• Home
  • Et Cetera

Infosecurity.US

Adobe Remediates Acrobat and Reader Vulnerabilities

By Marc Handelman on October 15th, 2009

Adobe Wall

News, overnight, of the large number of vulnerabilities now remediated in Adobe Systems, Inc.’s (NasdaqGS: ADBE) Acrobat and Reader PDF authoring, workflow and reading applications. With twenty-nine discreet patches, the company seems to have lifted itself from the dubious honor of tardy security patch releases. The MITRE CVEs related to these patches are CVE-2007-0048, CVE-2007-0045, CVE-2009-2564, CVE-2009-2979, CVE-2009-2980, CVE-2009-2981, CVE-2009-2982, CVE-2009-2983, CVE-2009-2984, CVE-2009-2985, CVE-2009-2986, CVE-2009-2987, CVE-2009-2988, CVE-2009-2989, CVE-2009-2990, CVE-2009-2991, CVE-2009-2992, CVE-2009-2993, CVE-2009-2994, CVE-2009-2995, CVE-2009-2996, CVE-2009-2997, CVE-2009-2998, CVE-2009-3431, CVE-2009-3458, CVE-2009-3459, CVE-2009-3460, CVE-2009-3461, CVE-2009-3462. More information, including linkage, and a short snippet from the original post at HeiseSecurity appears after the jump.

From HeieseSecurity: “Adobe closes 29 vulnerabilities in Acrobat and Reader“

“Adobe has released updates for its Acrobat and Reader products, closing 29 security vulnerabilities.  The updates include a previously reported critical hole that is already being exploited by attackers. According to Adobe, version 9.1.3 and 8.1.6 of Acrobat and Reader for Windows, Macintosh and UNIX and version 7.1.3 of Acrobat and Reader for Windows and Macintosh are affected. Adobe Reader and Acrobat 9.2, 8.17 and 7.14 address the vulnerabilities and are available now…”

Security Updates Available for Adobe Reader and Acrobat

Release date: October 13, 2009

Vulnerability identifier: APSB09-15

CVE number: CVE-2007-0048, CVE-2007-0045, CVE-2009-2564, CVE-2009-2979, CVE-2009-2980, CVE-2009-2981, CVE-2009-2982, CVE-2009-2983, CVE-2009-2984, CVE-2009-2985, CVE-2009-2986, CVE-2009-2987, CVE-2009-2988, CVE-2009-2989, CVE-2009-2990, CVE-2009-2991, CVE-2009-2992, CVE-2009-2993, CVE-2009-2994, CVE-2009-2995, CVE-2009-2996, CVE-2009-2997, CVE-2009-2998, CVE-2009-3431, CVE-2009-3458, CVE-2009-3459, CVE-2009-3460, CVE-2009-3461, CVE-2009-3462

Platform: All

Summary

Critical vulnerabilities have been identified in Adobe Reader 9.1.3 and Acrobat 9.1.3, Adobe Reader 8.1.6 and Acrobat 8.1.6 for Windows, Macintosh and UNIX, and Adobe Reader 7.1.3 and Acrobat 7.1.3 for Windows and Macintosh. These vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system. This update represents the second quarterly security update for Adobe Reader and Acrobat.

Adobe recommends users of Adobe Reader 9.1.3 and Acrobat 9.1.3 and earlier versions update to Adobe Reader 9.2 and Acrobat 9.2. Adobe recommends users of Acrobat 8.1.6 and earlier versions update to Acrobat 8.1.7, and users of Acrobat 7.1.3 and earlier versions update to Acrobat 7.1.4. For Adobe Reader users who cannot update to Adobe Reader 9.2, Adobe has provided the Adobe Reader 8.1.7 and Adobe Reader 7.1.4 updates. Updates apply to all platforms: Windows, Macintosh and UNIX.

Affected software versions

Adobe Reader 9.1.3 and earlier versions for Windows, Macintosh, and UNIX
Adobe Acrobat 9.1.3 and earlier versions for Windows and Macintosh

Solution

Adobe Reader

Adobe Reader users on Windows can find the appropriate update here: http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows.

Adobe Reader users on Macintosh can find the appropriate update here: http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Macintosh.

Adobe Reader users on UNIX can find the appropriate update here: http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Unix.

Acrobat

Acrobat Standard and Pro users on Windows can find the appropriate update here:
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows.

