<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: adobe]]></title>
    <link>http://securityratty.com/tag/adobe</link>
    <description></description>
    <pubDate>Thu, 29 May 2008 11:59:09 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Why You Should Update Acrobat]]></title>
      <link>http://securityratty.com/article/b15fbd65c0aac92c5f17dce407a98803</link>
      <guid>http://securityratty.com/article/b15fbd65c0aac92c5f17dce407a98803</guid>
      <description><![CDATA[Did you know that there's a secret plan by ISPs to kill off the Internet as we know it and replace it with a TV-like subscription? This scandalous news may not be in the mainstream media, but you can...]]></description>
      <content:encoded><![CDATA[Did you know that there's a secret plan by ISPs to kill off the Internet as we know it and replace it with a TV-like subscription? This scandalous news may not be in the mainstream media, but you can read it in <a href="https://forums.symantec.com/syment/blog/article?blog.id=spam&message.id=109#M109" target="_blank">a spam message reported on by the Symantec Security Response blog.</a>

The scam about the Internet TV conspiracy is more interesting than the average spam, but what's really interesting here is the attachment to the e-mail, which is a malicious Acrobat file detected by Symantec's products as <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2007-102310-3513-99" target="_blank">Trojan.Pidief.A</a> that exploits <a href="http://blogs.pcmag.com/securitywatch/2007/10/time_to_update_some_versions_o.php" target="_blank">a famous Adobe Acrobat vulnerability announced in 2007.</a>

That vulnerability affected versions of Acrobat up to 8.1 on Windows XP (not Vista) and was only patched in the 8.x generation. 7.x users were left to the wolves.

Acrobat is one of those core applications now that is critical for almost anyone and heavily attacked. If you're not going to be aggressive about applying updates, you really should look at using an alternative reader.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=b48f776e0139e617211ff45b097f82db" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=b48f776e0139e617211ff45b097f82db" style="display: none;" border="0" height="1" width="1" alt=""/><img src="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~4/338277676" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 13 Jul 2008 04:37:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/acrobat">acrobat</category>
      <category domain="http://securityratty.com/tag/malicious acrobat file">malicious acrobat file</category>
      <category domain="http://securityratty.com/tag/internet tv conspiracy">internet tv conspiracy</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/average spam">average spam</category>
      <category domain="http://securityratty.com/tag/core applications">core applications</category>
      <category domain="http://securityratty.com/tag/scandalous news">scandalous news</category>
      <category domain="http://securityratty.com/tag/secret plan">secret plan</category>
      <category domain="http://securityratty.com/tag/spam message">spam message</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/338277676/why_you_should_update_acrobat.html">Why You Should Update Acrobat</source>
    </item>
    <item>
      <title><![CDATA[Apple OS update fixes Adobe corruption bug]]></title>
      <link>http://securityratty.com/article/b4b80f4b64824fd415b0380dfcc87495</link>
      <guid>http://securityratty.com/article/b4b80f4b64824fd415b0380dfcc87495</guid>
      <description><![CDATA[Apple's update for its operating system, released late yesterday, fixes a data corruption problem that Photoshop users first reported after the company's last Mac OS X upgrade in...]]></description>
      <content:encoded><![CDATA[Apple's update for its operating system, released late yesterday, fixes a data corruption problem that Photoshop users first reported after the company's last Mac OS X upgrade in May.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=SGIMSS"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=SGIMSS" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/324219697" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/apple">apple</category>
      <category domain="http://securityratty.com/tag/fixes">fixes</category>
      <category domain="http://securityratty.com/tag/photoshop users">photoshop users</category>
      <category domain="http://securityratty.com/tag/data corruption">data corruption</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/upgrade">upgrade</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/mac">mac</category>
      <category domain="http://securityratty.com/tag/yesterday">yesterday</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/324219697/article.do">Apple OS update fixes Adobe corruption bug</source>
    </item>
    <item>
      <title><![CDATA[Researcher slams Adobe for 'epidemic' of JavaScript bugs]]></title>
      <link>http://securityratty.com/article/cc01034a4193158b22ae1387fdcfcbe3</link>
      <guid>http://securityratty.com/article/cc01034a4193158b22ae1387fdcfcbe3</guid>
      <description><![CDATA[Adobe Systems has patched its free Reader and commercial Acrobat software to fix the latest in what one researcher called an &quot;epidemic&quot; of JavaScript vulnerabilities in the popular...]]></description>
