PC Review


Reply
Thread Tools Rate Thread

buffer overflow in adobe reader 8/9

 
 
robinb
Guest
Posts: n/a
 
      24th Feb 2009
http://www.adobe.com/support/securit...apsa09-01.html

Buffer overflow issue in versions 9.0 and earlier of Adobe Reader and
Acrobat

Release date: February 19, 2009

Vulnerability identifier: APSA09-01

CVE number: CVE-2009-0658

Platform: All platforms
Summary

A critical vulnerability has been identified in Adobe Reader 9 and Acrobat 9
and earlier versions. This vulnerability would cause the application to
crash and could potentially allow an attacker to take control of the
affected system. There are reports that this issue is being exploited.

Adobe is planning to release updates to Adobe Reader and Acrobat to resolve
the relevant security issue. Adobe expects to make available an update for
Adobe Reader 9 and Acrobat 9 by March 11th, 2009. Updates for Adobe Reader 8
and Acrobat 8 will follow soon after, with Adobe Reader 7 and Acrobat 7
updates to follow. In the meantime, Adobe is in contact with anti-virus
vendors, including McAfee and Symantec, on this issue in order to ensure the
security of our mutual customers. A security bulletin will be published on
http://www.adobe.com/support/security as soon as product updates are
available.

--
Do You Feel Like a Hostage To Your Computer?
Then You Need
R&D Internet Associates
24 Coriander Drive
Princeton NJ 08540
732-355-0156
http://rdinternetassociates.com

 
Reply With Quote
 
 
 
 
Randy Knobloch
Guest
Posts: n/a
 
      24th Feb 2009
robinb wrote:
> http://www.adobe.com/support/securit...apsa09-01.html

<snip>
This is basically a short-term fix, which basically tells users of affected software to
disable JavaScript in Preferences.
OK, done, until Adobe release a "real" patch.
Beware of third-party fixes as outlined here >
<http://www.theregister.co.uk/2009/02/24/unofficial_adobe_patch/>

More info here which goes to the URL Robin posted >
<http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20090221>

--
Randy
<http://msmvps.com/blogs/siljaline/default.aspx>



 
Reply With Quote
 
Tom Emmelot
Guest
Posts: n/a
 
      24th Feb 2009
Hi Robin,

I use this for a while now!

http://www.foxitsoftware.com/downloads/
Faster, plugin for firefox also and PDF creator also!

Regards >*<TOM >*<

robinb schreef:
> http://www.adobe.com/support/securit...apsa09-01.html
>
> Buffer overflow issue in versions 9.0 and earlier of Adobe Reader and
> Acrobat
>
> Release date: February 19, 2009
>
> Vulnerability identifier: APSA09-01
>
> CVE number: CVE-2009-0658
>
> Platform: All platforms
> Summary
>
> A critical vulnerability has been identified in Adobe Reader 9 and
> Acrobat 9 and earlier versions. This vulnerability would cause the
> application to crash and could potentially allow an attacker to take
> control of the affected system. There are reports that this issue is
> being exploited.
>
> Adobe is planning to release updates to Adobe Reader and Acrobat to
> resolve the relevant security issue. Adobe expects to make available an
> update for Adobe Reader 9 and Acrobat 9 by March 11th, 2009. Updates for
> Adobe Reader 8 and Acrobat 8 will follow soon after, with Adobe Reader 7
> and Acrobat 7 updates to follow. In the meantime, Adobe is in contact
> with anti-virus vendors, including McAfee and Symantec, on this issue in
> order to ensure the security of our mutual customers. A security
> bulletin will be published on http://www.adobe.com/support/security as
> soon as product updates are available.
>

 
Reply With Quote
 
Alan D
Guest
Posts: n/a
 
      24th Feb 2009
Hi Tom. I use Foxit too - but presumably it too is vulnerable to this
exploit?
Alan D


