{"id":20,"date":"2010-01-05T12:57:38","date_gmt":"2010-01-05T17:57:38","guid":{"rendered":"http:\/\/williamscomputers.com\/?p=20"},"modified":"2010-01-05T12:57:38","modified_gmt":"2010-01-05T17:57:38","slug":"security-advisory-for-adobe-reader-and-acrobat","status":"publish","type":"post","link":"https:\/\/williamscomputers.com\/?p=20","title":{"rendered":"Security Advisory for Adobe Reader and Acrobat"},"content":{"rendered":"<p>From Adobe<\/p>\n<p><strong>Vulnerability identifier:<\/strong> APSA09-07<\/p>\n<p><strong>CVE number:<\/strong> CVE-2009-4324<\/p>\n<p><strong>Platform:<\/strong> All Platforms<\/p>\n<h3>Summary<\/h3>\n<p>Adobe has confirmed a critical vulnerability in Adobe Reader and Acrobat 9.2  and earlier versions that could cause a crash and potentially allow an attacker  to take control of the affected system. There are reports that this  vulnerability is being actively exploited in the wild. Adobe recommends  customers follow the mitigation guidance below until a patch is available.<\/p>\n<p>Adobe plans to make available an update to Adobe Reader and Acrobat by  January 12, 2010 to resolve the issue.<\/p>\n<h3>Affected software versions<\/h3>\n<p>Adobe Reader 9.2 and earlier versions for Windows, Macintosh, and UNIX<br \/>\nAdobe Acrobat 9.2 and earlier versions for Windows and Macintosh<\/p>\n<h3>Solution<\/h3>\n<p>Customers using Adobe Reader or Acrobat versions 9.2 or 8.1.7 can utilize the  JavaScript Blacklist Framework to prevent this vulnerability. Please<a href=\"http:\/\/go.adobe.com\/kb\/ts_cpsid_53237_en-us\"> refer to the TechNote<\/a> for more information.<\/p>\n<p>Customers who are not able to utilize the JavaScript Blacklist functionality  can mitigate the issue by disabling JavaScript in Adobe Reader and Acrobat using  the instructions below:<br \/>\n1. Launch Acrobat or Adobe Reader.<br \/>\n2. Select  Edit&gt;Preferences<br \/>\n3. Select the JavaScript Category<br \/>\n4. Uncheck the  &#8221;Enable Acrobat JavaScript&#8221; option<br \/>\n5. Click OK<\/p>\n<p>Customers using Microsoft DEP (&#8220;Data Execution Prevention&#8221;) functionality  available in certain versions of Microsoft Windows are at reduced risk in the  following configurations:<\/p>\n<ul>\n<li>All versions of Adobe Reader 9 running on Windows Vista SP1 or Windows 7<\/li>\n<li>Acrobat 9.2 running on Windows Vista SP1 or Windows 7<\/li>\n<li>Acrobat and Adobe Reader 9.2 running on Windows XP SP3<\/li>\n<li>Acrobat and Adobe Reader 8.1.7 running on Windows XP SP3, Windows Vista SP1,  or Windows 7<\/li>\n<\/ul>\n<p>With the DEP mitigation in place, the impact of this exploit has been reduced  to a Denial of Service during our testing.<\/p>\n<h3>Severity rating<\/h3>\n<p>Adobe categorizes this as a <a href=\"http:\/\/www.adobe.com\/devnet\/security\/security_zone\/severity_ratings.html\">critical<\/a> issue and recommends that users follow the mitigation guidance above until a  patch is available.<\/p>\n<h3>Details<\/h3>\n<p>Adobe has confirmed a critical vulnerability in Adobe Reader and Acrobat 9.2  and earlier versions that could cause a crash and potentially allow an attacker  to take control of the affected system. There are reports that this  vulnerability is being actively exploited in the wild. Adobe recommends  customers follow the mitigation guidance above until a patch is available. Adobe  plans to make available an update to Adobe Reader and Acrobat by January 12,  2010 to resolve the issue.<\/p>\n<p>Adobe actively shares information about this and other vulnerabilities with  partners in the security community to enable them to quickly develop detection  and quarantine methods to protect users until a patch is available. Adobe  recommends that you keep your anti-malware software and definitions up-to-date  and monitor releases from your vendor about this issue.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>From Adobe Vulnerability identifier: APSA09-07 CVE number: CVE-2009-4324 Platform: All Platforms Summary Adobe has confirmed a critical vulnerability in Adobe Reader and Acrobat 9.2 and earlier versions that could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-20","post","type-post","status-publish","format-standard","hentry","category-virusalerts"],"_links":{"self":[{"href":"https:\/\/williamscomputers.com\/index.php?rest_route=\/wp\/v2\/posts\/20","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/williamscomputers.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/williamscomputers.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/williamscomputers.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/williamscomputers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=20"}],"version-history":[{"count":0,"href":"https:\/\/williamscomputers.com\/index.php?rest_route=\/wp\/v2\/posts\/20\/revisions"}],"wp:attachment":[{"href":"https:\/\/williamscomputers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=20"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/williamscomputers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=20"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/williamscomputers.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=20"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}