<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
   <channel>
      <title>Adobe Product Security Incident Response Team (PSIRT)</title>
      <link>http://blogs.adobe.com/psirt/</link>
      <description>Working to help protect customers from vulnerabilities in Adobe software</description>
      <language>en</language>
      <copyright>Copyright 2009</copyright>
      <lastBuildDate>Fri, 03 Jul 2009 20:02:12 -0800</lastBuildDate>
      <generator>http://www.sixapart.com/movabletype/?v=3.38</generator>
      <docs>http://blogs.law.harvard.edu/tech/rss</docs> 

            <item>
         <title>Potential ColdFusion security issue</title>
         <description><![CDATA[<p>Adobe is aware of reports of ColdFusion websites being compromised through a vulnerability in the FCKEditor rich text editor, which is installed with ColdFusion 8. Adobe is working on an update to ColdFusion to resolve the issue, which we expect to make available next week. In the meantime, ColdFusion 8 administrators are advised to mitigate this issue by following the steps below:</p>

<p>1.	Disable connectors by setting config.Enabled to false in the editor/filemanager/connectors/cfm/config.cfm file.<br />
2.	Remove unused cfm files under editor/filemanager/connectors/cfm directory of the FCKeditor.<br />
3.	Inspect FCKeditor directories for content that has already been uploaded. The uploaded files go under the directory specified in the config.UserFilesPath set in config.cfm. </p>

<p><strong>This posting is provided "AS IS" with no warranties and confers no rights.</strong><br />
</p>]]></description>
         <link>http://blogs.adobe.com/psirt/2009/07/potential_coldfusion_security.html</link>
         <guid>http://blogs.adobe.com/psirt/2009/07/potential_coldfusion_security.html</guid>
         <category></category>
         <pubDate>Fri, 03 Jul 2009 20:02:12 -0800</pubDate>
      </item>
            <item>
         <title>Security Bulletin - Adobe Shockwave Player</title>
         <description><![CDATA[<p>A <a href="http://www.adobe.com/support/security/bulletins/apsb09-08.html">Security Bulletin</a> has been posted for Shockwave Player.  Adobe is not currently aware of any exploits in the wild for this issue.</p>

<p><strong>This posting is provided "AS IS" with no warranties and confers no rights.</strong></p>]]></description>
         <link>http://blogs.adobe.com/psirt/2009/06/security_bulletin_adobe_shockw.html</link>
         <guid>http://blogs.adobe.com/psirt/2009/06/security_bulletin_adobe_shockw.html</guid>
         <category>Security Bulletins and Advisories</category>
         <pubDate>Tue, 23 Jun 2009 11:00:00 -0800</pubDate>
      </item>
            <item>
         <title>Adobe Reader for Unix updates available</title>
         <description><![CDATA[<p>We released security updates for <a href="http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Unix">Adobe Reader 9.1.2 for Unix</a> and <a href="http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Unix">Adobe Reader 8.1.6 for Unix</a> today.  Our June 9 <a href="http://www.adobe.com/support/security/bulletins/apsb09-07.html">Security Bulletin APSB09-07</a> has been updated to reflect the availability of these updates.  Adobe is not currently aware of any exploits in the wild for these issues.</p>

<p><strong>This posting is provided “AS IS” with no warranties and confers no rights.</strong><br />
</p>]]></description>
         <link>http://blogs.adobe.com/psirt/2009/06/adobe_reader_for_unix_updates.html</link>
         <guid>http://blogs.adobe.com/psirt/2009/06/adobe_reader_for_unix_updates.html</guid>
         <category>Security Bulletins and Advisories</category>
         <pubDate>Tue, 16 Jun 2009 13:49:00 -0800</pubDate>
      </item>
            <item>
         <title>Security Bulletin - Adobe Reader and Acrobat</title>
         <description><![CDATA[<p>Today we posted a <a href="http://www.adobe.com/go/apsb09-07">Security Bulletin</a> and provided Adobe Reader and Acrobat patches to our <a href="http://www.adobe.com/downloads/updates">Product Update area</a>. This is the first quarterly security update for Adobe Reader and Acrobat as described in our <a href="http://blogs.adobe.com/asset/2009/05/adobe_reader_and_acrobat_secur.html">May 20 blog post</a>, and incorporates the initial output of code hardening efforts. Today’s updates also address externally reported issues, as detailed in our Security Bulletin. Adobe is not currently aware of any exploits in the wild for these issues.</p>

<p><strong>This posting is provided “AS IS” with no warranties and confers no rights.</strong></p>]]></description>
         <link>http://blogs.adobe.com/psirt/2009/06/security_bulletin_adobe_reader_2.html</link>
         <guid>http://blogs.adobe.com/psirt/2009/06/security_bulletin_adobe_reader_2.html</guid>
         <category>Security Bulletins and Advisories</category>
         <pubDate>Tue, 09 Jun 2009 14:09:00 -0800</pubDate>
      </item>
            <item>
         <title>Adobe Security Bulletin Advance Notification</title>
         <description><![CDATA[<p>Adobe expects to deliver security updates for Adobe Reader and Acrobat versions 7.x, 8.x, and 9.x for Windows and Macintosh on Tuesday, June 9. This is the first quarterly security update for Adobe Reader and Acrobat as described in our <a href="http://blogs.adobe.com/asset/2009/05/adobe_reader_and_acrobat_secur.html">May 20 blog post</a>, and incorporates the initial output of code hardening efforts.</p>

<p>Adobe considers this a <a href="http://www.adobe.com/devnet/security/security_zone/severity_ratings.html">critical</a> update and recommends users be prepared to apply the update for their product installations. Details of where to download updates will be posted to Adobe’s <a href="http://www.adobe.com/support/security/">Security Bulletins and Advisories</a> support page on June 9.</p>

<p>Details regarding security updates for the UNIX platform will be communicated when available.</p>

<p><strong>This posting is provided “AS IS” with no warranties and confers no rights.</strong></p>]]></description>
         <link>http://blogs.adobe.com/psirt/2009/06/adobe_security_bulletin_advanc.html</link>
         <guid>http://blogs.adobe.com/psirt/2009/06/adobe_security_bulletin_advanc.html</guid>
         <category></category>
         <pubDate>Thu, 04 Jun 2009 14:58:29 -0800</pubDate>
      </item>
            <item>
         <title>Security Bulletin - Adobe Reader and Acrobat</title>
         <description><![CDATA[<p>Today, we have posted a <a href="http://www.adobe.com/go/apsb09-06">Security Bulletin</a> and provided Adobe Reader and Acrobat patches to our <a href="http://www.adobe.com/downloads/updates">Product Update area</a>.  This update resolves the vulnerabilities from <a href="http://www.adobe.com/go/apsa09-02/">Security Advisory APSA09-02</a>.  Adobe is not currently aware of any exploits in the wild for these issues.</p>

<p><strong>This posting is provided “AS IS” with no warranties and confers no rights.</strong><br />
</p>]]></description>
         <link>http://blogs.adobe.com/psirt/2009/05/security_bulletin_adobe_reader_1.html</link>
         <guid>http://blogs.adobe.com/psirt/2009/05/security_bulletin_adobe_reader_1.html</guid>
         <category>Security Bulletins and Advisories</category>
         <pubDate>Tue, 12 May 2009 14:50:59 -0800</pubDate>
      </item>
            <item>
         <title>Adobe Reader Issue Update</title>
         <description><![CDATA[<p>A <a href="http://www.adobe.com/support/security/advisories/apsa09-02.html">Security Advisory</a> has been posted in regards to the Adobe Reader vulnerability last mentioned in the Adobe PSIRT blog on April 28 (“<a href="http://blogs.adobe.com/psirt/2009/04/update_on_adobe_reader_issue.html">Update to Adobe Reader Issue</a>”, CVE-2009-1492).  We are in the process of fixing the issue, and expect to make available product updates for the relevant supported Adobe Reader and Acrobat versions and platforms by May 12th, 2009.  Adobe plans to make available Windows updates for Adobe Reader versions 9.X, 8.X, and 7.X and Acrobat versions 9.X, 8.X, and 7.X, Macintosh updates for Adobe Reader versions 9.X and 8.X and Acrobat versions 9.X and 8.X, as well as Adobe Reader for Unix versions 9.X and 8.X.</p>