"Tom Emmelot" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Hi Robin,
>
> I use this for a while now!
>
> http://www.foxitsoftware.com/downloads/
> Faster, plugin for firefox also and PDF creator also!
>
> Regards >*<TOM >*<
>
> robinb schreef:
>> http://www.adobe.com/support/securit...apsa09-01.html
>>
>> Buffer overflow issue in versions 9.0 and earlier of Adobe Reader and
>> Acrobat
>>
>> Release date: February 19, 2009
>>
>> Vulnerability identifier: APSA09-01
>>
>> CVE number: CVE-2009-0658
>>
>> Platform: All platforms
>> Summary
>>
>> A critical vulnerability has been identified in Adobe Reader 9 and
>> Acrobat 9 and earlier versions. This vulnerability would cause the
>> application to crash and could potentially allow an attacker to take
>> control of the affected system. There are reports that this issue is
>> being exploited.
>>
>> Adobe is planning to release updates to Adobe Reader and Acrobat to
>> resolve the relevant security issue. Adobe expects to make available an
>> update for Adobe Reader 9 and Acrobat 9 by March 11th, 2009. Updates for
>> Adobe Reader 8 and Acrobat 8 will follow soon after, with Adobe Reader 7
>> and Acrobat 7 updates to follow. In the meantime, Adobe is in contact
>> with anti-virus vendors, including McAfee and Symantec, on this issue in
>> order to ensure the security of our mutual customers. A security bulletin
>> will be published on http://www.adobe.com/support/security as soon as
>> product updates are available.
>>



 
Reply With Quote
 
robinb
Guest
Posts: n/a
 
      25th Feb 2009
I did the fix until the patch comes out. Adobe asks you to do it
the fix is
Open Adobe Reader

Click: Edit -> Preferences -> JavaScript and uncheck Enable Acrobat
JavaScript- then click OK
they say the reader will still crash if it is hit by the exploit but it will
not spread the exploit
robin

"robinb" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> http://www.adobe.com/support/securit...apsa09-01.html
>
> Buffer overflow issue in versions 9.0 and earlier of Adobe Reader and
> Acrobat
>
> Release date: February 19, 2009
>
> Vulnerability identifier: APSA09-01
>
> CVE number: CVE-2009-0658
>
> Platform: All platforms
> Summary
>
> A critical vulnerability has been identified in Adobe Reader 9 and Acrobat
> 9 and earlier versions. This vulnerability would cause the application to
> crash and could potentially allow an attacker to take control of the
> affected system. There are reports that this issue is being exploited.
>
> Adobe is planning to release updates to Adobe Reader and Acrobat to
> resolve the relevant security issue. Adobe expects to make available an
> update for Adobe Reader 9 and Acrobat 9 by March 11th, 2009. Updates for
> Adobe Reader 8 and Acrobat 8 will follow soon after, with Adobe Reader 7
> and Acrobat 7 updates to follow. In the meantime, Adobe is in contact with
> anti-virus vendors, including McAfee and Symantec, on this issue in order
> to ensure the security of our mutual customers. A security bulletin will
> be published on http://www.adobe.com/support/security as soon as product
> updates are available.
>
> --
> Do You Feel Like a Hostage To Your Computer?
> Then You Need
> R&D Internet Associates
> 24 Coriander Drive
> Princeton NJ 08540
> 732-355-0156
> http://rdinternetassociates.com


 
Reply With Quote
 
Bill Sanderson
Guest
Posts: n/a
 
      25th Feb 2009

I recommend this action if you are worried about this issue. It is easily
reversible and effective--and the chance are you've never seen a PDF that
needed javascript.

So far, this is a limited scale targeted attack--so I'm sitting tight as far
as machines that I administer.

