<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CompuWorld &#187; adobe bugs</title>
	<atom:link href="http://www.nofullstop.com/category/bugs-found/adobe-bugs/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.nofullstop.com</link>
	<description></description>
	<lastBuildDate>Sat, 12 Nov 2011 08:15:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Your Adobe Flash Player Has A Security Vulnerability</title>
		<link>http://www.nofullstop.com/2011/03/15/your-adobe-flash-player-has-a-security-vulnerability/</link>
		<comments>http://www.nofullstop.com/2011/03/15/your-adobe-flash-player-has-a-security-vulnerability/#comments</comments>
		<pubDate>Tue, 15 Mar 2011 13:41:00 +0000</pubDate>
		<dc:creator>Salman</dc:creator>
				<category><![CDATA[adobe bugs]]></category>
		<category><![CDATA[bugs found]]></category>

		<guid isPermaLink="false">http://www.nofullstop.com/?p=2882</guid>
		<description><![CDATA[Adobe has a vulnerability (again) in Flash Player that they say will not be fixed before next week. As per the security advisory Adobe Flash Player has a security vulnerability for all platforms which actually means the entire Internet population. Affected Software Versions Adobe Flash Player 10.2.152.33 and earlier versions for Windows, Macintosh, Linux and [...]]]></description>
			<content:encoded><![CDATA[<p>Adobe has a vulnerability (<a title="Adobe Vulnerability" href="http://www.nofullstop.com/2007/02/21/vulnerability-in-versions-708-and-earlier-of-adobe-reader-and-acrobat/" target="_blank">again</a>) in Flash Player that they say will not be fixed before next week. As per the security advisory Adobe Flash Player has a <a title="Adobe Security Advisory " href="http://www.adobe.com/support/security/advisories/apsa11-01.html" target="_blank">security vulnerability</a> for <em>all platforms</em> which actually means the entire Internet population.</p>
<p><strong>Affected Software Versions</strong></p>
<ul>
<li>Adobe Flash Player 10.2.152.33 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems</li>
<li>Adobe Flash Player 10.2.154.18 and earlier for Chrome users</li>
<li>Adobe Flash Player 10.1.106.16 and earlier for Android</li>
<li>The Authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.1) and earlier 10.x and 9.x versions for Windows and Macintosh operating systems.</li>
</ul>
<p>Adobe has confirmed that the vulnerability is being actively exploited <em>in the wild</em> with the help of a .swf file embed within Excel spreadsheet.</p>
<p><strong>Description</strong></p>
<blockquote><p>This vulnerability (CVE-2011-0609) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being exploited in the wild in targeted attacks via a Flash (.swf) file embedded in a Microsoft Excel (.xls) file delivered as an email attachment. Adobe is not currently aware of attacks targeting Adobe Reader and Acrobat. Adobe Reader X Protected Mode mitigations would prevent an exploit of this kind from executing.</p></blockquote>
<p>Users can follow the <a title="Adobe PSIRT blog" href="http://blogs.adobe.com/psirt/" target="_blank">Adobe PSIRT blog</a> if they are keen on updating the vulnerability as soon as the fix is available.</p>
<hr>
<p>© <a href="">CompuWorld</a> - because <b><i>The Genius Inside You Is Still Sleeping.</i></b><br/></p>
	Tags: <a href="http://www.nofullstop.com/tag/adobe-bugs/" title="adobe bugs" rel="tag">adobe bugs</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.nofullstop.com/2011/03/15/your-adobe-flash-player-has-a-security-vulnerability/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Vulnerability In Versions 7.08 And Earlier Of Adobe Reader And Acrobat</title>
		<link>http://www.nofullstop.com/2007/02/21/vulnerability-in-versions-708-and-earlier-of-adobe-reader-and-acrobat/</link>
		<comments>http://www.nofullstop.com/2007/02/21/vulnerability-in-versions-708-and-earlier-of-adobe-reader-and-acrobat/#comments</comments>
		<pubDate>Wed, 21 Feb 2007 10:16:00 +0000</pubDate>
		<dc:creator>Salman</dc:creator>
				<category><![CDATA[adobe bugs]]></category>
		<category><![CDATA[bugs found]]></category>

		<guid isPermaLink="false">http://www.nofullstop.com/2007/02/21/vulnerability-in-versions-708-and-earlier-of-adobe-reader-and-acrobat/</guid>
		<description><![CDATA[A vulnerability has been reported in Adobe Reader. It is caused due to an unspecified error when processing pdf files. Related Software Versions Adobe Reader 7.0.8 and earlier versions Adobe Acrobat Standard, Professional and Elements 7.0.8 and earlier versions Adobe Acrobat 3D Description A cross-site scripting (XSS) vulnerability in versions 7.0.8 and earlier of Adobe [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify">A vulnerability has been reported in Adobe Reader. It is caused due to an unspecified error when processing pdf files.</p>
<p><span style="font-weight: bold">Related Software Versions<br />
</span>Adobe Reader 7.0.8  and earlier versions<br />
Adobe Acrobat Standard, Professional and Elements 7.0.8 and earlier versions<br />
Adobe Acrobat 3D</p>
<p><span style="font-weight: bold">Description</span></p>
<p style="text-align: justify">A cross-site scripting (XSS) vulnerability in versions 7.0.8 and earlier of Adobe Reader and Acrobat could allow remote attackers to inject arbitrary JavaScript into a browser session.The vulnerability could allow an attacker who successfully exploits these vulnerabilities to take control of the affected system. These vulnerabilities have been assigned a <a href="http://www.adobe.com/devnet/security/security_zone/severity_ratings.html">critical</a> severity rating. A malicious file must be loaded in Adobe Reader by the end user for an attacker to exploit these vulnerabilities.</p>
