08 December 2011

Security Issues with Adobe Reader

Teresa at Technicalities highlights the latest security problem with Reader:

There is currently a zero day exploit - a hole in the software that is known but has no patch available as yet - making the rounds.

Security Threat in Reader

I'm linking to a Mac site because it needs to be emphasized that this is a problem with Adobe Reader NOT just on Windows PC's but on Windows, Mac, and even UNIX machines (which I assume includes Linux).

Version 9.4.6 is the currently exploited software (there is malicious software in the wild).  On Windows machines, it will be patched next week. If you are on a Mac or on Unix using this version you are SOL because... hey dudes, it's the holidays! They'll get something out early next year...

I recommend you listen to her; this is what she does. She has the fix for you, too.

6 comments:

drjim said...

Yep, there's more than one alternative to Acrobat Reader. For Linux, which I run, I use "Okular". which also has the ability to edit pdf's.
And Mac OS is based on one of the "BSD" variants of Unix, so it would be vulnerable, too.
Generally, though, it would require root privleiges to mess up something other than your "/home" directory.
Got backups?
:-)

Teresa said...

drjim - I always figure the Linux community is far more up to figuring this stuff out than Windows/Mac regular users. ;-)

Adobe has so many holes I post every once in a while trying to get people to change pdf readers... heh.

drjim said...

Well, seeing as the Portable Document Format is a published, open standard, it's not terribly hard to write an application to use the documents.
Well....it's a LOT easier than dealing with Micro$oft Word docs!
Open Office, and it's fully open source replacement Libre Office, can also handle pdf's extremely well.
One thing that really annoys me about Acrobat Reader is every single time they release a new version, they change the user interface!
Geez, guys, it wasn't broke, so don't "fix" it!

drjim said...

Just FYI.....

The version of Linux I use (OpenSUSE) just released a security update for Acroread, the binary executable for Acrobat Reader.

Anonymous said...

Does that mean that she could even help ME? With the problem of the page going blank every time I download mail or delete mail, sending me a message that "they" are notifying Windows, then flipping back, either onto the page I want or the page I just deleted, and saying that Windows has been notified? And after it has been going on for 3 weeks, without Windows seeming to care?

DG

drjim said...

Sounds like you might have a virus, or some malware.
Get "Malwarebytes", and "SpyBot Search and Destroy" installed on your PC, update them, and run them. Some of the nasties out there are smart enough to hide from an anti-virus program.