"robinb" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> I did the fix until the patch comes out. Adobe asks you to do it
> the fix is
> Open Adobe Reader
>
> Click: Edit -> Preferences -> JavaScript and uncheck Enable Acrobat
> JavaScript- then click OK
> they say the reader will still crash if it is hit by the exploit but it
> will not spread the exploit
> robin
>
> "robinb" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed)...
>> http://www.adobe.com/support/securit...apsa09-01.html
>>
>> Buffer overflow issue in versions 9.0 and earlier of Adobe Reader and
>> Acrobat
>>
>> Release date: February 19, 2009
>>
>> Vulnerability identifier: APSA09-01
>>
>> CVE number: CVE-2009-0658
>>
>> Platform: All platforms
>> Summary
>>
>> A critical vulnerability has been identified in Adobe Reader 9 and
>> Acrobat 9 and earlier versions. This vulnerability would cause the
>> application to crash and could potentially allow an attacker to take
>> control of the affected system. There are reports that this issue is
>> being exploited.
>>
>> Adobe is planning to release updates to Adobe Reader and Acrobat to
>> resolve the relevant security issue. Adobe expects to make available an
>> update for Adobe Reader 9 and Acrobat 9 by March 11th, 2009. Updates for
>> Adobe Reader 8 and Acrobat 8 will follow soon after, with Adobe Reader 7
>> and Acrobat 7 updates to follow. In the meantime, Adobe is in contact
>> with anti-virus vendors, including McAfee and Symantec, on this issue in
>> order to ensure the security of our mutual customers. A security bulletin
>> will be published on http://www.adobe.com/support/security as soon as
>> product updates are available.
>>
>> --
>> Do You Feel Like a Hostage To Your Computer?
>> Then You Need
>> R&D Internet Associates
>> 24 Coriander Drive
>> Princeton NJ 08540
>> 732-355-0156
>> http://rdinternetassociates.com

>



--


 
Reply With Quote
 
Bill Sanderson
Guest
Posts: n/a
 
      25th Feb 2009
Breaking news:

It now appears that javascript is unnecessary to exploit the vulnerability,
according to Secunia.

Best to watch for the patch from Adobe. And, get the older versions updated
to 9.x. They are all vulnerable, but 9.x will be patched first.

"Bill Sanderson" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
>
> I recommend this action if you are worried about this issue. It is easily
> reversible and effective--and the chance are you've never seen a PDF that
> needed javascript.
>
> So far, this is a limited scale targeted attack--so I'm sitting tight as
> far as machines that I administer.
>
> "robinb" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed)...
>> I did the fix until the patch comes out. Adobe asks you to do it
>> the fix is
>> Open Adobe Reader
>>
>> Click: Edit -> Preferences -> JavaScript and uncheck Enable Acrobat
>> JavaScript- then click OK
>> they say the reader will still crash if it is hit by the exploit but it
>> will not spread the exploit
>> robin
>>
>> "robinb" <(E-Mail Removed)> wrote in message
>> news:(E-Mail Removed)...
>>> http://www.adobe.com/support/securit...apsa09-01.html
>>>
>>> Buffer overflow issue in versions 9.0 and earlier of Adobe Reader and
>>> Acrobat
>>>
>>> Release date: February 19, 2009
>>>
>>> Vulnerability identifier: APSA09-01
>>>
>>> CVE number: CVE-2009-0658
>>>
>>> Platform: All platforms
>>> Summary
>>>
>>> A critical vulnerability has been identified in Adobe Reader 9 and
>>> Acrobat 9 and earlier versions. This vulnerability would cause the
>>> application to crash and could potentially allow an attacker to take
>>> control of the affected system. There are reports that this issue is
>>> being exploited.
>>>
>>> Adobe is planning to release updates to Adobe Reader and Acrobat to
>>> resolve the relevant security issue. Adobe expects to make available an
>>> update for Adobe Reader 9 and Acrobat 9 by March 11th, 2009. Updates for
>>> Adobe Reader 8 and Acrobat 8 will follow soon after, with Adobe Reader 7
>>> and Acrobat 7 updates to follow. In the meantime, Adobe is in contact
>>> with anti-virus vendors, including McAfee and Symantec, on this issue in
>>> order to ensure the security of our mutual customers. A security
>>> bulletin will be published on http://www.adobe.com/support/security as
>>> soon as product updates are available.
>>>
>>> --
>>> Do You Feel Like a Hostage To Your Computer?
>>> Then You Need
>>> R&D Internet Associates
>>> 24 Coriander Drive
>>> Princeton NJ 08540
>>> 732-355-0156
>>> http://rdinternetassociates.com