<p>Additionally, we have confirmed the second vulnerability (CVE-2009-1493) for Adobe Reader for Unix (first mentioned in our April 28 post). This issue will be resolved in the upcoming Adobe Reader for Unix updates. Currently, we have not been able to reproduce an exploitable scenario for Windows and Macintosh, but we will continue to investigate. </p>

<p>In the meantime, to mitigate both issues disable JavaScript in Adobe Reader and Acrobat using the following instructions below:<br />
1. Launch Acrobat or Adobe Reader.<br />
2. Select Edit>Preferences<br />
3. Select the JavaScript Category<br />
4. Uncheck the ‘Enable Acrobat JavaScript’ option<br />
5. Click OK<br />
Adobe is in contact with Antivirus and Security vendors regarding both of these issues in order to ensure the security of our mutual customers. </p>

<p>We will continue to provide updates on these issues via the <a href="http://www.adobe.com/support/security/">Security Advisory section of the Adobe web site</a>, as well as the <a href="http://blogs.adobe.com/psirt/">Adobe PSIRT blog</a>.</p>

<p><strong>This posting is provided “AS IS” with no warranties and confers no rights.</strong><br />
</p>]]></description>
         <link>http://blogs.adobe.com/psirt/2009/05/adobe_reader_issue_update.html</link>
         <guid>http://blogs.adobe.com/psirt/2009/05/adobe_reader_issue_update.html</guid>
         <category></category>
         <pubDate>Fri, 01 May 2009 13:56:59 -0800</pubDate>
      </item>
            <item>
         <title>Security Bulletin - Flash Media Server</title>
         <description><![CDATA[<p>We’ve just posted a <a href="http://www.adobe.com/go/apsb09-05">Security Bulletin</a> and <a href="http://www.adobe.com/support/flashmediaserver/downloads_updaters.html">update for Flash Media Server</a>. The update addresses a potential privilege escalation issue in Flash Media Server. </p>

<p><strong>This posting is provided “AS IS” with no warranties and confers no rights</strong><br />
</p>]]></description>
         <link>http://blogs.adobe.com/psirt/2009/04/security_bulletin_flash_media.html</link>
         <guid>http://blogs.adobe.com/psirt/2009/04/security_bulletin_flash_media.html</guid>
         <category>Security Bulletins and Advisories</category>
         <pubDate>Thu, 30 Apr 2009 11:20:18 -0800</pubDate>
      </item>
            <item>
         <title>Update on Adobe Reader Issue</title>
         <description><![CDATA[<p>This is an update on the Adobe Reader vulnerability first discussed on the Adobe PSIRT blog on April 27 (“<a href="http://blogs.adobe.com/psirt/2009/04/potential_adobe_reader_issue.html">Potential Adobe Reader Issue</a>”).  All currently supported shipping versions of Adobe Reader and Acrobat (Adobe Reader and Acrobat 9.1, 8.1.4, and 7.1.1 and earlier versions) are vulnerable to this issue. Adobe plans to provide updates for the following supported versions and platforms to resolve this issue: Windows (9.x, 8.x, 7.x), Macintosh (9.x, 8.x) and Unix (9.x, 8.x).  We are working on a development schedule for these updates and will post a timeline as soon as possible. We are currently not aware of any reports of exploits in the wild for this issue.  To mitigate the issue disable JavaScript in Adobe Reader and Acrobat using the following instructions below:</p>

<p>1. Launch Acrobat or Adobe Reader.<br />
2. Select Edit>Preferences<br />
3. Select the JavaScript Category<br />
4. Uncheck the ‘Enable Acrobat JavaScript’ option<br />
5. Click OK</p>

<p>In addition, Adobe is in contact with Antivirus and Security vendors on this issue in order to ensure the security of our mutual customers. </p>

<p>Adobe is also currently investigating the issue posted on SecurityFocus as BID 34740. </p>

<p>We will continue to provide updates on these issues via the <a href="http://www.adobe.com/support/security">Security Advisory section of the Adobe web site</a>, as well as the <a href="http://blogs.adobe.com/psirt/">Adobe PSIRT blog</a>.</p>

<p><strong>This posting is provided “AS IS” with no warranties and confers no rights.</strong><br />
</p>]]></description>
         <link>http://blogs.adobe.com/psirt/2009/04/update_on_adobe_reader_issue.html</link>
         <guid>http://blogs.adobe.com/psirt/2009/04/update_on_adobe_reader_issue.html</guid>
         <category></category>
         <pubDate>Tue, 28 Apr 2009 13:35:10 -0800</pubDate>
      </item>
            <item>
         <title>Potential Adobe Reader Issue</title>
         <description><![CDATA[<p>Adobe is aware of reports of a potential vulnerability in Adobe Reader 9.1 and 8.1.4, as described in SecurityFocus BID 34736. We are currently investigating, and will have an update once we get more information.</p>

<p><strong>This posting is provided “AS IS” with no warranties and confers no rights</strong><br />
</p>]]></description>
         <link>http://blogs.adobe.com/psirt/2009/04/potential_adobe_reader_issue.html</link>
         <guid>http://blogs.adobe.com/psirt/2009/04/potential_adobe_reader_issue.html</guid>
         <category></category>
         <pubDate>Mon, 27 Apr 2009 18:20:50 -0800</pubDate>
      </item>
            <item>
         <title>Adobe Reader for Unix updates available</title>
         <description><![CDATA[<p>Today, we have released the <a href="http://www.adobe.com/go/apsb09-04">Adobe Reader 9.1 for Unix, and Adobe Reader 8.1.4 for Unix updates</a>. These updates resolve the JBIG2 vulnerability from <a href="http://www.adobe.com/apsa09-01/">Security Advisory APSA09-01</a> and <a href="http://www.adobe.com/go/apsb09-03/">Security Bulletin APSB09-03</a>. As mentioned previously, there are reports that this issue is being exploited.</p>

<p>In addition, the updates released today, as well as the most recent updates for Windows and Macintosh - Adobe Reader 9.1, 8.1.4, and 7.1.1, and Acrobat 9.1, 8.1.4, and 7.1.1 - address four additional, critical JBIG2 security issues. Adobe has worked with the security researchers who reported these additional issues and is communicating about them today, now that updates for all platforms are available. We appreciate the cooperation of these security researchers - Sean Larsson of <a href="http://labs.idefense.com/">iDefense Labs</a>, Jonathan Brossard from <a href="http://www.ivizsecurity.com/">iViZ Security Research Team</a>, Will Dormann of <a href="http://www.cert.org/">CERT/CC</a>, and Alin Rad Pop of <a href="http://www.secunia.com/">Secunia Research</a>. We are not aware of any exploits in the wild for any of the additional JBIG2 issues newly disclosed today in <a href="http://www.adobe.com/go/apsb09-04/">Security Bulletin APSB09-04</a>. </p>

<p><strong>This posting is provided “AS IS” with no warranties and confers no rights</strong><br />
</p>]]></description>
         <link>http://blogs.adobe.com/psirt/2009/03/adobe_reader_updates_for_linux.html</link>
         <guid>http://blogs.adobe.com/psirt/2009/03/adobe_reader_updates_for_linux.html</guid>
         <category>Security Bulletins and Advisories</category>
         <pubDate>Tue, 24 Mar 2009 12:39:24 -0800</pubDate>
      </item>
            <item>
         <title>Adobe Reader and Acrobat updates for Windows and Macintosh available</title>
         <description><![CDATA[<p>Today, we have released the <a href="http://www.adobe.com/go/apsb09-04">Acrobat 8.1.4 and 7.1.1, and Adobe Reader 8.1.4 and 7.1.1, updates for Windows and Macintosh</a>.  These updates resolve the vulnerability from <a href="http://www.adobe.com/go/apsa09-01">Security Advisory APSA09-01</a> and <a href="http://www.adobe.com/go/apsb09-03">Security Bulletin APSB09-03</a>. There are reports that this issue is being exploited.</p>

