Posts tagged "Acrobat"

Prenotification: Quarterly Security Updates for Adobe Reader and Acrobat

A prenotification Security Advisory has been posted in regards to the upcoming quarterly Adobe Reader and Acrobat updates scheduled for Tuesday, February 8, 2011. The updates will address critical security issues in the products.

We will continue to provide updates on the upcoming release via the Security Advisory section of the Adobe website as well as the Adobe PSIRT blog.

This posting is provided “AS IS” with no warranties and confers no rights.

Security updates released for Adobe Reader and Acrobat (APSB10-28)

Today, a Security Bulletin (APSB10-28) has been posted regarding security releases for Adobe Reader and Acrobat.  The updates address critical security issues in the products, including CVE-2010-3654 noted in Security Advisory APSA10-05 and CVE-2010-4091 referenced in the Adobe PSIRT blog (“Potential issue in Adobe Reader“), as well as the vulnerabilities addressed in the November 4 Adobe Flash Player update as noted in Security Bulletin APSB10-26.  Adobe recommends that users apply the updates for their product installations.

Note that today’s updates represent and out-of-cycle release.  The next quarterly security updates for Adobe Reader and Acrobat are scheduled for February 8, 2011.

This posting is provided “AS IS” with no warranties and confers no rights.

Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat (APSA10-05)

A Security Advisory (APSA10-05) has been posted in regards to a new Flash Player, Adobe Reader and Acrobat issue (CVE-2010-3654). A critical vulnerability exists in Adobe Flash Player 10.1.85.3 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems; Adobe Flash Player 10.1.95.2 and earlier versions for Android; and the authplay.dll component that ships with Adobe Reader 9.4 and earlier 9.x versions for Windows, Macintosh and UNIX operating systems, and Adobe Acrobat 9.4 and earlier 9.x versions for Windows and Macintosh operating systems. This vulnerability (CVE-2010-3654) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against Adobe Reader and Acrobat 9.x. Adobe is not currently aware of attacks targeting Adobe Flash Player.

Adobe Reader and Acrobat 8.x, and Adobe Reader for Android are confirmed not vulnerable. Mitigations for Adobe Reader and Acrobat 9.x are included in the Security Advisory.

We are in the process of finalizing a fix for the issue and expect to provide an update for Adobe Flash Player 10.x for Windows, Macintosh, Linux and Android by November 9, 2010. We expect to make available an update for Adobe Reader and Acrobat 9.4 and earlier 9.x versions during the week of November 15, 2010.

We will continue to provide updates on this issue via the Security Advisory section of the Adobe website as well as the Adobe PSIRT blog.

This posting is provided “AS IS” with no warranties and confers no rights.

Security updates released for Adobe Reader and Acrobat

Today, a Security Bulletin has been posted in regards to this quarter’s security updates for Adobe Reader and Acrobat. The updates address critical security issues in the products, including CVE-2010-2883 referenced in Security Advisory APSA10-02 and CVE-2010-2884 referenced in the Adobe Flash Player Security Bulletin APSB10-22. Adobe recommends that users apply the updates for their product installations.

Note that today’s updates represent an accelerated release of the quarterly security update originally scheduled for October 12, 2010. With this accelerated schedule, Adobe will not release additional updates for Adobe Reader and Acrobat on October 12, 2010. The next quarterly security updates for Adobe Reader and Acrobat are scheduled for February 8, 2011.

This posting is provided “AS IS” with no warranties and confers no rights.

Prenotification: Quarterly Security Updates for Adobe Reader and Acrobat

A prenotification Security Advisory has been posted in regards to the upcoming quarterly Adobe Reader and Acrobat updates scheduled for October 5, 2010. The updates will address critical security issues in the products, including CVE-2010-2883 referenced in Security Advisory APSA10-02 and CVE-2010-2884 referenced in the Adobe Flash Player Security Bulletin APSB10-22. These security updates will be made available for Windows, Macintosh and UNIX.

Note that the October 5, 2010 updates represent an accelerated release of the next quarterly security update originally scheduled for October 12, 2010. With this accelerated schedule, Adobe will not release additional updates for Adobe Reader and Acrobat on October 12, 2010.

We will continue to provide updates on the upcoming release via the Security Advisory section of the Adobe website as well as the Adobe PSIRT blog.

This posting is provided “AS IS” with no warranties and confers no rights.

Schedule Update to Security Advisory for Adobe Reader and Acrobat (APSA10-02)

We just updated the Security Advisory (APSA10-02) posted on Wednesday, September 8, 2010 to include the planned schedule for a patch to resolve CVE-2010-2883. Adobe plans to make available updates for Adobe Reader and Acrobat 9.3.4 for Windows, Macintosh and UNIX during the week of October 4, 2010. In the meantime, we have provided a mitigation option for Windows users; see the Security Advisory for details.

Please note that these Adobe Reader and Acrobat updates represent an accelerated release of the next quarterly security updates originally scheduled for October 12, 2010. With this accelerated schedule, we do not plan to release any new updates for Adobe Reader and Acrobat on October 12, 2010.

We will continue to provide updates on this issue via the Security Advisory section of the Adobe website as well as the Adobe PSIRT blog.

This posting is provided “AS IS” with no warranties and confers no rights.

Update to Security Advisory for Adobe Reader and Acrobat (APSA10-02)

We just updated the Security Advisory (APSA10-02) posted on Wednesday, September 8, 2010 with a mitigation option for Windows users.

We will continue to provide updates on this issue via the Security Advisory section of the Adobe website as well as the Adobe PSIRT blog.

This posting is provided “AS IS” with no warranties and confers no rights.

Security Advisory for Adobe Reader and Acrobat

A Security Advisory has been posted in regards to a new Adobe Reader and Acrobat issue (CVE-2010-2883). A critical vulnerability exists in Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild.

We will continue to provide updates on this issue via the Security Advisory section of the Adobe website as well as the Adobe PSIRT blog.

This posting is provided “AS IS” with no warranties and confers no rights.

Security updates released for Adobe Reader and Acrobat

Today, a Security Bulletin has been posted regarding security releases for Adobe Reader and Acrobat. The updates address critical security issues in the products, including CVE-2010-2862 discussed at the recent Black Hat USA 2010 security conference and vulnerabilities addressed in the August 10 Adobe Flash Player update as noted in Security Bulletin APSB10-16. Adobe recommends that users apply the updates for their product installations.

Note that today’s updates represent an out-of-cycle release. The next quarterly security updates for Adobe Reader and Acrobat is scheduled for October 12, 2010.

This posting is provided “AS IS” with no warranties and confers no rights.

Prenotification: Out-of-band Security Updates for Adobe Reader and Acrobat

A Security Advisory has been posted in regards to upcoming Adobe Reader and Acrobat updates scheduled for Thursday, August 19, 2010. The updates will address critical security issues in the products, including CVE-2010-2862 discussed at the Black Hat USA 2010 security conference and the Adobe Flash Player update as noted in Security Bulletin APSB10-16. These security updates will be made available for Windows, Macintosh and UNIX.

At this time Adobe is not aware of exploits in the wild for any of the issues addressed in this Security Advisory.

Note that these updates represent an out-of-cycle release. Adobe will release the next quarterly security update for Adobe Reader and Acrobat on October 12, 2010.

We will continue to provide updates on the upcoming release via the Security Advisory section of the Adobe website as well as the Adobe PSIRT blog.

This posting is provided “AS IS” with no warranties and confers no rights.

Thursday, August 19, 2010