Free Newsletters
InfoWorld Daily

InfoWorld
Log-in | Register

Adobe fixes undisclosed vulnerabilities in Reader

Adobe has not given out details of the fix, which could indicate the vulnerabilities are serious and could result in a compromised PC, security expert says


Adobe released on Wednesday an update that fixes vulnerabilities in its widely used Reader document viewing program.

Users are urged to upgrade to version 8.1.2, available for download on Adobe's Web site.

Adobe has not given out details of the vulnerabilities, even though the company has a section on its Web site detailing security advisories for Reader.

That could indicate that the vulnerabilities are fairly serious and could result in a compromised PC, said Thomas Kristensen, chief technical officer for Secunia, a security vendor in Denmark.

Secunia is performing a binary analysis of the old and new versions of Reader to figure out the vulnerabilities. However, that analysis takes one to three days, Kristensen said.

Kristensen said no proof-of-concept code has been seen yet and no attacks have been reported. But people should be especially cautious of PDFs, the common file type that Reader opens.

"PDFs are generally highly trusted," Kristensen said. "It's a common format for exchanging information."

Secunia estimates that more than 60 percent of home PC users have the Reader program, based on data from one of its software products that checks to see if programs have up-to-date patches. Corporate use of Reader is less, around 30 percent, since many companies use other business applications that can open PDFs, Kristensen said.

Hackers seized on PDFs last year after the disclosure of a protocol handling vulnerability involving Windows. The problem allowed them to create malicious PDF documents that would infect a PC with malicious software if opened.

Adobe officials could not be reached.


Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





THE TOP THREE WAYS TO CUT COSTS IN 2009
With the current economic environment, organizations are looking for ways to cut costs. With Oracle Content Management, you can cut costs in three ways in 2009: consolidation, process automation and compliance. Learn more from this webcast sponsored by Oracle.

»  Click here to view this Webcast
  Enterprise Data Security Solutions Guide
Data security used to be about outside threats. These days the biggest challenge for data-driven organizations is the management of secure information from the inside out. Data is available on laptops, your network and even USB devices, but not always secure. Read this Solutions Guide to learn the best ways to keep it safe. Sponsored by ISC2

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
IFW Daily 01/09/2009

Palm launches new smartphone and OS, Asustek sees slower demand for Eee...

 
 
 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2009, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist
TecChannel :: TecCommunity