<p>In addition, the updates address other critical security issues. The Adobe Reader and Acrobat 9.1 and 7.1.1 updates resolve a critical issue that has already been addressed in the Adobe Reader 8.1.3 and Acrobat 8.1.3 updates. The Adobe Reader 7.1.1 and Acrobat 7.1.1 updates resolve critical issues previously addressed in Adobe Reader 8.1.3 and 9.0, and Acrobat 8.1.3 and 9.0.</p>

<p>Users who have previously updated to Adobe Reader 9.1 and Acrobat 9.1 for Windows and Macintosh need not take any action. Adobe now plans to make available Adobe Reader 9.1 and Adobe Reader 8.1.4 for Unix by March 24.</p>

<p><strong>This posting is provided “AS IS” with no warranties and confers no rights</strong><br />
</p>]]></description>
         <link>http://blogs.adobe.com/psirt/2009/03/adobe_reader_and_acrobat_updat.html</link>
         <guid>http://blogs.adobe.com/psirt/2009/03/adobe_reader_and_acrobat_updat.html</guid>
         <category>Security Bulletins and Advisories</category>
         <pubDate>Wed, 18 Mar 2009 11:10:16 -0800</pubDate>
      </item>
            <item>
         <title> Adobe Reader and Acrobat 9.1 update available</title>
         <description><![CDATA[<p>Today, we posted the Adobe Reader 9.1 and Acrobat 9.1 update, which resolves the recent JBIG2 security issue (CVE-2009-0658), including the ‘no-click’ variant of the vulnerability. We encourage all Adobe Reader users to download and install the free Adobe Reader 9.1. The Adobe Reader 9.1 update is available <a href="http://get.adobe.com/reader">here</a>. Acrobat 9 users should refer to the <a href="http://www.adobe.com/go/apsb09-03/">Security Bulletin</a> for download details. We expect updates for Adobe Reader 7 and 8, and Acrobat 7 and 8, to be available by March 18. In addition, Adobe plans to make available Adobe Reader 9.1 for Unix by March 25. In the meantime, for Adobe Reader 7 and 8 users who are unable to update to Adobe Reader 9.1, as well as Acrobat 7 and 8 users, more information on immediate protection for this issue from anti-virus and security vendors is available <a href="http://blogs.adobe.com/psirt/2009/02/adobe_reader_and_acrobat_issue_2.html">in the post directly below</a>.</p>

<p><strong>This posting is provided “AS IS” with no warranties and confers no rights</strong></p>]]></description>
         <link>http://blogs.adobe.com/psirt/2009/03/_adobe_reader_and_acrobat_91_u.html</link>
         <guid>http://blogs.adobe.com/psirt/2009/03/_adobe_reader_and_acrobat_91_u.html</guid>
         <category>Security Bulletins and Advisories</category>
         <pubDate>Tue, 10 Mar 2009 11:19:57 -0800</pubDate>
      </item>
            <item>
         <title>Adobe Reader and Acrobat Issue update</title>
         <description><![CDATA[<p>This is an update on the Adobe Reader and Acrobat issue (CVE-2009-0658) discussed in <a href="http://www.adobe.com/go/apsa09-01/">Security Advisory APSA09-01</a>. As mentioned previously, Adobe currently plans to make available an update for Adobe Reader 9 and Acrobat 9 by March 11th. In addition, Adobe is also planning to make updates available for Adobe Reader 7 and 8, and Acrobat 7 and 8, by March 18th. </p>

<p>We have seen reports that disabling JavaScript in Adobe Reader and Acrobat can protect users from this issue. Disabling JavaScript provides protection against currently known attacks. However, the vulnerability is not in the scripting engine and, therefore, disabling JavaScript does not eliminate all risk. Keeping this in mind, should users choose to disable JavaScript, it can be accomplished following the instructions below:</p>

<p>1.         Launch Acrobat or Adobe Reader.<br />
2.         Select Edit>Preferences<br />
3.         Select the JavaScript Category<br />
4.         Uncheck the ‘Enable Acrobat JavaScript’ option<br />
5.         Click OK</p>

<p>In addition, Adobe continues its contact with Antivirus and Security vendors on this issue in order to ensure the security of our mutual customers. We are now able to report that the following Antivirus and Security vendors and related products provide protections and information regarding this vulnerability:</p>

<p><strong>Bitdefender</strong></p>

<p>BitDefender has provided info that their customers using the following products are protected from attacks against this exploit:  </p>

<p>•	BitDefender Antivirus 2009:  <a href="http://www.bitdefender.com/PRODUCT-2216-en--BitDefender-Antivirus-2009.html">http://www.bitdefender.com/PRODUCT-2216-en--BitDefender-Antivirus-2009.html</a><br />
•	BitDefender Internet Security 2009: <a href="http://www.bitdefender.com/PRODUCT-2217-en--BitDefender-Internet-Security-2009.html">http://www.bitdefender.com/PRODUCT-2217-en--BitDefender-Internet-Security-2009.html</a><br />
•	BitDefender Total Security 2009:  <a href="http://www.bitdefender.com/PRODUCT-2214-en--BitDefender-Total-Security-2009.html">http://www.bitdefender.com/PRODUCT-2214-en--BitDefender-Total-Security-2009.html</a></p>

<p><br />
<strong>Checkpoint:</strong><br />
Check Point customers using Check Point Security Gateway products are protected from attacks exploiting this vulnerability, provided that the appropriate protection is activated. For more details and precise list of products, see <a href="http://www.checkpoint.com/defense/advisories/public/2009/sbp-24-Feb.html ">http://www.checkpoint.com/defense/advisories/public/2009/sbp-24-Feb.html </a></p>

<p><strong>F-Secure</strong><br />
F-Secure Anti-Virus 2009:<br />
<a href="http://www.f-secure.com/home_user/products_a-z/fsav2009.html">http://www.f-secure.com/home_user/products_a-z/fsav2009.html</a><br />
F-Secure Internet Security 2009:<br />
<a href="http://www.f-secure.com/home_user/products_a-z/fsis2009.html">http://www.f-secure.com/home_user/products_a-z/fsis2009.html</a><br />
F-Secure Client Security: <br />
<a href="http://www.f-secure.com/small_businesses/products/fscs.html">http://www.f-secure.com/small_businesses/products/fscs.html</a><br />
F-Secure Online Scanner (free to use):<br />
<a href="http://support.f-secure.com/enu/home/ols.shtml">http://support.f-secure.com/enu/home/ols.shtml</a><br />
F-Secure Anti-Virus for Windows Servers:<br />
<a href="http://www.f-secure.com/small_businesses/products/fsavsrv.html">http://www.f-secure.com/small_businesses/products/fsavsrv.html</a><br />
F-Secure Internet Gatekeeper (Windows and Linux)<br />
<a href="http://www.f-secure.com/small_businesses/products/fsigk.html">http://www.f-secure.com/small_businesses/products/fsigk.html</a><br />
F-Secure Anti-Virus for MS Exchange:<br />
<a href="http://www.f-secure.com/small_businesses/products/fsavmse.html">http://www.f-secure.com/small_businesses/products/fsavmse.html</a><br />
F-Secure Secure Messaging Gateway:<br />
<a href="http://www.f-secure.com/small_businesses/products/fsmsgx.html">http://www.f-secure.com/small_businesses/products/fsmsgx.html</a></p>

<p><br />
<strong>McAfee:</strong><br />
Enterprise: <a href="http://www.mcafee.com/us/enterprise/products/system_security/servers/virusscan_enterprise.html">http://www.mcafee.com/us/enterprise/products/system_security/servers/virusscan_enterprise.html</a><br />
Consumer: <a href="http://us.mcafee.com/">http://us.mcafee.com/</a><br />
Desktop: <a href="http://www.mcafee.com/us/enterprise/products/system_security/clients/host_intrusion_prevention_desktop_server.html">http://www.mcafee.com/us/enterprise/products/system_security/clients/host_intrusion_prevention_desktop_server.html</a><br />
Server: <a href="http://www.mcafee.com/us/enterprise/products/system_security/servers/host_intrusion_prevention_server.html">http://www.mcafee.com/us/enterprise/products/system_security/servers/host_intrusion_prevention_server.html</a><br />
Intrushield - Network IPS: <a href="http://www.mcafee.com/us/enterprise/products/network_intrusion_prevention/network_security_platform.html">http://www.mcafee.com/us/enterprise/products/network_intrusion_prevention/network_security_platform.html</a></p>

