Feeds

The long road to Reader and Flash security Nirvana

Critical Adobe updates not easy to come by

SANS - Survey on application security programs

Updated Adobe on Tuesday patched a hole in its ubiquitous Acrobat Reader program that allows attackers to remotely install malware without requiring unsuspecting users to do anything more than browse to the wrong website.

Real-world attacks targeting the vulnerability, which affects all versions of Reader, have been circulating for the past three weeks. The update is for Windows and Mac users only. Those running Reader on Linux will have to wait another one to two weeks before their patches are available. That seems like a long time to wait.

People who don't want Google toolbar foisted upon them are reminded to unclick the "install Google toolbar" checkbox, which can be easy to miss.

To be fair, those attacks are narrowly tailored and require victims to actually open a booby-trapped file. But researcher Didier Stevens has created a proof-of-concept attack that uses the Reader vulnerability to take control of a PC without requiring a user to double-click on anything.

The Reader vulnerability is only the latest security peril to be unleashed on the masses by software from Adobe. Two weeks ago, the company pushed out out a fix for critical vulnerabilities in its Flash player. According to researchers at Secunia, "at least one of them is quite nasty and does indeed allow remote code execution in a very reliable manner."

Like a lot of Reg readers, your reporter is the de facto system administrator for a lot of friends and family members. More than a week after Adobe released the Flash update, none of the 10 PCs in his care had automatically received it. That meant the patch had to be installed manually on each machine.

What's more, computers using more than one browser would appear to need two updates - one for Internet Explorer and another for Firefox. For an update so important, Adobe is certainly making us work awfully hard to install it, no?

Until Adobe makes the process more user-friendly, the best thing to do is to manually check each machine you care about using this link for Flash. We couldn't find a similar link for Reader, so the easiest way to make sure you're current is to open it and choose "check for updates" in the Help menu.

Better yet, use Secunia's Personal Sofware Inspector to stay on top of critical updates for hundreds of third-party applications. We also welcome feedback from Adobe on ways people can lessen the updating pain.

However you update your Adobe software, make sure that you do. The PC you save, may be your own. ®

This article was updated after Adobe released its patch. It was also corrected to reflect that the patch covers Mac versions of Reader, in addition to Windows versions.

Combat fraud and increase customer satisfaction

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
prev story

Whitepapers

Designing a defence for mobile apps
In this whitepaper learn the various considerations for defending mobile applications; from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.