Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

When PDFs Attack II - New Adobe Acrobat Reader 0-Day On the Loose

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
Home » Discuss » DU Groups » Computers & Internet » Computer Help and Support Group Donate to DU
 
Earth Bound Misfit Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Dec-17-09 12:20 AM
Original message
When PDFs Attack II - New Adobe Acrobat Reader 0-Day On the Loose
http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214

Greetings Everyone,

It has been a while since we have posted anything publicly, but we promise that we have been hard at work all this time. However, we come to you today with some bad news but hope to be of assistance. The Shadowserver Foundation has become aware of a new vulnerability affecting Adobe Acrobat that is currently unpatched. Several tests have confirmed this is a 0-day vulnerability affecting several versions of Adobe Acrobat to include the most recent versions of 8.x and 9.x. We have not tested on 7.x, but it may also be vulnerable.

snip

Exploit Details
We can tell you that this exploit is in the wild and is actively being used by attackers and has been in the wild since at least December 11, 2009. However, the number of attacks are limited and most likely targeted in nature. Expect the exploit to become more wide spread in the next few weeks and unfortunately potentially become fully public within the same timeframe. We are fully aware of all the details related to the exploit but do not plan to publish them for a few reasons:

snip

Antivirus detection should improve in the coming weeks and hopefully a patch. Right now only 5 out of the 41 different Antivirus vendors used by Virustotal are detecting this threat. Even then their detection appears to be generic and is not currently specifically detecting this exploit. The 5 vendors to detect the threat are:

(McAfee-GW-Edition)
(eSafe)
(NOD32)
(AntiVir)
(Kaspersky)
---------------------------------------

I unloaded this resource hogging, slow to load, vulnerable to exploits POS about 3 mos ago & installed Foxit Reader. :thumbsup:
Refresh | 0 Recommendations Printer Friendly | Permalink | Reply | Top
Earth Bound Misfit Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Dec-17-09 09:16 AM
Response to Original message
1. Adobe releases Security Advisory Bulletin for Reader workaround
Edited on Thu Dec-17-09 09:18 AM by Earth Bound Misfit
http://www.adobe.com/support/security/advisories/apsa09-07.html

Release date: December 15, 2009
Last updated: December 15, 2009
Vulnerability identifier: APSA09-07

Summary
Adobe has confirmed a critical vulnerability in Adobe Reader and Acrobat 9.2 and earlier versions that could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild. Adobe recommends customers follow the mitigation guidance below until a patch is available.

Adobe plans to make available an update to Adobe Reader and Acrobat by January 12, 2010 to resolve the issue.
more at link
-----------------------------

More (free) PDF readers available here: http://pdfreaders.org/
Printer Friendly | Permalink | Reply | Top
 
Occulus Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Dec-19-09 04:11 AM
Response to Original message
2. Bloody hell.
I wonder if that's what this was about. I have Acrobat Reader installed.
Printer Friendly | Permalink | Reply | Top
 
madokie Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Dec-19-09 11:14 AM
Response to Original message
3. Another reason to get rid of a windows machine
I doubt this is any concern to me and my linux mint installed used to be xp machine

Have I mentioned how much I like linux yet today? Well I do
Printer Friendly | Permalink | Reply | Top
 
struggle4progress Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jan-16-10 07:00 AM
Response to Reply #3
6. Security update available for Linux Flash Player 10.0.12.36 and Linux Flash Player 9.0.151.0
Printer Friendly | Permalink | Reply | Top
 
Why Syzygy Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Dec-20-09 06:53 PM
Response to Original message
4. Is this the fix
that Adobe just notified me in systray was ready for update? Sorry, I am in a dash, and looking for a quick answer if anyone has it. Thanks!
Printer Friendly | Permalink | Reply | Top
 
struggle4progress Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jan-16-10 07:18 AM
Response to Reply #4
7. Update your Adobe software Now
January 14, 2010, 02:58 PM —

Some things are the same no matter what operating system you run. Mac, Windows, or Linux user chances are you use Adobe Reader to read PDF (Portable Document Files) and Adobe Acrobat to create them. So it is that, no matter what you're running on your PC, you need to update your copies of Reader and Acrobat ... I'm raising a little Cain about it because major attacks on Google and Adobe are already happening because of these now fixed security holes. These attacks aren't coming from J. Random Hacker, they're coming, according to Google, from the Chinese government.If you don't want your computer to be part of state-sponsored espionage, you need to fix it now before you run across a malware-infected PDF ...

http://www.itworld.com/security/92714/update-your-adobe-software-now
Printer Friendly | Permalink | Reply | Top
 
madokie Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Dec-28-09 08:40 AM
Response to Original message
5. I'll stick with linux
thank you

Printer Friendly | Permalink | Reply | Top
 
hobbit709 Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jan-16-10 07:41 AM
Response to Reply #5
8. While this can't infect a Linux machine
It can embed it in a pdf document you send on to someone with a Windows machine.
I'd rather not become a "Typhoid Mary"
Printer Friendly | Permalink | Reply | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Tue Apr 30th 2024, 01:26 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » DU Groups » Computers & Internet » Computer Help and Support Group Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC