Wednesday, April 29, 2009 8:43 AM cmosby

Two Adobe 0-day vulnerabilities – SANS Internet Storm Center

Two Adobe 0-day vulnerabilities

Published: 2009-04-29,
Last Updated: 2009-04-29 03:22:48 UTC
by Jason Lam (Version: 1)

0 comment(s) acebook witter

There are two 0-day vulnerabilities on Adobe Acrobat announced today, all current versions are vulnerable. One exploits the annotation function and the other exploits the custom Dictionary function. Both of these buffer overflow vulnerabilities exist in the Javascript system of the Adobe Acrobat and can be mitigated by disabling Javascript on Adobe Acrobat.

Since the exploits for these vulnerabilities on Linux platform are posted to the Internet, we can just guess that someone will somehow make it work on Windows and use it to spread botnet agents shortly.

http://blogs.adobe.com/psirt/2009/04/update_on_adobe_reader_issue.html

Keywords: adobe acrobat 0day

0 comment(s) acebook witter

Filed under: , , , ,

Comments

No Comments