Acrobat Pro Extended users on Windows can find the appropriate update here: http://www.adobe.com/support/downloads/product.jsp?product=158&platform=Windows

Acrobat 3D users on Windows can find the appropriate update here:
http://www.adobe.com/support/downloads/product.jsp?product=112&platform=Windows.

Acrobat Pro users on Macintosh can find the appropriate update here:
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Macintosh.

Severity rating

Adobe categorizes this as a critical update.

Details

Critical vulnerabilities have been identified in Adobe Reader 9.1.3 and Acrobat 9.1.3, Adobe Reader 8.1.6 and Acrobat 8.1.6 for Windows, Macintosh and UNIX, and Adobe Reader 7.1.3 and Acrobat 7.1.3 for Windows and Macintosh. These vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system. This update represents the second quarterly security update for Adobe Reader and Acrobat.

Adobe recommends users of Adobe Reader 9.1.3 and Acrobat 9.1.3 and earlier versions update to Adobe Reader 9.2 and Acrobat 9.2. Adobe recommends users of Acrobat 8.1.6 and earlier versions update to Acrobat 8.1.7, and users of Acrobat 7.1.3 and earlier versions update to Acrobat 7.1.4. For Adobe Reader users who cannot update to Adobe Reader 9.2, Adobe has provided the Adobe Reader 8.1.7 and Adobe Reader 7.1.4 updates. Updates apply to all platforms: Windows, Macintosh and UNIX.

This update resolves a heap overflow vulnerability that could lead to code execution (CVE-2009-3459).
NOTE: There are reports that this issue is being exploited in the wild, via limited, targeted attacks.
This update resolves a memory corruption issue that could potentially lead to code execution (CVE-2009-2985).
This update resolves multiple heap overflow vulnerabilities that could potentially lead to code execution (CVE-2009-2986).
This update resolves an invalid array index issue that could potentially lead to code execution (CVE-2009-2990).
NOTE: this issue is resolved in the Adobe Reader and Acrobat 9.2 and 8.1.7 updates.
This update resolves a remote exploitation issue specific to the Mozilla plug-in that could potentially allow an attacker to execute arbitrary code with the privileges of the current user (CVE-2009-2991). NOTE: this issue is resolved in the Adobe Reader and Acrobat 8.1.7 updates.
This update resolves multiple input validation vulnerabilities that could potentially lead to code execution (CVE-2009-2993).
This update resolves a buffer overflow issue that could potentially lead to code execution (CVE-2009-2994).
This update resolves a heap overflow vulnerability that could potentially lead to code execution (CVE-2009-2997).
This update resolves an input validation issue that could potentially lead to code execution (CVE-2009-2998).
This update resolves an input validation issue that could potentially lead to code execution (CVE-2009-3458).
This update resolves a memory corruption issue that could potentially lead to code execution. This issue is specific to Acrobat and does not affect Adobe Reader. (CVE-2009-3460).NOTE: this issue is resolved in the Acrobat 9.2 and 8.1.7 updates.
This update resolves an integer overflow that could potentially lead to code execution. This issue is specific to Acrobat and does not affect Adobe Reader. (CVE-2009-2989).NOTE: this issue is resolved in the Acrobat 9.2 and 8.1.7 updates.
This update resolves a memory corruption issue that leads to a Denial of Service (DoS); arbitrary code execution has not been demonstrated, but may be possible (CVE-2009-2983).NOTE: this issue is resolved in the Adobe Reader and Acrobat 9.2 and 8.1.7 updates.
This update resolves an integer overflow that leads to a Denial of Service (DoS); arbitrary code execution has not been demonstrated, but may be possible (CVE-2009-2980).
This update resolves a memory corruption issue that leads to a Denial of Service (DoS); arbitrary code execution has not been demonstrated, but may be possible (CVE-2009-2996).
This update resolves a Unix-only format bug when running in Debug mode that could lead to arbitrary code execution (CVE-2009-3462).
This update resolves an image decoder issue that leads to a Denial of Service (DoS); arbitrary code execution has not been demonstrated, but may be possible. This issue is specific to Acrobat and does not affect Adobe Reader. (CVE-2009-2984).
NOTE: this issue is resolved in the Acrobat 9.2 update.
This update resolves an input validation issue that could potentially lead to a bypass of Trust Manager restrictions (CVE-2009-2981). This update resolves an issue that could allow a malicious user to bypass file extension security controls. This issue is specific to Acrobat 9.X. (CVE-2009-3461).
This update modifies a certificate that if compromised could potentially be used in a social engineering attack (CVE-2009-2982).NOTE: this issue is resolved in the Adobe Reader and Acrobat 9.2 and 8.1.7 updates.
This update resolves a stack overflow issue that could potentially lead to a Denial of Service (DoS) attack (CVE-2009-3431).NOTE: this issue is resolved in the Adobe Reader and Acrobat 9.2 and 8.1.7 updates.
This update resolves a XMP-XML entity expansion issue that could lead to a Denial of Service (DoS) attack (CVE-2009-2979).NOTE: this issue is resolved in the Adobe Reader and Acrobat 9.2 and 8.1.7 updates.
This update resolves a remote denial of service issue in the ActiveX control specific to the Windows OS (CVE-2009-2987).
This update resolves an input validation issue that could lead to a Denial of Service (DoS) issue (CVE-2009-2988).
This update resolves an input validation issue specific to the ActiveX control that could lead to a Denial of Service (DoS) attack (CVE-2009-2992).NOTE: this issue is resolved in the Adobe Reader and Acrobat 9.2 and 8.1.7 updates.

