Original URL: http://www.theregister.co.uk/2010/06/07/adobe_0day/
Adobe warns over unpatched PDF peril
Happy zero-day. Again
Hackers are exploiting critical, unpatched vulnerabilities in Adobe Reader, Acrobat and Flash Player.
The zero-day vulnerabilities are platform independent and can affect users of Adobe products regardless of whether they run Windows, Mac or Linux systems, Adobe warns.
The software developer reckons that Adobe Reader and Acrobat version 8.x are not vulnerable, but users of the newer version 9.0 of the software are at risk. Adobe has published a workaround involving the deletion of a library file connected with processing Flash content in PDF files pending the development of a more comprehensive fix.
Adobe is yet to publish a timetable of when patches will become available. Adobe Flash Player 10.0.45.2 and earlier versions are vulnerable to the bug. Users of Flash Player 10.1 Release Candidate may be in the clear but that's uncertain, as an advisory from Adobe explains.
The bugs are the latest in a series of security pratfalls to befall Adobe software, joint favourite with Microsoft's browser and applications as the main targets of hacker attacks. The latest flaw can be blamed on the support of exotic files and formats within PDF files, a problem that has cropped up in the past. ®