You are here: silicon.com > Software > Security Strategy

Security Strategy

Adobe fixes risky PDF holes

Out damn spot...

Tags: adobe acrobat, pdf, adobe, flaw

By Dawn Kawamoto

Published: 11 January 2007 09:10 GMT

Adobe Systems has issued updates to fix security flaws in its Reader and Acrobat software that could allow an attacker to remotely commandeer a computer.

The vulnerabilities affect Adobe Reader and Adobe Acrobat Standard, Professional and Elements versions 7.0.8 and earlier, as well as Adobe Acrobat 3D, the company said in its advisory. Secunia rated the Reader flaw as "highly critical".

The version 7.0.9 updates issued on Tuesday are designed to address holes that could allow outsiders to gain access to hard-disk drives via a malicious link that targets PDF files on vulnerable computers.

The attackers could then take the compromised system and read and delete files, execute programs and forward information from the computer.

Adobe recommends Reader users upgrade to Reader 8, the most recent major version, to fix the problem. Those whose computer systems are not compatible, or who do not want to move to version 8 can install Tuesday's 7.0.9 version instead.

That means people will have to do a full installation of a software version to protect their computers. Typically, companies will provide a patch to fix security holes - a less time-consuming process - but Adobe has not done that in this case.

The 7.0.9 update is slightly larger than a patch, an Adobe representative said. The company was already working on the update when it added the security features, so Adobe was able to get out a full installation faster than it would for just a patch, the representative added.

Dawn Kawamoto writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
Functional Tester- ISU

Ability to analyse defects and to fix them. Experience with message hubs * Experience with AMT Sybex DTS system Deliverables/Timelines: * Writing / ...

C++ Software Engineer

Keywords:Software engineer Unix engineer C/C++ software engineer coder programmer systems engineer IT engineer network engineer Dublin greater Dublin ...

Trainer

Therefore any candidate applying for this role should have very strong IT admin and written skills.The key technologies that the IT trainer must be ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: