Wednesday, November 29, 2006 12:38 PM cmosby

SANS - Internet Storm Center - New Adobe vulnerability

New Adobe vulnerability (NEW)

Published: 2006-11-29,
Last Updated: 2006-11-29 18:34:37 UTC by Toby Kohlenberg (Version: 1)

Frank Klein has written to let us know that there are new vulnerabilities in Adobe Acrobat and Acrobat Reader that have the potential for code execution as a result of incorrect argument handling in the ActiveX control for IE. There is no patch currently available and Adobe is offering a mitigation of deleting the control. FrSIRT has provided a kill bit option that you can set that should disable the control.

The vulnerable versions are:
Adobe Standard, Reader & Professional 7.0.0 - 7.0.8

http://www.frsirt.com/english/advisories/2006/4751
http://www.adobe.com/support/security/advisories/apsa06-02.html

SANS - Internet Storm Center - Cooperative Cyber Threat Monitor And Alert System.

Filed under: ,

Comments

No Comments