This update resolves an integer overflow in that leads to a Denial of Service (DoS). This issue is specific to Acrobat and does not affect Adobe Reader. (CVE-2009-2995).
(CVE-2009-2564).
This update resolves a cross-site scripting issue when the browser plugin is used with Google Chrome and Opera browsers (CVE-2007-0048, CVE-2007-0045)

Acknowledgments

Adobe would like to thank the following individuals and organizations for reporting the relevant issues and for working with Adobe to help protect our customers’ security:

  • Michael Schmidt of Compass Security (http://www.csnc.ch) (CVE-2007-0048, CVE-2007-0045)
  • Didier Stevens (CVE-2009-2979)
  • Drew Yao of Apple Product Security (http://www.apple.com/support/security/) (CVE-2009-2980)
  • Stefano Di Paola of Minded Security (http://www.mindedsecurity.com/) (CVE-2009-2981)
  • Guillaume Delugré and Frédéric Raynal of SOGETI ESEC (http://esec.fr.sogeti.com/) (CVE-2009-2982, CVE-2009-3461, CVE-2009-3462)
  • SkyLined of Google Inc. (http://skypher.com/SkyLined) (CVE-2009-2983)
  • Tavis Ormandy, Google Security Team (http://www.google.com/corporate/security.html) (CVE-2009-2984)
  • An anonymous researcher reported through TippingPoint’s Zero Day Initiative (http://www.zerodayinitiative.com/) (CVE-2009-2985)
  • Will Dormann, CERT (http://www.cert.org/) (CVE-2009-2986)
  • Zhenhua Liu and Xiaopeng Zhang of Fortinet’s FortiGuard Global Security Research Team (http://www.fortiguardcenter.com) (CVE-2009-2987, CVE-2009-2988, CVE-2009-2996)
  • Tielei Wang from ICST-ERCIS (Engineering Research Center of Info Security, Institute of Computer Science & Technology, Peking University / China) (CVE-2009-2989, CVE-2009-2995)
  • Dionysus Blazakis through iDefense’s Vulnerability Contributor Program (http://www.idefense.com/vcp/) (CVE-2009-2990)
  • Elazar Broad through iDefense’s Vulnerability Contributor Program (http://www.idefense.com/vcp/) (CVE-2009-2991)
  • David Soldera of Next Generation Security Software (http://www.ngssoftware.com/) (CVE-2009-2992)
  • IOActive (http://www.ioactive.com/) (CVE-2009-2993)
  • Felipe Andres Manzano through the iSIGHT Partners GVP (https://gvp.isightpartners.com) (CVE-2009-2994)
  • Nicolas Joly of VUPEN Security (http://www.vupen.com ) (CVE-2009-2997, CVE-2009-2998, CVE-2009-3458)
  • Chia-Ching Fang of the Information and Communication Security Technology Center (http://www.icst.org.tw) (CVE-2009-3459)
  • Haifei Li of Fortinet’s FortiGuard Global Security Research Team (http://www.fortiguardcenter.com/) (CVE-2009-3460)

Categories: Infosecurity
Tags: Adobe Acrobat, Adobe Reader, Adobe Systems, Software Patches

Comments are closed.

