Adobe hit by second vulnerability

Posted by   Virus Bulletin on   Dec 8, 2006

More document software security worries.

PDF software giant Adobe has released details of its second vulnerability in little over a week. The first, which was discovered in the company's PDF reader itself, was soon discovered to be less serious than initially believed; the second, a buffer overflow problem in the Adobe Download Manager, is described as 'highly critical' by security watchers at Secunia.

The earlier problem, affecting Adobe Acrobat 7 and Adobe Reader 7, was first thought to render the system vulnerable to remote access, but on further investigation by Adobe it was discovered that the most serious danger was of a crash in the product (see the Secunia alert here).

The latest problem, first spotted by researchers at eEye Digital Security and TippingPoint's Zero Day Initiative, was reported to Adobe almost a month ago, and is now being disclosed in the wake of a fix release. The vulnerability could be used by malicious sites to gain remote system access, and all Adobe users are advised to ensure they update to the latest version. Full instructions are available from Adobe, here.

The eEye announcement is here, and one from the Zero Day Initiative here.

Posted on 08 December 2006 by Virus Bulletin

 Tags

twitter.png
fb.png
linkedin.png
hackernews.png
reddit.png

 

Latest posts:

In memoriam: Prof. Ross Anderson

We were very sorry to learn of the passing of Professor Ross Anderson a few days ago.

In memoriam: Dr Alan Solomon

We were very sorry to learn of the passing of industry pioneer Dr Alan Solomon earlier this week.

New paper: Nexus Android banking botnet – compromising C&C panels and dissecting mobile AppInjects

In a new paper, researchers Aditya K Sood and Rohit Bansal provide details of a security vulnerability in the Nexus Android botnet C&C panel that was exploited in order to gather threat intelligence, and present a model of mobile AppInjects.

New paper: Collector-stealer: a Russian origin credential and information extractor

In a new paper, F5 researchers Aditya K Sood and Rohit Chaturvedi present a 360 analysis of Collector-stealer, a Russian-origin credential and information extractor.

VB2021 localhost videos available on YouTube

VB has made all VB2021 localhost presentations available on the VB YouTube channel, so you can now watch - and share - any part of the conference freely and without registration.

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.