March 2009 in-the-Wild Adobe Reader Vulnerability Information

Adobe Released a second wave of Updates in the A.P.S.B.-09-04 advisory for Acrobat and Reader 07 and 08. These Patches were Released in response to the discovery of a Vulnerability affecting J.B.I.G.2 data inside malformed P.D.F. documents. Patches for both Acrobat and Reader 09 were released in the A.P.S.B.-09-03 advisory on March 10, 2009. Adobe has stated that Patches for Unix Versions of the software will be Released on March 24, 2009.

Security Updates for Adobe Acrobat 07/08 and Reader 07/08:
http://www.adobe.com/support/security/bulletins/apsb09-04.html.

Security Updates for Adobe Acrobat 09 and Reader 09:
http://www.adobe.com/support/security/bulletins/apsb09-03.html.

We strongly advise all Users to Update to the Latest Version of Acrobat and Reader as soon as possible, because Public Exploits for the associated Vulnerability are Available. In-the-Wild Exploitation is known to have been going on for some time now. Users who cannot Update immediately should refer to the workarounds and mitigating strategies suggested by symantec and Adobe.

Adobe Acrobat and Reader P.D.F. File Handling J.B.I.G.2 Image Remote Code Execution Vulnerability:
http://www.securityfocus.com/bid/33751.

 

Message Edited by Floating_Red on 03-19-2009 10:40 PM
Message Edited by Floating_Red on 03-19-2009 10:43 PM