« Wondermark: Great Dilbert: The Project Timeline »
  • Latest
  • Random
  • Bookmarks
  • Archives
  • Lisa Benson: Jobs
  • Final Apache HTTP Server 1.3 Series Release
  • Sherffius: The Moon
  • NSA To Aid Google In Chinese State Sponsored Intrusion Investigation
  • Oracle Patches Critical WebLogic Flaw
  • Lisa Benson: Beanstalk
  • USB Electronic Key Impressioner – Open Sesame
  • Sherffius: Bacterial-Laden
  • Firefox Malware Extensions Discovered
  • Holbert: Trillion Dollar Stuck Pedal
  • Palestinian Al-Fatah Hackers Attack Hamas Military Web Site
  • Happy New Year 2010!
  • XKCD: Simple
  • Firefox 3.0.2 Released – Multiple Vulnerabilites Addressed
  • Oracle Identity Management: Adaptive Access Manager Released
  • Apple Updates Bonjour for Windows
  • Wondermark: Aardshark
  • Research Study: Vista Still Insecure. Stunning.
  • Wondermark: The Portrait
  • Brilliant Metasploit Developer Joins Microsoft Security
  • Apple
  • BSD
  • Closson
  • Darknet
  • Debian
  • Finnigan
  • ha.ckers
  • Hoff
  • Insecure
  • Krebs
  • Layer8
  • MSRC
  • Network Security Blog
  • NSA SEL
  • openSUSE
  • RedHat
  • SANS
  • Schneier
  • Security Eunoia
  • Securosis
  • Shimel
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
Subscribe

Featured Blog - Blogs.com SANS Security Reading Room KnotOriginal: fine art to hang on your body and walls Member - Security Bloggers Network

Dilbert

Sponsored Links

KnotOriginal

Featured Video

RSS Cryptography

  • Microscope-wielding boffins crack cordless phone crypto 2010/02/08
  • Making packet processing more efficient with network-optimized multicore designs: Part 2 2010/02/08
  • New Attack on Threefish 2010/02/07
  • So I deleted it without reading it. 2010/02/06
  • Kaspersky: Google hack takes spotlight from Russia 2010/02/05
  • IP Cores, Inc. Announces an Update of its Elliptic Curve Crypto Accelerator 2010/02/05
  • SMIC, SSHIC deliver smart card IC using 0.162 m EEPROM 2010/02/04
  • Revere Security Appoints Co-Inventor of Public-Key Cryptography... 2010/02/03
  • Data defenders: Researchers try to ward off increasingly sophisticated cyber attacks 2010/02/02
  • IP Cores Selects Phoenix Technologies for Israel 2010/02/02

RSS Security Bloggers Network

  • My Blackhat DC Paper, Slides, and Video are available 2010/02/08 IBM Internet Security Systems Frequency X Blog
  • Is Your BlackBerry Spying On You? 2010/02/08 spinman
  • The 800-lb Dragon’s APTitude 2010/02/08 Bill Wildprett
  • Wrapping insecure web apps with Apache 2010/02/08 Asmodian X
  • Oracle Patches Critical WebLogic Flaw 2010/02/08 Marc Handelman
  • Lisa Benson: Beanstalk 2010/02/08 Marc Handelman
  • Week 5 in Review 2010/02/08 glenn
  • Google Street View Car Gets GPSed by F.A.T. Pranksters 2010/02/08 Devin McDonald

RSS SANS ISC

  • Oracle has an unscheduled security alert and patch for CVE-2010-0073. The issue affects WebLogic Server and is remotely exploitable. Details and patch are here http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0073.html, (Tue, Feb 9th) 2010/02/09
  • When is a 0day not a 0day? Samba symlink bad default config, (Tue, Feb 9th) 2010/02/09
  • When is a 0day not a 0day? Fake OpenSSh exploit, again. , (Mon, Feb 8th) 2010/02/08
  • Mandiant Mtrends Report, (Sun, Feb 7th) 2010/02/07
  • LANDesk Management Gateway Vulnerability, (Sat, Feb 6th) 2010/02/06
  • tweaked ISC layout. Please submit screen shot and browser details if things don't look right., (Sat, Feb 6th) 2010/02/06
  • Oracle WebLogic Server Security Alert, (Sat, Feb 6th) 2010/02/06
  • New version of Andreas Schuster's Evtx Parser released http://computer.forensikblog.de/en/2010/02/evtx_parser_1_0_2.html, (Sat, Feb 6th) 2010/02/06
  • Memory Analysis - time to move beyond XP, (Fri, Feb 5th) 2010/02/06

RSS Oracle

  • Oracle to Acquire AmberPoint 2010/02/09
  • Bookmarkable page with parameters 2010/02/09
  • 32-bit to 64-bit database migration tips: OLAP upgrade 2010/02/08
  • ADF Coding Ninja 2010/02/08
  • Case Study: Swedish Rail Operator SJ Increases Revenue and Customer Satisfaction Using CRM 2010/02/08
  • Random Things: Volume #13 2010/02/08
  • v-Commerce? 2010/02/08

RSS MySQL

  • A deep look at MySQL 5.5 partitioning enhancements 2009/12/24
  • Sun "Tech Days" Conference World Tour Kicks Off in Brazil 2009/12/07
  • Tino Rachui: Using MySQL Cluster in Sun's Virtual Desktop Infrastructure 2009/11/10
  • MySQL Database Analytics with InfiniDB from Calpont – Part 2 2009/10/28
  • MySQL Database Analytics with InfiniDB from Calpont – Part 1 2009/10/27
  • What's New in the MySQL Enterprise Fall 2009 Release? - Interview with Mark Matthews and Andy Bang 2009/09/08
  • Introducing the MySQL Librarian 2009/07/14

RSS Linux

  • Oracle Drops Sun's Commitment To Accessibility - Slashdot 2010/02/09
  • LinuxCon Puts Out Call for Papers Ahead of Summer Event - OStatic (blog) 2010/02/09
  • How To Reverse Engineer A Motherboard BIOS - Benchmark Reviews 2010/02/09
  • Oracle Patches Dangerous WebLogic Server Flaw - eWeek 2010/02/09
  • Unix ENGINEER - TRADING - SYDNEY CBD! - Australian Techworld 2010/02/09

RSS MAC OSX

  • Anti-DRM Protest Against The iPad Grows 2010/02/08 Eli Milchman
  • Amazon to Hike Ebook Pricing as iPad Ships 2010/02/08 Ed Sutherland
  • Daily Deals: iPhone Acces. Bundle, External Superdrive, App Store Freebies 2010/02/08 Ed Sutherland
  • Mock Up Your iPad Ideas With IA’s Omnigraffle Template 2010/02/08 Giles Turnbull
  • The inevitable DIY iPad papercraft mockup 2010/02/08 John Brownlee
  • Apple to app devs: don’t use Core Location “primarily” for advertising 2010/02/08 John Brownlee
  • Report: Carriers to Subsidized iPads for 2-Year 3G Contracts 2010/02/08 Ed Sutherland

RSS Microsoft

  • February 2010 Bulletin Release Advance Notification 2010/02/04 MSRCTEAM
  • Security Advisory 980088 Released 2010/02/03 MSRCTEAM
  • January 2010 Out-of-Band Security Bulletin Webcast 2010/01/22 MSRCTEAM
  • Bulletin MS10-002 Released 2010/01/21 MSRCTEAM
  • Security Advisory 979682 Released 2010/01/21 MSRCTEAM
  • Advance Notification for Out-of-Band Bulletin Release 2010/01/20 MSRCTEAM
  • Security Advisory 979352 – Going out of Band 2010/01/19 MSRCTEAM

RSS Network

  • Europe lagging behind on fibre broadband adoption 2010/02/08
  • LG NAS N4B1 review 2010/02/08
  • VoIP patent under review by Patent Office 2010/02/08
  • YouTube now supports IPv6 2010/02/08
  • Where do web giants stand on IPv6? 2010/02/05
  • Intel details vPro for Core i5, i7 processors 2010/02/05
  • Microsoft IE still popular, researcher says 2010/02/05

Daily Posts

February 2010
S M T W T F S
« Jan    
 123456
78910111213
14151617181920
21222324252627
28  
Creative Commons License
The Infosecurity.US Blog is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.

Find the best blogs at Blogs.com.

Creative Commons Attribution-Share Alike 3.0 U.S. License ©2010 Infosecurity.US

Subscribe