October 14, 2009, 9:50AM

Adobe Ships 29 Patches for Reader and Acrobat

On the same day that Microsoft unleashed a torrent of 34 patches on its customer base, Adobe on Tuesday published patches for 29 vulnerabilities in its Acrobat and Reader products as part of its new quarterly patch release program.

The Adobe vulnerabilities patched yesterday include a remote code-execution vulnerability found in Adobe Reader and Acrobat that is already being used by attackers. The flaw is a heap overflow and the SANS Internet Storm Center reports that it has been under attack in the wild since last week. Adobe's security team said that there are some mitigations that can protect customers against the attacks, even before the patch is installed.

Adobe Reader and Acrobat 9.1.3 customers with DEP enabled on Windows Vista will be protected from this exploit. Disabling JavaScript also mitigates against this specific exploit, although a variant that does not rely on JavaScript could be possible. In the meantime, Adobe is also in contact with Antivirus and Security vendors regarding the issue and recommends users keep their anti-virus definitions up to date.

Adobe has rated the huge batch of fixes as critical and recommends that customers install the package immediately.


Shorten URL: http://threatpost.com/en_us/lHx. Click to copy to clipboard or post to Twitter

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
CAPTCHA
Please enter the two words below to help prevent spam.
Incorrect please try again
Enter the words above: Enter the numbers you hear:

 

Copyright © 2010 threatpost.com | Terms of Service | Privacy