17 Dec 2009
Adobe has sought to explain to customers the reason for its delaying until mid-January the patch for a newly found critical vulnerability currently being exploited in the wild.
An Adobe security advisory said that the flaw, which V3.co.uk first reported on Tuesday, affects Adobe Reader and Acrobat 9.2 and earlier versions, and "could cause a crash and potentially allow an attacker to take control of the affected system".
In a blog posting yesterday, Adobe director of product security and privacy Brad Arkin tried to explain why the firm will not release a patch for the flaw until 12 January, even though it has admitted that there are reports of it currently being exploited.
He argued that, if the security team worked on an out-of-cycle update, it would take two to three weeks and "negatively impact the timing of the next quarterly security update".
"The team determined that, by putting additional resources over the holidays towards the engineering and testing work required to ship a high confidence fix for this issue with low risk of introducing any new problems, they could deliver the fix as part of the quarterly update on January 12 2010," he explained.
In the meantime, Adobe is recommending that customers either disable JavaScript in Reader and Acrobat or, for those running versions 9.2 or 8.1.7, to use the JavaScript Blacklist Framework.
Latest stories from Security
Related videos
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
V3 examines the key strengths and weaknesses of Samsung's latest iPhone killer
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
Service Manager - Technology Managed Services, Service...
Reporting to the Managing Director, the role of the Client...
Senior Technical Support/ Support Engineer...
Job Purpose To analyse system requirements...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
How to get Acrobat 9.2 without
the additional and UNWANTED 15Mb Adobe Air ? Why do they and Apple (try getting Quick Time without iTunes) push stuff we don't need or want ?
Posted by: Martin 17 Dec 2009