Wednesday, March 11, 2009

前陣子的開PDF檔會導致中毒的事

自由時報的新聞,好像其他的報紙也有報吧!

PDF檔網上直接開恐當機中毒

就是說 Adobe reader 9 和 Acrobat 9 或更早期的版本,被人發現有弱點(Bug?)

,可能導致程式不正常或被駭客利用此弱點去入侵攻擊妳的電腦。

五告等ㄟ時間!一堆人的computer早就掛了,Adobe才終於釋出更新的程式,

只不過是針對9版的,就是叫妳去網路下載9.1版的來更新。

其他版的(7 or 8)就等到3/18吧!因為妳們的電腦不值錢啦!

http://www.adobe.com/support/security/bulletins/apsb09-03.html

Security Updates available for Adobe Reader 9 and Acrobat 9

Release date: March 10, 2009

Vulnerability identifier: APSB09-03

CVE number: CVE-2009-0658

Platform: All Platforms

Summary

A critical vulnerability has been identified in Adobe Reader 9 and Acrobat 9 and earlier versions. This vulnerability would cause the application to crash and could potentially allow an attacker to take control of the affected system. There are reports that this issue is being exploited.

Adobe recommends users of Adobe Reader and Acrobat 9 update to Adobe Reader 9.1 and Acrobat 9.1. Adobe is planning to make available updates for Adobe Reader 7 and 8, and Acrobat 7 and 8, by March 18. In addition, Adobe plans to make available Adobe Reader 9.1 for Unix by March 25.

Affected software versions

Adobe Reader 9 and earlier versions
Adobe Acrobat 9 Standard, Pro, and Pro Extended and earlier versions

Solution

Adobe Reader

Adobe recommends Adobe Reader users update to Adobe Reader 9.1, available here:
http://get.adobe.com/reader/

Acrobat 9

Adobe recommends Acrobat 9 Standard and Acrobat 9 Pro users on Windows update to Acrobat 9.1, available at the following URLs:
http://www.adobe.com/support/downloads/detail.jsp?ftpID=4375
http://www.adobe.com/support/downloads/detail.jsp?ftpID=4382

Adobe recommends Acrobat 9 Pro Extended users on Windows update to Acrobat 9.1, available here:
http://www.adobe.com/support/downloads/detail.jsp?ftpID=4381

Adobe recommends Acrobat 9 Pro users on Macintosh update to Acrobat 9.1, available here:
http://www.adobe.com/support/downloads/detail.jsp?ftpID=4374

Severity rating

Adobe categorizes this as a critical issue and recommends that users apply the update for their product installations.

Details

A critical vulnerability has been identified in Adobe Reader 9 and Acrobat 9 and earlier versions. This vulnerability would cause the application to crash and could potentially allow an attacker to take control of the affected system. This issue is remotely exploitable. There are reports that this issue is being exploited.

Adobe recommends users of Adobe Reader and Acrobat 9 update to Adobe Reader 9.1 and Acrobat 9.1. Adobe is planning to make available updates for Adobe Reader 7 and 8, and Acrobat 7 and 8, by March 18. In addition, Adobe plans to make available Adobe Reader 9.1 for Unix by March 25.

Adobe is also in contact with anti-virus and security vendors, including McAfee, Symantec and others, on this issue in order to ensure the security of our mutual customers. For Adobe Reader 7 and 8 users who are unable to update to Adobe Reader 9.1, as well as Acrobat 7 and 8 users, more information on immediate protection for this issue from anti-virus and security vendors is available on the Adobe Product Security Incident Response Team blog.

A security bulletin will be published on http://www.adobe.com/support/security as soon as further product updates are available. Users may also monitor the latest information on the Adobe Product Security Incident Response Team blog at the following URL: http://blogs.adobe.com/psirt or by subscribing to the RSS feed here: http://blogs.adobe.com/psirt/atom.xml

No comments:

Post a Comment