-=PCTechTalk=- Flash, Acrobat & Acrobat Reader security alert
- From: Gman <gman.pctt@xxxxxxxxx>
- To: "PCTechTalk Group <FreeLists>" <PCTechTalk@xxxxxxxxxxxxx>
- Date: Thu, 26 Feb 2009 11:42:26 -0500
Important info for those who choose to continue using Adobe's Acrobat Reader
as well as those who use the full Acrobat authoring program. This security
article also contains info on Adobe's Flash add-on that affects all users,
regardless of browser preference.
From Windows Secrets:
********************************
Watch out for zero-day attack on Adobe apps
Expect to see arrive on your desktop shortly a patch for a security hole
that affects Adobe Flash Player versions 10.0.12.36 and earlier, as
documented in Adobe's security bulletin
(http://www.adobe.com/support/security/bulletins/apsb09-01.html). Then be
prepared on Mar. 11 to apply updates for Adobe's Acrobat and Reader
software. An exploit currently making the rounds takes advantage of Adobe's
ability to use JavaScript.
Adobe's report indicates that the glitch affects versions 9 and earlier of
Adobe Reader and Acrobat. At this time, it appears that antivirus vendors
have been able to keep up with the risks, but to play it safe, do the
following in Reader and Acrobat. Click Edit, Preferences; select JavaScript
in the left pane; and uncheck Enable Acrobat JavaScript.
You can also disable JavaScript in Acrobat and Reader by running a little
batch file. You can download this file from the PhishLabs blog
(http://www.phishlabs.com/blog/archives/122), though I think the
instructions for disabling JavaScript within the program itself are much
easier and just as effective.
To date, this vulnerability appears to have been targeted only sparingly by
virus writers. Sometimes, however, being safe is better than being sorry. It
doesn't appear that the alternative PDF readers, CutePDF and Foxit Reader,
are vulnerable to these attacks at present.
********************************
Stay safe!
Peace,
Gman
http://www.bornagainamerican.org
"The only dumb questions are the ones we fail to ask"
---------------------------------------------------------------
Please remember to trim your replies (including this sentence and everything
below it) and adjust the subject line as necessary.
To subscribe, unsubscribe or modify your email settings:
http://www.freelists.org/webpage/pctechtalk
To access our Archives:
http://groups.yahoo.com/group/PCTechTalk/messages/
http://www.freelists.org/archives/pctechtalk/
To contact only the PCTT Mod Squad, write to:
pctechtalk-moderators@xxxxxxxxxxxxx
To join the PCTableTalk off-topic group, send a blank email to:
pctabletalk+subscribe@xxxxxxxxxxxxxxxx
---------------------------------------------------------------
Other related posts:
- » -=PCTechTalk=- Flash, Acrobat & Acrobat Reader security alert - Gman