eWeek Security Watch
Advertisement
Advertisement
February 17, 2010 1:49 PM

Adobe Patches Reader, Acrobat Flaws



Adobe Systems has issued an out-of-band security update to patch two critical vulnerabilities in Adobe PDF and Reader.

The update fixes a critical vulnerability in Adobe Reader and Acrobat versions 9.3 and 8.2 for Windows, Mac and Unix users that could be leveraged to subvert the domain sandbox and make unauthorized cross-domain requests. A second vulnerability could be exploited to cause the applications to crash and potentially allow an attacker to take control of a vulnerable system.

The patch appears to be related to an update issued last week for Adobe Flash Player. That update plugged a hole that could also be used to make cross-domain requests, and according to Adobe affected Adobe Flash Player version 10.0.42.34 and earlier.

For more on Adobe's approach to security, read eWEEK's discussion with Brad Arkin, Adobe's director of product security and privacy.

TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/19138

Post a Comment

 
 
RSS Syndication
Advertisement

CAG

SEO

Advertisement
Security Watch     Contact Us | Advertise | Site Map
eWEEK Quick LInks

Ziff Davis Enterprise