>>

>
>
> --
>
>



--


 
Reply With Quote
 
robinb
Guest
Posts: n/a
 
      25th Feb 2009
problem is my husband can only use adobe 8 for some of his tax pdfs. For
some reason adobe 9 will not allow you to fill in some of the forms online.
Only adobe 8 will allow this- got me why they made this change. I did the
fix but we will wait for the patch and pray :P
robin

"Bill Sanderson" <(E-Mail Removed)> wrote in message
news:#(E-Mail Removed)...
> Breaking news:
>
> It now appears that javascript is unnecessary to exploit the
> vulnerability, according to Secunia.
>
> Best to watch for the patch from Adobe. And, get the older versions
> updated to 9.x. They are all vulnerable, but 9.x will be patched first.
>
> "Bill Sanderson" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed)...
>>
>> I recommend this action if you are worried about this issue. It is
>> easily reversible and effective--and the chance are you've never seen a
>> PDF that needed javascript.
>>
>> So far, this is a limited scale targeted attack--so I'm sitting tight as
>> far as machines that I administer.
>>
>> "robinb" <(E-Mail Removed)> wrote in message
>> news:(E-Mail Removed)...
>>> I did the fix until the patch comes out. Adobe asks you to do it
>>> the fix is
>>> Open Adobe Reader
>>>
>>> Click: Edit -> Preferences -> JavaScript and uncheck Enable Acrobat
>>> JavaScript- then click OK
>>> they say the reader will still crash if it is hit by the exploit but it
>>> will not spread the exploit
>>> robin
>>>
>>> "robinb" <(E-Mail Removed)> wrote in message
>>> news:(E-Mail Removed)...
>>>> http://www.adobe.com/support/securit...apsa09-01.html
>>>>
>>>> Buffer overflow issue in versions 9.0 and earlier of Adobe Reader and
>>>> Acrobat
>>>>
>>>> Release date: February 19, 2009
>>>>
>>>> Vulnerability identifier: APSA09-01
>>>>
>>>> CVE number: CVE-2009-0658
>>>>
>>>> Platform: All platforms
>>>> Summary
>>>>
>>>> A critical vulnerability has been identified in Adobe Reader 9 and
>>>> Acrobat 9 and earlier versions. This vulnerability would cause the
>>>> application to crash and could potentially allow an attacker to take
>>>> control of the affected system. There are reports that this issue is
>>>> being exploited.
>>>>
>>>> Adobe is planning to release updates to Adobe Reader and Acrobat to
>>>> resolve the relevant security issue. Adobe expects to make available an
>>>> update for Adobe Reader 9 and Acrobat 9 by March 11th, 2009. Updates
>>>> for Adobe Reader 8 and Acrobat 8 will follow soon after, with Adobe
>>>> Reader 7 and Acrobat 7 updates to follow. In the meantime, Adobe is in
>>>> contact with anti-virus vendors, including McAfee and Symantec, on this
>>>> issue in order to ensure the security of our mutual customers. A
>>>> security bulletin will be published on
>>>> http://www.adobe.com/support/security as soon as product updates are
>>>> available.
>>>>
>>>> --
>>>> Do You Feel Like a Hostage To Your Computer?
>>>> Then You Need
>>>> R&D Internet Associates
>>>> 24 Coriander Drive
>>>> Princeton NJ 08540
>>>> 732-355-0156
>>>> http://rdinternetassociates.com
>>>

>>
>>
>> --
>>
>>

>
>
> --
>
>

 
Reply With Quote
 
Bill Sanderson
Guest
Posts: n/a
 
      26th Feb 2009
Ouch. 9 usually, but not always, replaces 8--not sure they can really
coexist--when I've seen both in add or remove programs, I 've just removed 8
asap.

Here's hoping Adobe will do the right thing and patch 8 as well.

