !



onDvine
Don't litter. Spay-neuter.
Premium
join:2005-01-29
So. CA, USA
kudos:7
Reviews:
·Verizon Online DSL

reply to chachazz
Thanks, chachazz See Profile.

When a user has more than one of the four protections in place that cause the exploit to fail there's no compelling reason to update, is there?
--
"... life goes not backward nor tarries with yesterday. ..." ▪Kahlil Gibran's The Prophet


mysec
Premium
join:2005-11-29
kudos:4

reply to trparky

said by trparky:

It works via Firefox because Firefox is loading the Acrobat DLL into itself to display the PDF and since the PDF was crafted to exploit Acrobat... well you get the idea.

I get it! Another clue is that it is the Acrobat Reader that is connecting out for the malware, and not Firefox - as indicated in my screenshot of the firewall alert.

said by tux789 :

this question is valid for Linux, too

Thanks - glad to know that.

said by onDvine:

When a user has more than one of the four protections in place that cause the exploit to fail there's no compelling reason to update, is there?

That's how I see it - I've got all four protections in place. I've been using version 6 for years with all of the unnecessary plugins removed! A good solution if all you want is just the basic Reader.

----
rich

Sunday, 12-Feb 00:44:49 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online! © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics