Channel Register

Adobe update foils Reader and Acrobat exploits

Bugs provoke PDF botnet risk warning

Free whitepaper – The future of SaaS and IT infrastructure management

Adobe pushed out an update to its Reader and Acrobat packages on Monday to close a pair of critical flaws in the popular packages.

Patches to version 8.1.2 of each application resolves vulnerabilities which create a means for miscreants to drop malware onto vulnerable systems. Users of earlier versions of the software (Adobe Reader 7.1.0 and Acrobat 7.1.0) are not at risk from the bug. Version 9 of each package - due to appear next month - are also safe, Adobe reports.

The software developer credits boffins at the Johns Hopkins University Applied Physics Laboratory for discovering the flaw. Adobe's description of the bugs explains their impact but fails to reveal much about the source of the problem.

"A critical vulnerability has been identified in Adobe Reader and Acrobat 8.1.2 and earlier versions. This vulnerability would cause the application to crash and could potentially allow an attacker to take control of the affected system," it said.

The SANS Institute's Internet Storm Center warns that the vulnerability might lend itself to botnet exploitation. It advises users to update their systems sooner rather than later. ®

Free whitepaper – Why email fails

Don’t Miss

Pirates ahoy!Sign up, sign up for The Register IT security newsletter

Narrowcasting for the email classes

SunFormer top Sun exec mourns end of a franchise

Watermelons, Elton John, and killing SGI

HTC Touch Diamond 2Win an HTC Touch Diamond2!

Reg Lucky Draw Last call for iPhone botherer promo

thumbs down teaser 75Disties braced for autumn reseller collapses

Is that why they call it fall?