Startupware: Managing Startups

Autorunning Software & Running a Software Business

Adobe Reader moves to 9.3.4, Off-schedule patch

Filed under: Patches — August 20, 2010 @ 8:22 am

Adobe Reader has a new patch, moving it to a current release of 9.4.4. This is not on their announced schedule of matching the Microsoft second-Tuesday patch release calendar. This patch requires a system reboot.

According to the Adobe release notes:

These updates resolve an integer overflow vulnerability that could lead to code execution (CVE-2010-2862).

These updates further mitigate a social engineering attack that could lead to code execution (CVE-2010-1240).

These updates incorporate the Adobe Flash Player update as noted in Security Bulletin APSB10-16.

Translation into non-technobabble: Without the patch, bad guys can run their programs on your computer, including malware installers.

In my opinion, all users should also turn off two features in Adobe Reader to reduce the possibility of third-party code running unapproved. In the Tools, Preferences menu, go to Javascript. Uncheck the top box. And in Trust Manager, uncheck the top box. The first option runs scripts, and the second runs embedded documents, including possible macro code. No one uses these features except malware writers.



No Comments »

No comments yet.

RSS feed for comments on this post. TrackBack URI

Leave a comment

Line and paragraph breaks automatic, e-mail address never displayed, HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)