Status Tracking Note JVNTR-2009-13

Adobe Reader and Acrobat JavaScript Vulnerabilities (TA09-133B)

Overview

Adobe has released Security Bulletin APSB09-06, which describes Adobe Reader and Acrobat updates for two JavaScript vulnerabilities that could allow a remote attacker to execute arbitrary code.
Event Information

Date (UTC)Description
2009-05-13 20:38 US-CERT
TA09-133B: Adobe Reader and Acrobat JavaScript Vulnerabilities
Via US-CERT Mailing List
2009-05-13 13:12 US-CERT
Adobe Releases Security Updates for Adobe Reader and Acrobat
US-CERT Current Activity
Adobe has released security updates to address a vulnerability that affects Reader 9.1 and earlier and Acrobat 9.1 and earlier. This vulnerability could allow an attacker to execute arbitrary code or cause a denial-of-service condition.
2009-05-13 09:36 JPCERT/CC
JPCERT-AT-2009-0006: Vulnerability in Adobe Reader and Acrobat
2009-05-12 23:13 SANS Internet Storm Center
Adobe Acrobat (reader) patches released
While patching your macs and windows machines on reboot Wednesday tomorrow, don't forget to patch adobe's acrobat (reader) just as well.
2009-05-12 14:50 Adobe
Security Bulletin - Adobe Reader and Acrobat
Adobe Product Security Incident Response Team (PSIRT)
Today, we have posted a Security Bulletin and provided Adobe Reader and Acrobat patches to our Product Update area. This update resolves the vulnerabilities from Security Advisory APSA09-02. Adobe is not currently aware of any exploits in the wild for these issues.
2009-05-12 Adobe
APSB09-06: Security Updates available for Adobe Reader and Acrobat
Adobe recommends users of Adobe Reader 9.1 and Acrobat 9.1 and earlier versions update to Adobe Reader 9.1.1 and Acrobat 9.1.1. Adobe recommends users of Acrobat 8 update to Acrobat 8.1.5, and users of Acrobat 7 update to Acrobat 7.1.2. For Adobe Reader users who canft update to Adobe Reader 9.1.1, Adobe has provided the Adobe Reader 8.1.5 and Adobe Reader 7.1.2 updates.
2009-05-01 13:56 Adobe
Adobe Reader Issue Update
Adobe Product Security Incident Response Team (PSIRT)
A Security Advisory has been posted in regards to the Adobe Reader vulnerability last mentioned in the Adobe PSIRT blog on April 28 ("Update to Adobe Reader Issue", CVE-2009-1492).
2009-05-01 Adobe
APSA09-02: Security updates available for buffer overflow issues in Adobe Reader and Acrobat
A critical vulnerability has been identified in Adobe Reader 9.1 and Acrobat 9.1 and earlier versions. This vulnerability (CVE-2009-1492) would cause the application to crash and could potentially allow an attacker to take control of the affected system. A second vulnerability has also been reported that appears to affect Adobe Reader for UNIX only (CVE-2009-1493).
2009-04-29 Bugtraq
Adobe 8.1.4/9.1 customDictionaryOpen() Code Execution Exploit
customDictionaryOpen() vulnerability (CVE-2009-1493)
Vulnerability Proof Of Concept
#Cid: 34740.txt
#Tested: Linux + Adobe 9.1
#Tested: Linux + Adobe 8.1.4
2009-04-28 16:34 US-CERT
Adobe Reader JavaScript Function Vulnerability
US-CERT Current Activity
US-CERT is aware of public reports of a vulnerability affecting Adobe Reader. Reports indicate that this vulnerability is due to an error in the 'getAnnots()' JavaScript function. Exploitation of this vulnerability may allow a remote attacker to execute arbitrary code. Adobe has indicated via a blog entry that they are aware of the reports and are investigating the issue.
2009-04-27 18:20 Adobe
Potential Adobe Reader Issue
Adobe Product Security Incident Response Team (PSIRT)
Adobe is aware of reports of a potential vulnerability in Adobe Reader 9.1 and 8.1.4, as described in SecurityFocus BID 34736. We are currently investigating, and will have an update once we get more information.

Reference

Date first published (UTC): 2009-05-17T06:45+00:00
Date last updated (UTC): 2009-06-10T23:48+00:00
Valid HTML 4.01!