 Reviews:
·TELUS
1 edit | Security Updates available for Adobe Reader and Acrobat Release date: May 12, 2009 Vulnerability identifier: APSB09-06 CVE number: CVE-2009-1492, CVE-2009-1493 Platform: All Platforms
Summary A critical vulnerability has been identified in Adobe Reader 9.1 and Acrobat 9.1 and earlier versions. This vulnerability (CVE-2009-1492) would cause the application to crash and could potentially allow an attacker to take control of the affected system. A second vulnerability has also been reported that appears to affect Adobe Reader for UNIX only (CVE-2009-1493).
Adobe recommends users of Adobe Reader 9.1 and Acrobat 9.1 and earlier versions update to Adobe Reader 9.1.1 and Acrobat 9.1.1. Adobe recommends users of Acrobat 8 update to Acrobat 8.1.5, and users of Acrobat 7 update to Acrobat 7.1.2. For Adobe Reader users who cant update to Adobe Reader 9.1.1, Adobe has provided the Adobe Reader 8.1.5 and Adobe Reader 7.1.2 updates.
Affected software versions Adobe Reader 9.1 and earlier versions. Adobe Acrobat Standard, Pro, and Pro Extended 9.1 and earlier versions.
Solution Adobe Reader Adobe Reader users on Windows can find the appropriate update here: »www.adobe.com/support/downloads/···=Windows.
Adobe Reader users on Macintosh can find the appropriate update here: »www.adobe.com/support/downloads/···acintosh.
Adobe Reader users on UNIX can find the appropriate update here: »www.adobe.com/support/downloads/···orm=Unix.
Acrobat Acrobat Standard, Pro and Pro Extended users on Windows can find the appropriate update here: »www.adobe.com/support/downloads/···=Windows
Acrobat 3D users on Windows can find the appropriate update here: »www.adobe.com/support/downloads/···=Windows
Acrobat Pro users on Macintosh can find the appropriate update here: »www.adobe.com/support/downloads/···acintosh
Severity rating Adobe categorizes this as a critical update and recommends that users apply the update for their product installations.
A critical vulnerability has been identified in Adobe Reader 9.1 and Acrobat 9.1 and earlier versions. This vulnerability (CVE-2009-1492) would cause the application to crash and could potentially allow an attacker to take control of the affected system. A second vulnerability has also been reported that appears to affect Adobe Reader for UNIX only (CVE-2009-1493). These issues are remotely exploitable.
Adobe recommends users of Acrobat and Adobe Reader update their product installations to versions 9.1.1, 8.1.5, or 7.1.2 using the instructions above to protect themselves from potential vulnerabilities. Adobe expects to make available Adobe Reader 7 and Acrobat 7 updates for Macintosh before the end of June. This document will be updated to specify the expected date of these updates once available.
Link to this Security Bulletin -- Gladiator Security Forum: www.gladiator-antivirus.com/
|
|
|
|
 mysecPremium join:2005-11-29 kudos:4 | As everyone who follows these things knows, this vulnerability has been unpatched for more than a week.
Adobe Reader/Acrobat Critical Vulnerability »isc.sans.org/diary.html?storyid=6334 Published: 2009-05-04
Adobe expects to make available Windows updates ... Macintosh updates ... Unix updates by May 12th, 2009. Quiz for the day:
QUESTION FOR WINDOWS USERS
What are the four ways a user with the Adobe Reader was protected even though the vulnerability was unpatched?
ANSWER
If the user has any one of these four protections in place, the exploit fails:
• Javascript disabled
• Acrobat Plugin disabled, or "Show PDF file in browser" unchecked in the Reader Preferences
• Firewall with outbound protection
• Execution Prevention to block the installation of the malware.
REFERENCE
»www.urs2.net/rsj/computing/tests/pdf
EXTRA CREDIT
I used Firefox to demonstrate the success of the attack. Does this mean that it is a Firefox exploit? Why?
---- rich |
|
 trparkyApple... YUMPremium,MVM join:2000-05-24 Cleveland, OH kudos:1 | It works via Firefox because Firefox is loading the Acrobat DLL into itself to display the PDF and since the PDF was crafted to exploit Acrobat... well you get the idea. -- Tom |
|
 iam xSungazerPremium join:2005-02-23 ॐ | reply to chachazz im glad im using nitropdf and foxit pdf reader. |
|
 Its a SecretPlease speak into the microphonePremium join:2008-02-23 Da wet coast kudos:3 | reply to chachazz FYI, I've just updated it and every setting remains the same; nothing was broken. YMMV. |
|
 | reply to mysec said by mysec:QUESTION FOR WINDOWS USERSWhat are the four ways a user with the Adobe Reader was protected even though the vulnerability was unpatched? this question is valid for Linux, too |
|
 Jrb2Premium join:2001-08-31 kudos:3 | reply to chachazz Thanks chachazz ! |
|
 onDvineDon't litter. Spay-neuter.Premium join:2005-01-29 So. CA, USA kudos:7 Reviews:
·Verizon Online DSL
| reply to chachazz Thanks, chachazz . 
When a user has more than one of the four protections in place that cause the exploit to fail there's no compelling reason to update, is there? -- "... life goes not backward nor tarries with yesterday. ..." ▪Kahlil Gibran's The Prophet |
|
 mysecPremium join:2005-11-29 kudos:4 | reply to trparky said by trparky:It works via Firefox because Firefox is loading the Acrobat DLL into itself to display the PDF and since the PDF was crafted to exploit Acrobat... well you get the idea. I get it! Another clue is that it is the Acrobat Reader that is connecting out for the malware, and not Firefox - as indicated in my screenshot of the firewall alert.
said by tux789 :
this question is valid for Linux, too Thanks - glad to know that.
said by onDvine:When a user has more than one of the four protections in place that cause the exploit to fail there's no compelling reason to update, is there? That's how I see it - I've got all four protections in place. I've been using version 6 for years with all of the unnecessary plugins removed! A good solution if all you want is just the basic Reader.
---- rich |
|