Announcement

Collapse
No announcement yet.

Adobe fails to patch Linux version of their reader

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Adobe fails to patch Linux version of their reader

    http://www.h-online.com/open/news/it...x-1668153.html

    Not that anyone using KDE should care, since Okular works wonderfully.

    On its August Patch Day, Adobe has fixed numerous critical memory-related bugs in Reader for Windows and Mac OS X – but has chosen to overlook Linux users. The researchers who discovered the holes now fear that potential attackers could find enough clues to build an exploit by comparing the current Windows version of Reader with the previous one. This would leave Linux users defenceless. On top of that, even the patched versions still contain a total of 16 open security holes.

    Google employees Mateusz Jurczyk and Gynvael Coldwind initially examined the PDF engine of the Chrome browser and discovered numerous holes. They then tested Adobe Reader and found about 60 issues that triggered crashes, 40 of which are potential attack vectors. When the two researchers reported their discoveries to Adobe, the company promised to provide fixes – but also indicated that not all the holes would be closed on Patch Day in August.
    On Tuesday, that is exactly what happened. Versions 10.1.4 and 9.5.2 were released for Windows and Mac OS X only. Even these patched versions are still vulnerable to 16 of the reported issues that affect Windows, Mac OS X or both systems.
    ...
    The Google employees therefore recommend that users refrain from opening any PDF documents from external sources in Adobe Reader. Those who use a browser other than Chrome can protect themselves by disabling the Reader's browser extension. The extension allows the holes to be exploited with a simple visit to a specially crafted web page.

    Adobe is repeatedly shooting itself in its corporate foot, and is rapidly becoming irrelevant.
    "A nation that is afraid to let its people judge the truth and falsehood in an open market is a nation that is afraid of its people.”
    – John F. Kennedy, February 26, 1962.

    #2
    Ah, Adobe. Makers of software that is to security as a sieve is to a hermetic seal. Reader and Flash both have a terrible security record.

    As a bonus, their software also performs about as well as a slug on Mogadons...

    I look forward to the day when HTML5 & Unity3D (when they finish their Linux port) between them completely replace Flash for online video and games.
    Last edited by HalationEffect; Aug 16, 2012, 09:54 AM.
    sigpic
    "Let us think the unthinkable, let us do the undoable, let us prepare to grapple with the ineffable itself, and see if we may not eff it after all."
    -- Douglas Adams

    Comment


      #3
      Originally posted by GreyGeek View Post
      Adobe is repeatedly shooting itself in its corporate foot, and is rapidly becoming irrelevant.
      Not rapidly enough, sadly. Points finger at US Citizenship and Immigration Services and its PDFs. (insert angry taxpayer icon)

      Comment


        #4
        I've long regarded Adobe software as a form of virus and should be avoided if at all possible.

        Please Read Me

        Comment

        Working...
        X