      <content:encoded><![CDATA[Adobe Systems has patched its free Reader and commercial Acrobat software to fix  the latest in what one researcher called an "epidemic" of JavaScript vulnerabilities in the popular apps.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=7uDrcQ"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=7uDrcQ" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/319076627" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 24 Jun 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/commercial acrobat software">commercial acrobat software</category>
      <category domain="http://securityratty.com/tag/popular apps">popular apps</category>
      <category domain="http://securityratty.com/tag/free reader">free reader</category>
      <category domain="http://securityratty.com/tag/javascript vulnerabilities">javascript vulnerabilities</category>
      <category domain="http://securityratty.com/tag/researcher">researcher</category>
      <category domain="http://securityratty.com/tag/epidemic">epidemic</category>
      <category domain="http://securityratty.com/tag/adobe systems">adobe systems</category>
      <category domain="http://securityratty.com/tag/fix">fix</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/319076627/article.do">Researcher slams Adobe for 'epidemic' of JavaScript bugs</source>
    </item>
    <item>
      <title><![CDATA[Adobe Reader/Acrobat JavaScript Method Handling Vuln]]></title>
      <link>http://securityratty.com/article/0a6f9d9d5bb6389f42e0bd2609650198</link>
      <guid>http://securityratty.com/article/0a6f9d9d5bb6389f42e0bd2609650198</guid>
      <description><![CDATA[Well, Adobe is in the news again this morning with the release of another patch to address a remote access problem
From Secunia
Description
A vulnerability has been reported in Adobe Reader/Acrobat,...]]></description>
      <content:encoded><![CDATA[<p>Well, Adobe is in the news again this morning with the release of another patch to address a remote access problem. </p>
<p>From Secunia:</p>
<blockquote><p>Description:<br />
A vulnerability has been reported in Adobe Reader/Acrobat, which potentially can be exploited by malicious people to compromise a user&#8217;s system.</p>
<p>The vulnerability is caused due to an error in the implementation of an unspecified JavaScript method and can be exploited to cause a crash or potentially execute arbitrary code via a specially crafted PDF file.</p>
<p>NOTE: The vulnerability is reportedly being exploited in the wild.</p></blockquote>
<p>Note the &#8216;note&#8217;. This one is getting pwned as we speak.</p>
<p><a href="http://secunia.com/advisories/30832/">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=qO1omM"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=qO1omM" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=zaqm3I"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=zaqm3I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=6uXPsi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=6uXPsi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=DhkOHi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=DhkOHi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=0VQa1i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=0VQa1i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=WeSmji"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=WeSmji" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/318806880" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 24 Jun 2008 06:48:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/adobe">adobe</category>
      <category domain="http://securityratty.com/tag/javascript method">javascript method</category>
      <category domain="http://securityratty.com/tag/execute arbitrary code">execute arbitrary code</category>
      <category domain="http://securityratty.com/tag/vulnerability">vulnerability</category>
      <category domain="http://securityratty.com/tag/note">note</category>
      <category domain="http://securityratty.com/tag/adobe readeracrobat">adobe readeracrobat</category>
      <category domain="http://securityratty.com/tag/malicious people">malicious people</category>
      <category domain="http://securityratty.com/tag/article link">article link</category>
      <category domain="http://securityratty.com/tag/remote access">remote access</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/318806880/">Adobe Reader/Acrobat JavaScript Method Handling Vuln</source>
    </item>
    <item>
      <title><![CDATA[Windows XP SP3 includes vulnerable Flash Player]]></title>
      <link>http://securityratty.com/article/40455b319db3756ef1f086db3eeacc51</link>
      <guid>http://securityratty.com/article/40455b319db3756ef1f086db3eeacc51</guid>
      <description><![CDATA[Microsoft's Windows XP Service Pack 3 (SP3) ships with an out-of-date version of Adobe's Flash Player that's vulnerable to recently-spotted attacks, according to Microsoft's support...]]></description>
      <content:encoded><![CDATA[Microsoft's Windows XP Service Pack 3 (SP3) ships with an out-of-date version of Adobe's Flash Player that's vulnerable to recently-spotted attacks, according to Microsoft's support documentation.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=78797?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=78797?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Mon, 02 Jun 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/flash player">flash player</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/support documentation">support documentation</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/sp3">sp3</category>
