Adobe hit by second vulnerability

More document software security worries.

PDF software giant Adobe has released details of its second vulnerability in little over a week. The first, which was discovered in the company's PDF reader itself, was soon discovered to be less serious than initially believed; the second, a buffer overflow problem in the Adobe Download Manager, is described as 'highly critical' by security watchers at Secunia.

Advertise on www.virusbtn.com

The earlier problem, affecting Adobe Acrobat 7 and Adobe Reader 7, was first thought to render the system vulnerable to remote access, but on further investigation by Adobe it was discovered that the most serious danger was of a crash in the product (see the Secunia alert here).

The latest problem, first spotted by researchers at eEye Digital Security and TippingPoint's Zero Day Initiative, was reported to Adobe almost a month ago, and is now being disclosed in the wake of a fix release. The vulnerability could be used by malicious sites to gain remote system access, and all Adobe users are advised to ensure they update to the latest version. Full instructions are available from Adobe, here.

The eEye announcement is here, and one from the Zero Day Initiative here.

08 December 2006

Tags: virus  

 del.icio.us  digg this! digg this

Quick Links

Poll
Does your company allow you to use a personal laptop/mobile device to access company resources?
Yes, it's allowed
Yes, it's actively encouraged
No
I don't know
Leave a comment
View 2 comments

Ciso-Intelligence

VB2012
VB2012 VB2012 will take place 26 - 28 September 2012 at the Fairmont Dallas hotel, Dallas, TX, USA.

Virus Bulletin currently has 225,278 registered users.