<p><span style="font-weight: bold">Workaround Available <span style="font-size: 78%">[via <a href="http://www.adobe.com/support/security/bulletins/apsb07-01.html">Adobe Security Advisories</a>]</span></span></p>
<blockquote>
<p style="text-align: justify">
<p style="text-align: justify"><strong>Adobe Reader on Windows</strong><br />
Adobe strongly recommends upgrading to  Adobe Reader 8, available from the following site:<br />
<a href="http://www.adobe.com/go/getreader">http://www.adobe.com/go/getreader</a>.</p>
<p style="text-align: justify">
<p style="text-align: justify">Users with Adobe Reader 7.0 through 7.0.8, who cannot upgrade to Reader 8, should upgrade to Reader 7.0.9. Adobe Reader 7.0.9 is available as a full installation package and not a patch. It can be installed on top of any older version of Reader 7 and user preferences will be preserved:<br />
<a href="http://www.adobe.com/go/getreader">http://www.adobe.com/go/getreader</a>.</p>
<p style="text-align: justify">
<p style="text-align: justify">If customers are using Adobe Reader 6.0–6.0.5 and are unable to upgrade to version 8 or 7.0.9 due to Operating System constraints for example, Adobe recommends upgrading to version 6.0.6 either via a series of patches from: <a href="http://www.adobe.com/downloads/">http://www.adobe.com/downloads</a> or by using the auto-update mechanism within the product when prompted.</p>
<p style="text-align: justify">
<p style="text-align: justify">
<p style="text-align: justify"><strong>Adobe Reader on Mac OS</strong><br />
Adobe strongly recommends upgrading to  Adobe Reader 8, available from the following site: <a href="http://www.adobe.com/go/getreader">http://www.adobe.com/go/getreader</a>.</p>
<p style="text-align: justify">
<p style="text-align: justify">Users with Adobe Reader 7.0 through 7.0.8, who cannot upgrade to Reader 8, should upgrade to Reader 7.0.9. The Reader 7.0.9 update requires that Adobe Reader 7.0.8 is installed on your Mac system. To determine which version of Adobe Reader is installed, choose Adobe Reader &gt; About Adobe Reader. The version number appears in the upper left corner below the Adobe Reader logo.</p>
<p>If version 7.0.8 is installed, download and install <a href="http://www.adobe.com/downloads/">this incremental patch</a>.<br />
After downloading the update file, double-click it to begin the update process  and access the file&#8217;s contents.</p>
<p>If version 7.0, 7.0.1, 7.0.2, 7.0.3, 7.0.5, 7.0.7 or an earlier version of Reader is installed and customers cannot update to Reader 8, Adobe recommends that customers download the full Adobe Reader 7.0.9 installer from the <a href="http://www.adobe.com/products/acrobat/readstep2.html">Reader download  page</a>.</p>
<p style="text-align: justify">
<p style="text-align: justify">
<p style="text-align: justify"><strong>Adobe Acrobat on Windows or Mac OS</strong><br />
For version 7.0–7.0.8, users should utilize the product&#8217;s automatic update facility. The default installation configuration runs automatic updates on a regular schedule, and can be manually activated by choosing Help &gt; Check For Updates Now. Alternatively, the update files can also be manually downloaded and installed from <a href="http://www.adobe.com/downloads/">www.adobe.com/downloads</a>.</p>
<p style="text-align: justify">
<p style="text-align: justify">If customers are using Adobe Acrobat 6.0–6.0.5 for Windows and are unable to upgrade to version 8 or 7.0.9 due to Operating System constraints for example, Adobe recommends upgrading to Windows version 6.0.6 either via a series of patches from: <a href="http://www.adobe.com/downloads/">http://www.adobe.com/downloads</a> or by using the auto-update mechanism  within the product when prompted.</p>
<p style="text-align: justify">
<p style="text-align: justify">
<p style="text-align: justify"><strong>Adobe Reader on UNIX</strong><br />
For version 7.0, users should upgrade  to Adobe Reader 7.0.9 from <a href="http://www.adobe.com/go/getreader">http://www.adobe.com/go/getreader</a>.</p>
<p style="text-align: justify">
<p style="text-align: justify">For versions prior to 7.0, users should  upgrade to 7.0.9 <a href="http://www.adobe.com/go/getreader">http://www.adobe.com/go/getreader</a>.</p>
<p style="text-align: justify">
<p style="text-align: justify">
<p style="text-align: justify"><strong>Server-side workarounds for website operators</strong><br />
Adobe has <a href="http://www.adobe.com/go/apsa07-02">provided  workarounds</a> for website operators to prevent the cross-site scripting  vulnerability (CVE-2007-0045) from the server side. Please review <a href="http://www.adobe.com/go/apsa07-02">Security Advisory APSA07-02</a> for  more information.</p></blockquote>
<p><span style="font-weight: bold">Related:</span><br />
<a href="http://www.nofullstop.com/2007/02/03/vulnerability-in-ms-office-could-give-access-to-your-computer/">Vulnerability In MS Office</a><br />
<a href="http://www.nofullstop.com/2007/01/28/25th-birthday-of-virus/">25th Birthday Of Virus</a><br />
<a href="http://www.nofullstop.com/2007/01/21/hackers-attack-gorbachevs-web-site/">Hackers Attacked Gorbachev&#8217;s Website</a></p>
<hr>
<p>© <a href="">CompuWorld</a> - because <b><i>The Genius Inside You Is Still Sleeping.</i></b><br/></p>
	Tags: <a href="http://www.nofullstop.com/tag/adobe-bugs/" title="adobe bugs" rel="tag">adobe bugs</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.nofullstop.com/2007/02/21/vulnerability-in-versions-708-and-earlier-of-adobe-reader-and-acrobat/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

