Adobe explains PDF patch delay
Emergency patch would have postponed Jan.'s enterprise-oriented update
Computerworld - Adobe chose to wait until mid-January to patch a critical PDF bug because issuing an emergency update would have disrupted its quarterly security update schedule, the company said today.
Unless users apply one of the workarounds that Adobe's suggested, the decision will leave systems open to attack until Jan. 12, when the patch is released. According to several security firms, the flaw has been in use by criminals since at least Nov. 20. Adobe only found out Monday that the vulnerability in its Reader and Acrobat applications was being actively exploited.
"We had two options," said Brad Arkin, Adobe's director for product security and privacy, describing the company's conundrum. "We could do an out-of-cycle update for this one vulnerability, and get out something as fast as we could, or try to work it into the Jan. 12 release."
The former, which would have gotten a fix for the current zero-day to users within "two or three weeks," said Arkin, had a down side. By pulling engineers into the Reader/Acrobat patch job, Adobe would have had to push back the already-scheduled Jan. 12 update into at least February.
"There really wasn't a third option," Arkin claimed, explaining that it would have been impossible for Adobe to do both -- rush an emergency patch to people by the end of December, then turn around and still meet the Jan. 12 deadline for updates already in progress.
"With a lot of work over the holidays, we decided we could get the patch into the code base for the Jan. 12 release, and still make that," Arkin said.
Helping to make Adobe's decision, Arkin argued, was the workaround it urged on users in a security advisory published late Monday. "We think we have an effective mitigation, the JavaScript Blacklist, which we included with the October security update."
JavaScript Blacklist Framework is a new feature that Adobe added to Reader and Acrobat that lets users and enterprise administrators lock down specific JavaScript functions, or APIs (application programming interfaces) to protect machines against known attacks without disabling all JavaScript functionality.
"This is the first time that we're using JavaScript Blacklist as a mitigation," said Arkin. Internal tests confirmed that by switching off the vulnerable API, users would be safe from the in-the-wild exploits making the rounds.
Adobe also talked with "lots of customers" to get their take on which path the company should take. "Having two updates, one this month for the vulnerability being exploited, then another roll-out, maybe in February, would be a lot more expensive for organizations than just one update [on Jan. 12]," Arkin said he concluded from those conversations.
Timing also played a part in Adobe's decision to delay the patch. The upcoming holidays, for example, were a concern to businesses, which weren't sure if they could test and deploy a rush patch before their workers returned to the job on Jan. 4. Also in play, said Arkin: The looming Jan. 12 deadline.
Last May, Adobe revamped the security process for its PDF viewing and editing applications, a move made after critics blasted the company for its slow patching process several months earlier. Adobe promised to speed up its patch work, go over old code to find flaws and release security updates for Reader and Acrobat every three months.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Driving Secure Enterprise File Sharing and Syncing in the Enterprise
- GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
- The Enterprise File Sharing Option
- Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
- Security Strategies to Virtualizing Internet-Facing Applications
- The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
- Cloud Security Planning Guide
- Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
- Cloud Security Vendor Round Table
- This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions... All Security White Papers
- Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute - Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
- Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
- FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
- BlackBerry PlayBook OS 2.0 Security Overview
- The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
- BlackBerry NFC Security Overview
- The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts