
Out damn spot...
Published: 11 January 2007 09:10 GMT
Adobe Systems has issued updates to fix security flaws in its Reader and Acrobat software that could allow an attacker to remotely commandeer a computer.
The vulnerabilities affect Adobe Reader and Adobe Acrobat Standard, Professional and Elements versions 7.0.8 and earlier, as well as Adobe Acrobat 3D, the company said in its advisory. Secunia rated the Reader flaw as "highly critical".
The version 7.0.9 updates issued on Tuesday are designed to address holes that could allow outsiders to gain access to hard-disk drives via a malicious link that targets PDF files on vulnerable computers.
The attackers could then take the compromised system and read and delete files, execute programs and forward information from the computer.
Adobe recommends Reader users upgrade to Reader 8, the most recent major version, to fix the problem. Those whose computer systems are not compatible, or who do not want to move to version 8 can install Tuesday's 7.0.9 version instead.
That means people will have to do a full installation of a software version to protect their computers. Typically, companies will provide a patch to fix security holes - a less time-consuming process - but Adobe has not done that in this case.
The 7.0.9 update is slightly larger than a patch, an Adobe representative said. The company was already working on the update when it added the security features, so Adobe was able to get out a full installation faster than it would for just a patch, the representative added.
Dawn Kawamoto writes for CNET News.com
Skills required: - knowledge of Microsoft products, Windows 2000, Vista, XP - Break/fix repair of computers, hardware & software - knowledge of DHCP, ...
The role is to provide day to day support, troubleshooting, tuning, administration, systems hardening (security), and project work for a wide range ...
Patch Management, Systems Tuning, Systems Hardening (security), Backup/Recovery, Shell Scripting, Hardware Setup/Configuration, Production ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Peter Cochrane Peter Cochrane's Blog: Is convergence a fiction? Or could it finally be happening…
Clive Longbottom Quocirca's Straight Talking: A game of two halves Microsoft Virtualisation scores while its SOA bores...