"robinb" <(E-Mail Removed)> wrote in message
news:u#(E-Mail Removed)...
> problem is my husband can only use adobe 8 for some of his tax pdfs. For
> some reason adobe 9 will not allow you to fill in some of the forms
> online. Only adobe 8 will allow this- got me why they made this change. I
> did the fix but we will wait for the patch and pray :P
> robin
>
> "Bill Sanderson" <(E-Mail Removed)> wrote in message
> news:#(E-Mail Removed)...
>> Breaking news:
>>
>> It now appears that javascript is unnecessary to exploit the
>> vulnerability, according to Secunia.
>>
>> Best to watch for the patch from Adobe. And, get the older versions
>> updated to 9.x. They are all vulnerable, but 9.x will be patched first.
>>
>> "Bill Sanderson" <(E-Mail Removed)> wrote in message
>> news:(E-Mail Removed)...
>>>
>>> I recommend this action if you are worried about this issue. It is
>>> easily reversible and effective--and the chance are you've never seen a
>>> PDF that needed javascript.
>>>
>>> So far, this is a limited scale targeted attack--so I'm sitting tight as
>>> far as machines that I administer.
>>>
>>> "robinb" <(E-Mail Removed)> wrote in message
>>> news:(E-Mail Removed)...
>>>> I did the fix until the patch comes out. Adobe asks you to do it
>>>> the fix is
>>>> Open Adobe Reader
>>>>
>>>> Click: Edit -> Preferences -> JavaScript and uncheck Enable Acrobat
>>>> JavaScript- then click OK
>>>> they say the reader will still crash if it is hit by the exploit but it
>>>> will not spread the exploit
>>>> robin
>>>>
>>>> "robinb" <(E-Mail Removed)> wrote in message
>>>> news:(E-Mail Removed)...
>>>>> http://www.adobe.com/support/securit...apsa09-01.html
>>>>>
>>>>> Buffer overflow issue in versions 9.0 and earlier of Adobe Reader and
>>>>> Acrobat
>>>>>
>>>>> Release date: February 19, 2009
>>>>>
>>>>> Vulnerability identifier: APSA09-01
>>>>>
>>>>> CVE number: CVE-2009-0658
>>>>>
>>>>> Platform: All platforms
>>>>> Summary
>>>>>
>>>>> A critical vulnerability has been identified in Adobe Reader 9 and
>>>>> Acrobat 9 and earlier versions. This vulnerability would cause the
>>>>> application to crash and could potentially allow an attacker to take
>>>>> control of the affected system. There are reports that this issue is
>>>>> being exploited.
>>>>>
>>>>> Adobe is planning to release updates to Adobe Reader and Acrobat to
>>>>> resolve the relevant security issue. Adobe expects to make available
>>>>> an update for Adobe Reader 9 and Acrobat 9 by March 11th, 2009.
>>>>> Updates for Adobe Reader 8 and Acrobat 8 will follow soon after, with
>>>>> Adobe Reader 7 and Acrobat 7 updates to follow. In the meantime, Adobe
>>>>> is in contact with anti-virus vendors, including McAfee and Symantec,
>>>>> on this issue in order to ensure the security of our mutual customers.
>>>>> A security bulletin will be published on
>>>>> http://www.adobe.com/support/security as soon as product updates are
>>>>> available.
>>>>>
>>>>> --
>>>>> Do You Feel Like a Hostage To Your Computer?
>>>>> Then You Need
>>>>> R&D Internet Associates
>>>>> 24 Coriander Drive
>>>>> Princeton NJ 08540
>>>>> 732-355-0156
>>>>> http://rdinternetassociates.com
>>>>
>>>
>>>
>>> --
>>>
>>>

>>
>>
>> --
>>
>>



--


 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
buffer overflow abhishekrishna Windows XP General 1 14th Jun 2010 08:24 PM
Buffer overflow =?Utf-8?B?UC5KLkEuIFRvbHNtYQ==?= Windows XP Help 0 9th Dec 2006 03:43 PM
Adobe Reader 7.0.1 does not download .pdf files like Adobe Reader 6.0.3 does. Richard A. Landkamer Windows XP General 4 10th Apr 2005 09:47 PM
Buffer overflow Remko van Leeuwen Windows XP Drivers 0 14th Sep 2004 01:49 PM
Buffer overflow Stephen Windows XP General 5 17th Aug 2003 10:58 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 09:02 PM.