      <category domain="http://securityratty.com/tag/service pack">service pack</category>
      <category domain="http://securityratty.com/tag/vulnerable">vulnerable</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/version">version</category>
      <source url="http://www.networkworld.com/news/2008/060308-windows-xp-sp3-includes-vulnerable.html?fsrc=rss-security">Windows XP SP3 includes vulnerable Flash Player</source>
    </item>
    <item>
      <title><![CDATA[Microsoft clarifies XP SP 3 Flash issue]]></title>
      <link>http://securityratty.com/article/1927ba42b69851b104ea6a5e81a573c9</link>
      <guid>http://securityratty.com/article/1927ba42b69851b104ea6a5e81a573c9</guid>
      <description><![CDATA[Amid concerns that users of its Window XP Service Pack 3 operating system may be vulnerable to online attacks, Microsoft has finally broken its silence and explained which XP users need to upgrade...]]></description>
      <content:encoded><![CDATA[Amid concerns that users of its Window XP Service Pack 3 operating system may be vulnerable to online attacks, Microsoft has finally broken its silence and explained which XP users need to upgrade their Adobe Flash Player software.]]></content:encoded>
      <pubDate>Mon, 02 Jun 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/online attacks">online attacks</category>
      <category domain="http://securityratty.com/tag/amid concerns">amid concerns</category>
      <category domain="http://securityratty.com/tag/service pack">service pack</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/window">window</category>
      <category domain="http://securityratty.com/tag/silence">silence</category>
      <category domain="http://securityratty.com/tag/upgrade">upgrade</category>
      <source url="http://www.networkworld.com/news/2008/060308-microsoft-clarifies-xp-sp-3.html?fsrc=rss-security">Microsoft clarifies XP SP 3 Flash issue</source>
    </item>
    <item>
      <title><![CDATA[Windows XP SP3 includes vulnerable Flash Player]]></title>
      <link>http://securityratty.com/article/13229795f83b57480aa5574621af5a43</link>
      <guid>http://securityratty.com/article/13229795f83b57480aa5574621af5a43</guid>
      <description><![CDATA[Microsoft's Windows XP Service Pack 3 (SP3) ships with an older version of Adobe's Flash Player that's vulnerable to recently-spotted...]]></description>
      <content:encoded><![CDATA[Microsoft's Windows XP Service Pack 3 (SP3) ships with an older version of Adobe's Flash Player that's vulnerable to recently-spotted attacks.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=ebnuFo"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=ebnuFo" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/303363629" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 02 Jun 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/flash player">flash player</category>
      <category domain="http://securityratty.com/tag/sp3">sp3</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/service pack">service pack</category>
      <category domain="http://securityratty.com/tag/vulnerable">vulnerable</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/version">version</category>
      <category domain="http://securityratty.com/tag/adobe">adobe</category>
      <category domain="http://securityratty.com/tag/ships">ships</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/303363629/article.do">Windows XP SP3 includes vulnerable Flash Player</source>
    </item>
    <item>
      <title><![CDATA[Apple Patches 40 Security Holes]]></title>
      <link>http://securityratty.com/article/6b8c8e831ce877818299a74183b41703</link>
      <guid>http://securityratty.com/article/6b8c8e831ce877818299a74183b41703</guid>
      <description><![CDATA[Apple on Wednesday released an update to fix at least 40 different security holes in computers powered by its Mac OS X operating system and other software, including a just-in-time update to fix a...]]></description>
      <content:encoded><![CDATA[Apple on Wednesday released an update to fix at least 40 different security holes in computers powered by its Mac OS X operating system and other software, including a just-in-time update to fix a dangerous vulnerability in the Adobe Flash Player that is being rather heavily exploited at the moment]]></content:encoded>
      <pubDate>Sat, 31 May 2008 10:38:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security holes">security holes</category>
      <category domain="http://securityratty.com/tag/adobe flash player">adobe flash player</category>
      <category domain="http://securityratty.com/tag/fix">fix</category>
      <category domain="http://securityratty.com/tag/apple">apple</category>
      <category domain="http://securityratty.com/tag/dangerous vulnerability">dangerous vulnerability</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/heavily">heavily</category>
      <category domain="http://securityratty.com/tag/computers">computers</category>
      <category domain="http://securityratty.com/tag/just-in-time">just-in-time</category>
      <source url="http://digg.com/security/Apple_Patches_40_Security_Holes">Apple Patches 40 Security Holes</source>
    </item>
    <item>
      <title><![CDATA[Apple Patches for Apache, Flash and More]]></title>
      <link>http://securityratty.com/article/5bab105b079ba8fb2f90fcc0e4655f7f</link>
      <guid>http://securityratty.com/article/5bab105b079ba8fb2f90fcc0e4655f7f</guid>
      <description><![CDATA[Yesterday I blogged a Windows flaw for Adobe Flash player. Today I came across another advisory about a patch Apple just put out earlier this week for Adobe Flash. The security update also covers...]]></description>
      <content:encoded><![CDATA[<p>Yesterday I blogged a Windows flaw for Adobe Flash player. Today I came across another advisory about a patch Apple just put out earlier this week for Adobe Flash. The security update also covers other software too. From <a rel="nofollow" target="_blank" href="http://www.securityfocus.com/brief/745?ref=rss">SecurityFocus</a>:</p>
<blockquote>
<p>The update patches eight vulnerabilities in the open-source Apache Web server and seven vulnerabilities in Adobe&#8217;s Flash Player plug-in. While the Apache flaws amount to, at most, cross-site scripting attacks, the Flash Player flaws could allow a malicious Flash file (SWF) to execute on the victim&#8217;s system, Apple stated in its security advisory.</p>
<p>The company also fixed five vulnerabilities in its ImageIO component that could allow denial-of-service attacks, information leakage, and in one case, possible code execution. The update also patches two flaws in the kernel that allow both local and remote users the ability to shutdown the system. A flaw in the way that the Mac&#8217;s Mail program handles the Internet&#8217;s next-generation addressing scheme, IP version 6, could allow remote code execution, Apple stated.</p></blockquote>]]></content:encoded>
      <pubDate>Fri, 30 May 2008 06:20:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/apple">apple</category>
      <category domain="http://securityratty.com/tag/flash player flaws">flash player flaws</category>
      <category domain="http://securityratty.com/tag/flaws">flaws</category>
      <category domain="http://securityratty.com/tag/adobe flash player">adobe flash player</category>
      <category domain="http://securityratty.com/tag/code execution">code execution</category>
      <category domain="http://securityratty.com/tag/adobe flash">adobe flash</category>
      <category domain="http://securityratty.com/tag/remote code execution">remote code execution</category>
      <category domain="http://securityratty.com/tag/security advisory">security advisory</category>
      <category domain="http://securityratty.com/tag/apache flaws amount">apache flaws amount</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/301391276/">Apple Patches for Apache, Flash and More</source>
    </item>
    <item>
      <title><![CDATA[Flash Player + Windows = Threat of SQL Injection]]></title>
      <link>http://securityratty.com/article/bcc3f89d776010d41693715b0461d5bf</link>
      <guid>http://securityratty.com/article/bcc3f89d776010d41693715b0461d5bf</guid>
      <description><![CDATA[Apparently Adobe Flash players that arent patched and up to date on Windows might be vulnerable to a new SQL injectionthere are apparently 18 variants of the new exploit. SecureWorks has the details...]]></description>
      <content:encoded><![CDATA[<p>Apparently Adobe Flash players that aren&#8217;t patched and up to date on Windows might be vulnerable to a new SQL injection&#8211;there are apparently 18 variants of the new exploit. <a rel="nofollow" target="_blank" href="http://www.secureworks.com/research/threats/adobeflashflaw/?threat=adobeflashflaw"> SecureWorks </a>has the details:</p>
<blockquote><p>
Attackers insert SCRIPT and IFRAME tags into the content of trusted, legitimate web sites via a known SQL injection attack. Those tags redirect the user to the attacker&#8217;s server which hosts the Flash exploit. Tens of thousands of web sites are vulnerable to the SQL injection attack, meaning the distribution potential is high.</p>
<p>The vulnerability is not &#8220;zero-day&#8221;; however, these are the first known public exploits targeting it. The SecureWorks Counter Threat Unit (CTU) has analyzed 18 variants of the exploit, and all attempt to leverage the integer overflow vulnerability originally discovered by Mark Dowd (CVE-2007-0071), which was patched by Adobe with release of version 9.0.124.0 of the Flash Player. While some have reported that the latest version is vulnerable, the CTU was unable to duplicate these results with samples taken from known exploit sites. The only confirmed vulnerable version is (pre-patch) 9.0.115.0.
</p></blockquote>]]></content:encoded>
      <pubDate>Thu, 29 May 2008 11:59:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vulnerable version">vulnerable version</category>
      <category domain="http://securityratty.com/tag/vulnerable">vulnerable</category>
      <category domain="http://securityratty.com/tag/exploit">exploit</category>
      <category domain="http://securityratty.com/tag/flash exploit">flash exploit</category>
      <category domain="http://securityratty.com/tag/sql injection attack">sql injection attack</category>
      <category domain="http://securityratty.com/tag/integer overflow vulnerability">integer overflow vulnerability</category>
      <category domain="http://securityratty.com/tag/exploit sites">exploit sites</category>
      <category domain="http://securityratty.com/tag/flash player">flash player</category>
      <category domain="http://securityratty.com/tag/vulnerability">vulnerability</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/300861445/">Flash Player + Windows = Threat of SQL Injection</source>
    </item>
  </channel>
</rss>
