January 27th, 2010 . by DarkFiber Consulting
Adobe has released an update for Reader and Acrobat to address multiple vulnerabilities. These vulnerabilities affect Adobe Reader 9.2 and earlier versions for Windows, Macintosh, and UNIX and Adobe Acrobat 9.2 and earlier versions for Windows and Macintosh. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code or cause a denial-of-service condition.
DarkFiber Consulting encourages users and administrators to review Adobe Security Bulletin APBS10-02 and apply any necessary updates to help mitigate the risks.
Posted in Security Alerts | No Comments »
Tagged With: Acrobat Adobe • Address • Adobe Acrobat • Adobe Reader • Adobe Update • Arbitrary Code • Attacker • Denial Of Service • Macintosh • Necessary Updates • Reader Acrobat • Security Bulletin • Unix
October 14th, 2009 . by DarkFiber Consulting
Adobe has republished security bulletin APSB09-015 to address multiple vulnerabilities in Adobe Reader and Acrobat. These vulnerabilities may allow an attacker to execute arbitrary code, escalate local privileges, or cause a denial-of-service condition.
DarkFiber Consulting encourages users and administrators to review Adobe security bulletin APSB09-015 and apply any necessary updates.
Posted in Security Alerts | No Comments »
Tagged With: Acrobat Adobe • Acrobat Security • Adobe Acrobat • Adobe Reader • Arbitrary Code • Attacker • Denial Of Service • Necessary Updates • Privileges • Reader Acrobat • Security Bulletin • Vulnerabilities
October 14th, 2009 . by DarkFiber Consulting
Adobe has released security bulletin APSB09-15 to alert users of a critical vulnerability in Adobe Reader and Acrobat. Adobe indicates that it has received reports of active exploitation of this vulnerability. Release of an update for this vulnerability is scheduled for Tuesday, October 13.
DarkFiber Consulting encourages users and administrators to take the following actions to help mitigate the risks:
- Review Adobe Security Bulletin APSB09-15.
- Disable JavaScript in Adobe Reader and Acrobat. Acrobat JavaScript can be disabled in the General preferences dialog (Edit, Preferences, JavaScript, and un-check “Enable Acrobat JavaScript”).
Posted in Security Alerts | No Comments »
Tagged With: Acrobat Adobe • Acrobat Javascript • Adobe Acrobat • Adobe Reader • Critical Vulnerability • Reader Acrobat • Security Bulletin • Tuesday October
July 30th, 2009 . by DarkFiber Consulting
Adobe has released a security advisory to address a vulnerability in Adobe Reader and Acrobat 9.1.2 and Flash Player 9 and 10. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial-of-service condition.
DarkFiber Consulting encourages users and administrators to review the security advisory and implement the following workarounds until a fix is available:
- Disable Flash in Adobe Reader 9 on Windows platforms by renaming the following files: “%ProgramFiles%\Adobe\Reader 9.0\Reader\authplay.dll” and “%ProgramFiles%\Adobe\Reader 9.0\Reader\rt3d.dll”.
Additional information regarding this vulnerability can be found in Technical Cyber Security Alert TA09-204A.
DarkFiber Consulting will provide additional information as it becomes available.
Posted in Security Alerts | No Comments »
Tagged With: Acrobat Adobe • Address • Adobe Acrobat • Adobe Reader • Arbitrary Code • Attacker • Cyber Security • Denial Of Service • Dll Reader • Flash Content • Flash Player 9 • Flash Reader • Programfiles • Reader Acrobat • Vulnerability • Windows Platforms • Workarounds
July 2nd, 2009 . by DarkFiber Consulting
Adobe has released security updates to address multiple vulnerabilities that affect versions of Reader and Acrobat up to and including Reader 9.1.1 and Acrobat 9.1.1. These vulnerabilities may allow an attacker to execute arbitrary code or cause a denial-of-service condition.
DarkFiber Consulting encourages users and administrators to review Adobe Security Bulletin APSB09-07 and apply any necessary updates to help mitigate the risks. Additional information regarding these vulnerabilities can be found in Technical Cyber Security Alert TA09-161A.
Posted in Security Alerts | No Comments »
Tagged With: Acrobat Adobe • Acrobat Reader • Acrobat Security • Address • Adobe Acrobat • Adobe Reader • Adobe Updates • Arbitrary Code • Attacker • Cyber Security • Denial Of Service • Necessary Updates • Reader Acrobat • Security Bulletin • Security Updates • Vulnerabilities
May 9th, 2009 . by DarkFiber Consulting
DarkFiber Consulting is aware of public reports of two vulnerabilities affecting Adobe Reader and Acrobat. The JavaScript methods customDictionaryOpen() and getAnnots() do not safely handle specially crafted arguments and can be manipulated to execute arbitrary code.
DarkFiber Consulting encourages users and administrators to disable JavaScript in Adobe Reader to help mitigate the risk:
- Open the General Preferences dialog box
- From the Edit menu, select Preferences and then choose JavaScript
- Un-check Enable Acrobat JavaScript
Additional information regarding these vulnerabilities can be found in the Adobe PSIRT blog entry and in the Vulnerability Notes Database. DarkFiber Consulting will provide additional information as it becomes available.
Posted in Security Alerts | No Comments »
Tagged With: Acrobat Javascript • Adobe Acrobat • Adobe Help • Adobe Reader • Arbitrary Code • Blog • Enable Javascript • Javascript Check • Javascript Help • Javascript Methods • Menu Javascript • Reader Acrobat • Risk • Vulnerability Notes Database