-=PCTechTalk=- Flash, Acrobat & Acrobat Reader security alert

  • From: Gman <gman.pctt@xxxxxxxxx>
  • To: "PCTechTalk Group <FreeLists>" <PCTechTalk@xxxxxxxxxxxxx>
  • Date: Thu, 26 Feb 2009 11:42:26 -0500

Important info for those who choose to continue using Adobe's Acrobat Reader 
as well as those who use the full Acrobat authoring program.  This security 
article also contains info on Adobe's Flash add-on that affects all users, 
regardless of browser preference.


From Windows Secrets:
********************************
Watch out for zero-day attack on Adobe apps

Expect to see arrive on your desktop shortly a patch for a security hole 
that affects Adobe Flash Player versions 10.0.12.36 and earlier, as 
documented in Adobe's security bulletin 
(http://www.adobe.com/support/security/bulletins/apsb09-01.html). Then be 
prepared on Mar. 11 to apply updates for Adobe's Acrobat and Reader 
software. An exploit currently making the rounds takes advantage of Adobe's 
ability to use JavaScript.

Adobe's report indicates that the glitch affects versions 9 and earlier of 
Adobe Reader and Acrobat. At this time, it appears that antivirus vendors 
have been able to keep up with the risks, but to play it safe, do the 
following in Reader and Acrobat. Click Edit, Preferences; select JavaScript 
in the left pane; and uncheck Enable Acrobat JavaScript.

You can also disable JavaScript in Acrobat and Reader by running a little 
batch file. You can download this file from the PhishLabs blog 
(http://www.phishlabs.com/blog/archives/122), though I think the 
instructions for disabling JavaScript within the program itself are much 
easier and just as effective.

To date, this vulnerability appears to have been targeted only sparingly by 
virus writers. Sometimes, however, being safe is better than being sorry. It 
doesn't appear that the alternative PDF readers, CutePDF and Foxit Reader, 
are vulnerable to these attacks at present.

********************************

Stay safe!

Peace,
Gman
http://www.bornagainamerican.org

"The only dumb questions are the ones we fail to ask"

---------------------------------------------------------------
Please remember to trim your replies (including this sentence and everything 
below it) and adjust the subject line as necessary.

To subscribe, unsubscribe or modify your email settings:
//www.freelists.org/webpage/pctechtalk

To access our Archives:
http://groups.yahoo.com/group/PCTechTalk/messages/
//www.freelists.org/archives/pctechtalk/

To contact only the PCTT Mod Squad, write to:
pctechtalk-moderators@xxxxxxxxxxxxx

To join the PCTableTalk off-topic group, send a blank email to:
pctabletalk+subscribe@xxxxxxxxxxxxxxxx
---------------------------------------------------------------

Other related posts:

  • » -=PCTechTalk=- Flash, Acrobat & Acrobat Reader security alert - Gman