<p><strong>Microsoft:</strong><br />
Microsoft Corporation products protecting against Exploit:Win32/Pidief and variants:<br />
<a href="http://www.microsoft.com/forefront/clientsecurity">Microsoft Forefront Client Security</a><br />
<a href="http://onecare.live.com/">Microsoft Windows Live OneCare</a><br />
<a href="http://safety.live.com/">Microsoft Windows Live OneCare safety scanner</a></p>

<p><strong>Sophos</strong><br />
Here is the list of Sophos products that protect in one way or another against exploits attempting to exploit the vulnerability:</p>

<p>Sophos Endpoint Security and Control - <a href="http://www.sophos.com/products/enterprise/endpoint/security-and-control/8.0/">http://www.sophos.com/products/enterprise/endpoint/security-and-control/8.0/</a> using HIPS buffer overflow protection and anti-malware protection engine.<br />
Sophos Web Security Appliance - <a href="http://www.sophos.com/products/enterprise/web/security-and-control/">http://www.sophos.com/products/enterprise/web/security-and-control/</a>, using anti-malware protection engine and URL filtering.<br />
Sophos PureMessage (all platforms) - <a href="http://www.sophos.com/products/enterprise/email/security-and-control/">http://www.sophos.com/products/enterprise/email/security-and-control/</a>, using anti-malware and anti-spam protection engines.</p>

<p><br />
<strong>Symantec:</strong><br />
Norton Antivirus 2009  (and earlier supported version) <a href="http://www.symantec.com/norton/antivirus">http://www.symantec.com/norton/antivirus</a><br />
Norton Internet Security 2009 (and earlier supported version) <a href="http://www.symantec.com/norton/internet-security">http://www.symantec.com/norton/internet-security</a><br />
Norton 360      <a href="http://www.symantec.com/norton/360">http://www.symantec.com/norton/360</a><br />
Symantec Endpoint Protection 11 <a href="http://www.symantec.com/business/endpoint-protection">http://www.symantec.com/business/endpoint-protection</a><br />
Symantec AntiVirus 10 (and earlier supported version) <a href="http://www.symantec.com/business/security_response/definitions.jsp">http://www.symantec.com/business/security_response/definitions.jsp</a><br />
Symantec AntiVirus for CacheFlow Security Gateway <a href="http://www.symantec.com/business/antivirus-for-caching">http://www.symantec.com/business/antivirus-for-caching</a><br />
Symantec AntiVirus for Inktomi Traffic Edge  <a href="http://www.symantec.com/business/security_response/definitions.jsp">http://www.symantec.com/business/security_response/definitions.jsp</a><br />
Symantec AntiVirus for NetApp Filer/NetCache <a href="http://www.symantec.com/business/security_response/definitions.jsp">http://www.symantec.com/business/security_response/definitions.jsp</a><br />
Symantec Mail Security for Domino v 5.x (and earlier supported version) <a href="http://www.symantec.com/business/mail-security-for-domino">http://www.symantec.com/business/mail-security-for-domino</a><br />
Symantec Mail Security for Microsoft Exchange v 5.x (and earlier supported version) <a href="http://www.symantec.com/business/mail-security-for-microsoft-exchange">http://www.symantec.com/business/mail-security-for-microsoft-exchange</a><br />
Symantec Mail Security for SMTP v 5.x (and earlier supported version) <a href="http://www.symantec.com/business/mail-security-for-smtp">http://www.symantec.com/business/mail-security-for-smtp</a><br />
Symantec Web Security 3.0 (and earlier supported version) <a href="http://www.symantec.com/business/security_response/definitions.jsp">http://www.symantec.com/business/security_response/definitions.jsp</a><br />
Symantec AntiVirus for Bluecoat Security Gateway <a href="http://www.symantec.com/business/security_response/definitions.jsp">http://www.symantec.com/business/security_response/definitions.jsp</a><br />
Symantec AntiVirus for Clearswift MIMESweeper <a href="http://www.symantec.com/business/security_response/definitions.jsp">http://www.symantec.com/business/security_response/definitions.jsp</a><br />
Symantec AntiVirus for Microsoft ISA Server <a href="http://www.symantec.com/business/security_response/definitions.jsp">http://www.symantec.com/business/security_response/definitions.jsp</a><br />
Symantec AntiVirus Scan Engine <a href="http://www.symantec.com/business/security_response/definitions.jsp">http://www.symantec.com/business/security_response/definitions.jsp</a><br />
Symantec AntiVirus for Linux <a href="http://www.symantec.com/business/endpoint-protection">http://www.symantec.com/business/endpoint-protection</a><br />
Symantec Brightmail Gateway <a href="http://www.symantec.com/business/brightmail-gateway">http://www.symantec.com/business/brightmail-gateway</a><br />
<strong><br />
Sourcefire:</strong><br />
Users/Customers of Sourcefire, Snort and ClamAV are protected against this vulnerability.</p>

<p>Sourcefire 3D System<br />
<a href="http://www.sourcefire.com/products/snort/rules/advisories/sa022009.html ">http://www.sourcefire.com/products/snort/rules/advisories/sa022009.html </a></p>

<p>OpenSource Snort<br />
<a href="http://www.snort.org/vrt/advisories/vrt-rules-2009-02-20.html ">http://www.snort.org/vrt/advisories/vrt-rules-2009-02-20.html </a><br />
<a href="http://www.snort.org/vrt/advisories/vrt-rules-2009-02-24.html ">http://www.snort.org/vrt/advisories/vrt-rules-2009-02-24.html </a></p>

<p>ClamAV<br />
<a href="http://www.clamav.net">http://www.clamav.net</a></p>

<p><strong>Trend Micro:</strong><br />
Product link: <a href="http://us.trendmicro.com/us/products/enterprise/officescan-client-server-edition/index.html">http://us.trendmicro.com/us/products/enterprise/officescan-client-server-edition/index.html</a><br />
Overview: <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FPIDIEF%2EIN">http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FPIDIEF%2EIN</a></p>

<p>We will continue to provide updates on this issue via Adobe’s Security Advisory and the PSIRT blog.</p>

<p><strong>This posting is provided “AS IS” with no warranties and confers no rights</strong><br />
</p>]]></description>
         <link>http://blogs.adobe.com/psirt/2009/02/adobe_reader_and_acrobat_issue_2.html</link>
         <guid>http://blogs.adobe.com/psirt/2009/02/adobe_reader_and_acrobat_issue_2.html</guid>
         <category></category>
         <pubDate>Tue, 24 Feb 2009 17:46:26 -0800</pubDate>
      </item>
            <item>
         <title>Security Bulletins – Flash Player and RoboHelp</title>
         <description><![CDATA[<p>We have just published a <a href="http://www.adobe.com/go/apsb09-01">Security Bulletin </a>and <a href="http://get.adobe.com/flashplayer">corresponding updates for Flash Player</a>, and a <a href="http://www.adobe.com/go/apsb09-02">Security Bulletin and updates for RoboHelp</a>. The RoboHelp Security Bulletin addresses two issues; one of them only affects RoboHelp Server installations. </p>

<p><strong>This posting is provided “AS IS” with no warranties and confers no rights</strong><br />
</p>]]></description>
         <link>http://blogs.adobe.com/psirt/2009/02/security_bulletins_flash_playe_2.html</link>
         <guid>http://blogs.adobe.com/psirt/2009/02/security_bulletins_flash_playe_2.html</guid>
         <category>Security Bulletins and Advisories</category>
         <pubDate>Tue, 24 Feb 2009 13:44:32 -0800</pubDate>
      </item>
      
   </channel>
</rss>
