18 Aug 2010
Adobe is to release several critical out-of-band updates on Thursday for its Reader and Acrobat software designed to patch vulnerabilities disclosed by security researchers at last month's Black Hat conference.
In an update to a security advisory issued at the beginning of this month, Adobe said that the patches target Adobe Reader 9.3.3 for Windows, Macintosh and UNIX, Adobe Acrobat 9.3.3 for Windows and Macintosh, and Adobe Reader 8.2.3 and Acrobat 8.2.3 for Windows and Macintosh.
The vulnerabilities could be used by hackers to compromise a victim's PC. Security firm Secunia said in an advisory that the at-risk versions of Acrobat/Reader bundle a vulnerable version of Adobe Player.
In addition, a flaw in TrueType could allow the running of malicious code embedded in a PDF document. "Successful exploitation may allow execution of arbitrary code," explained Secunia.
Adobe said that its next quarterly security update falls on 12 October, so the firm obviously rates these vulnerabilities important enough to patch them early.
The debate on how and when new vulnerabilities are disclosed gathered momentum recently when HP's TippingPoint announced a new initiative under which it will release all data on software flaws six months after notifying the vendor.
Security researchers who disclose vulnerabilities before the vendor responsible has had time to fix them are often pilloried by the industry.
Google engineer Tavis Ormandy was widely criticised for not giving Microsoft enough time to fix a flaw found in Windows Help and Support Center. Soon after, hackers were found to be exploiting the flaw in the wild.
Latest stories from Software
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
V3 examines the key strengths and weaknesses of Samsung's latest iPhone killer
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
Business Objects Developer - VP - Banking My leading...
C++ Programmer/ Developer/Object Orientated/ Software...
Senior Java Design Developer Banking / J2EE...
Internet Solutions Architect - Hands-on Banking experience...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?