06 Aug 2010
Adobe is to release an out-of-cycle patch next week to fix a critical flaw in its Acrobat and Reader platforms.
The company said in a security advisory that the attack vector is a flaw in TrueType that allows the running of malicious code embedded in a PDF document.
The problem was discovered by Charlie Miller, principal analyst at Independent Security Evaluators, and disclosed in a research document (PDF) at this year's Black Hat conference.
"The vulnerability is caused by an integer overflow error in CoolType.dll when parsing the 'maxCompositePoints' field value in the 'maxp' table of a TrueType font," said Secunia in a security advisory.
"This can be exploited to corrupt memory via a PDF file containing a specially crafted TrueType font. Successful exploitation may allow execution of arbitrary code."
The flaw affects Adobe Reader 9.3.3 for Windows, Macintosh and Unix, Acrobat 9.3.3 for Windows and Macintosh, and Reader 8.2.3 and Acrobat 8.2.3 for Windows and Macintosh.
Miller discovered the problem while testing a new security tool called BitBlaze. He did not publish exploit code, but gave enough details to allow exploit code to be designed.
"The updates will address critical security issues in the products, including CVE-2010-2862 which was discussed at the Black Hat USA 2010 security conference on July 28 2010," said Adobe's Product Security Incident Response team in a blog post.
The team also said that, as far as it is aware, no attacks have yet been found in the wild.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Hands on with the highly anticipated Android 4.0 Ice Cream Sandwich hybrid tablet
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
My client a leading company in the education and qualification...
Incident Manager - Investment banking Fantastic opportunity...
Senior Product Manager - Broadband Zen Internet...
Senior C# Developer - Reigate: £60,000 to £80,000 + benefits...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
adobe flaw
seems to be a regular thing with adobe of late perhaps it time to think about looking elsewhere for similar software alternatives
Posted by: neil2047 06 Aug 2010