Adobe to rush out another critical Reader patch
IDG News Service - Just weeks after patching a critical flaw, Adobe Systems is rushing out another patch for its Reader and Acrobat software. The company also patched a critical issue in Flash Player Thursday.
The Flash Player flaw could be used by an attacker to trick a Web browser into doing things that it shouldn't, but it's not what's known as a remote-code execution flaw. This means it can't be used to directly install unauthorized software on a victim's computer, said Brad Arkin, Adobe's director of product security and privacy.
If the bug is exploited, "the attacker would be able to execute a general class of cross-site request forgery type of attacks," Arkin said. Adobe rates the issue as "critical."
Normally Adobe patches Reader and Acrobat in quarterly security updates, but Adobe is being forced to rush out next Tuesday's fix because these products are also susceptible to the Flash Player flaw, Arkin said. "We decided that we wanted to get the update for Flash Player out to users as soon as possible," he said. "We didn't want to wait any extra time to do a coordinated release."
In theory, hackers could learn about the bug by looking at the Flash Player patch and then use that information to attack Reader and Acrobat, but Adobe is giving them just a five-day window to complete this work. At present, Adobe isn't aware of any attacks that exploit this Flash Player bug, Arkin said.
Users who are worried about the Flash Player bug being exploited in Reader can mitigate the threat by opening documents outside of the browser, Arkin said.
Next week's Reader and Acrobat update will also patch another undisclosed issue in the PDF-reading software, he added.
The flaws affect Windows, Mac and Unix platforms.
Adobe's security has come under scrutiny over the past year as attackers have increasingly leveraged Reader and Acrobat flaws to hack into computers. Because Reader is installed on almost all desktop computers, a well-crafted Reader attack can affect more victims than one that targets Internet Explorer or Firefox.
Adobe's next scheduled Reader and Acrobat update is due April 13.
Also on Thursday, Adobe patched an "important" bug in its open-source BlazeDS messaging software.
- 10 Hot Big Data Startups to Watch
- 11 Unique Uses for Google Glass, Demonstrated by Celebs
- How to Export Your Google Reader Account
- How to Better Engage Millennials (and Why They Aren't Really so Different)
- Telltale signs of ATM skimming
- 20 security and privacy apps for Androids and iPhones
- Big screen con artists: 7 great movies about social engineering
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- How Application Aware Networks Make the Impossible Possible Realizing Business Value and ROI with Application-Aware Network Performance Management
- Enabling Ubiquitous Visibility in Virtualized Environments Enterprises are rapidly adopting virtualization for dynamic service delivery and service management agility. IT challenges already exist in virtual environments and will only...
- The Importance of Performance Management in Software-defined Networking Riverbed Technology and VMware have joined forces to help address these problems and make it easy to deploy and manage VXLAN overlay networks...
- Network Monitoring and Troubleshooting for Dummies The Network Monitoring and Troubleshooting for Dummies Book introduces you to common network performance management (NPM) issues and give you a new way...
- Live Webcast
Virtustream (Vayence) video taking a 3000-Seat SAP Environment to the Cloud - How can public cloud services help your organization reduce costs and increase security for your mission
- Virtustream (Vayence) video taking a 3000-Seat SAP Environment to the Cloud How can public cloud services help your organization reduce costs and increase security for your mission
- Innovation in the Cloud Managing HR and financial information in the modern business requires efficient business practices and technology. All Applications White Papers | Webcasts