Account
Please wait, authorizing ...

Don't have an account? Register here today.

×

Adobe fixes only 25 out of 60 vulnerabilities (Patch!)

Adobe's security bulletins in August address 26 critical vulnerabilities related to remote code execution.

Adobe Systems Incorporated, has released three bulletins this month (APSB12-16/17/18) that fix a total of 26 vulnerabilities labeled as "critical", which can potentially lead to code execution: 20 in the Acrobat family, 5 in Shockwave Player and one in Flash player.

Some of these vulnerabilities are already being exploited by attackers who embed Flash animations in Word documents.

Google Chrome users will be updated automatically.

As a reminder of the announcement made by Adobe in June, from August 15 the versions of Flash Player for Android will no longer be officially downloaded from the Google Play Store, although security updates will continue to be provided until September 13, 2013.

- Publicidad -

Following the release of Adobe's latest bulletin for Reader and Acrobat (APSB12-16), researchers Mateusz Jurczyk and Gynvael Coldwind of the Google Security Team (and former colleagues at Hispasec) have published their analysis in which they conclude that Adobe, apart from leaving Linux users unprotected (as no fixed version has yet been published) has not resolved all the vulnerabilities reported by themselves.

The group was in charge of the "fuzzing" project of the PDF reader integrated in Google Chrome. They detected more than 50 problems. The most critical ones have already been corrected in the browser reader. Given the "success" of the operation, they decided to perform the same tests against the Adobe reader.

They concluded their tests with 60 failures. 31 problems could be "trivially exploitable" and 9 potentially exploitable. In June, they contacted Adobe's security team, who were very collaborative from the start. But the latest bulletin only corrects about 25 of these flaws in its 12 CVEs.

Thus, the researchers conclude that there are about 16 problems not yet corrected, which could represent perhaps 8 serious vulnerabilities (since 25 problems gave rise to 12 CVEs). Keep in mind that the problems detected by "fuzzing" can originate in the same vulnerability, and be corrected with the same modification of the code.

Adobe says it will fix it in the future. August 27 marks the 60-day limit that the researchers imposed as a condition for giving details, but since Adobe has no intention of publishing an out-of-cycle newsletter, it appears that the deadline will be met without patches. So they have decided, now, to make available to all their discoveries, given the risk that users face.

Source: Hispasec I, II

See original.

No thoughts on “Adobe fixes only 25 out of 60 vulnerabilities (Patch!)”

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
Suscribase Gratis
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS

Webinar: NxWitness el VMS rápido fácil y ultra ligero

Webinar: Por qué elegir productos con certificaciones de calidad

Por: Eduardo Cortés Coronado, Representante Comercial - SECO-LARM USA INC La importancia de utilizar productos certificados por varias normas internacionales como UL , Ul294, CE , Rosh , Noms, hacen a tus instalciones mas seguras y confiables además de ser un herramienta más de venta que garantice nuestro trabajo, conociendo qué es lo que certifica cada norma para así dormir tranquilos sabiendo que van a durar muchos años con muy bajo mantenimiento. https://www.ventasdeseguridad.com/2...

Webinar: Anviz ONE - Solución integral para pymes

Por: Rogelio Stelzer, Gerente comercial LATAM - Anviz Presentación de la nueva plataforma Anviz ONE, en donde se integran todas nuestras soluciones de control de acceso y asistencia, video seguridad, cerraduras inteligentes y otros sensores. En Anviz ONE el usuario podrá personalizar las opciones según su necesidad, de forma sencilla y desde cualquier sitio que tenga internet. https://www.ventasdeseguridad.com/2...

Webinar: Aplicaciones del IoT y digitalización en la industria logística

Se presentarán los siguientes temas: • Aplicaciones del IoT y digitalización en la industria logística. • Claves para decidir el socio en telecomunicaciones. • La última milla. • Nuevas estrategias de logística y seguimiento de activos sostenibles https://www.ventasdeseguridad.com/2...

Sesión 5: Milestone, Plataforma Abierta que Potencializa sus Instalaciones Manteniéndolas Protegidas

Genaro Sanchez, Channel Business Manager - MILESTONE https://www.ventasdeseguridad.com/2...
Load more...
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter