Adobe Confirms Critical PDF Fix, Will Issue Bulletin
Adobe spokesperson John Cristofano sent me a statement confirming the severity of the vulnerability fixed with Adobe Reader 8.1.2 and promising that a detailed bulletin is on tap for release later. Here's the full statement. On Feb. 6, Adobe made available an update to Acrobat and Adobe Reader 8.x. It updates the Windows and Mac versions of Acrobat to 8.1.2, and the Windows, Mac, Linux and Solaris versions of Adobe Reader to 8.1.2. This is a very serious vulnerability. I've tested the Immunity proof-of-concept exploit and can confirm that the attack vector -- code execution via Internet Explorer -- is real. Apply that patch now. |
