Adobe Issues Patches For Critical PDF Flaws

Vulnerabilities in Adobe Reader, Acrobat are already being exploited in the wild



While Microsoft kept security managers busy with one of its largest Patch Tuesday bulletins ever, Adobe was quietly fixing its own flaws, which may already be known to the hacking community.

Critical vulnerabilities have been identified in versions 9.1.3, 8.1.6, and 7.1.3 of Adobe Reader and Acrobat, according to a security update issued today by Adobe.

"These vulnerabilities could cause the application to crash, and could potentially allow an attacker to take control of the affected system," the company said.

Among other flaws, Adobe's patch resolves a heap overflow vulnerability that could lead to code execution (CVE-2009-3459), the company said. There are reports this issue is being exploited in the wild via limited, targeted attacks, Adobe acknowledged.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message. Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Email This  | 
Print  | 
RSS
More Insights
Copyright © 2021 UBM Electronics, A UBM company, All rights reserved. Privacy Policy | Terms of Service