Select your language

Adobe fixes only 25 out of 60 vulnerabilities (Patch!)

Adobe's security bulletins in August address 26 critical vulnerabilities related to remote code execution. Adobe Systems Incorporated, has released three bulletins this month (APSB12-16/17/18) that fix a total of 26 vulnerabilities labeled as "critical", which can potentially lead to code execution: 20 in the Acrobat family, 5 in Shockwave Player and one in Flash player. Some of these vulnerabilities are already being exploited by...

Co... Adobe's security bulletins in August address 26 critical vulnerabilities related to remote code execution.

Adobe Systems Incorporated, has released three bulletins this month (APSB12-16/17/18) that fix a total of 26 vulnerabilities labeled as "critical", which can potentially lead to code execution: 20 in the Acrobat family, 5 in Shockwave Player and one in Flash player.

Some of these vulnerabilities are already being exploited by attackers who embed Flash animations in Word documents.

Google Chrome users will be updated automatically.

- Publicidad -

As a reminder of the announcement made by Adobe in June, from August 15 the versions of Flash Player for Android will no longer be officially downloaded from the Google Play Store, although security updates will continue to be provided until September 13, 2013.

Following the release of Adobe's latest bulletin for Reader and Acrobat (APSB12-16), researchers Mateusz Jurczyk and Gynvael Coldwind of the Google Security Team (and former colleagues at Hispasec) have published their analysis in which they conclude that Adobe, apart from leaving Linux users unprotected (as no fixed version has yet been published) has not resolved all the vulnerabilities reported by themselves.

The group was in charge of the "fuzzing" project of the PDF reader integrated in Google Chrome. They detected more than 50 problems. The most critical ones have already been corrected in the browser reader. Given the "success" of the operation, they decided to perform the same tests against the Adobe reader.

They concluded their tests with 60 failures. 31 problems could be "trivially exploitable" and 9 potentially exploitable. In June, they contacted Adobe's security team, who were very collaborative from the start. But the latest bulletin only corrects about 25 of these flaws in its 12 CVEs.

Thus, the researchers conclude that there are about 16 problems not yet corrected, which could represent perhaps 8 serious vulnerabilities (since 25 problems gave rise to 12 CVEs). Keep in mind that the problems detected by "fuzzing" can originate in the same vulnerability, and be corrected with the same modification of the code.

Adobe says it will fix it in the future. August 27 marks the 60-day limit that the researchers imposed as a condition for giving details, but since Adobe has no intention of publishing an out-of-cycle newsletter, it appears that the deadline will be met without patches. So they have decided, now, to make available to all their discoveries, given the risk that users face.

Source: Hispasec I, II

- Publicidad -

See original.

No comments

• If you're already registered, please log in first. Your email will not be published.

Comments are closed

The comments for this content are closed.

Investing in Access Controllers: Why Eliminating Them Can Be a Strategic Mistake

Investing in Access Controllers: Why Eliminating Them Can Be a Strategic Mistake

Thanks to technological evolution, today there are smart readers with the capacity to process credentials, store information and even operate locks autonomously. This has led many organizations to...

Case study: How did a retail chain in Costa Rica reduce fraud by 18%?

Case study: How did a retail chain in Costa Rica reduce fraud by 18%?

Almacenes El Rey is a rapidly expanding department store, with 18 branches nationwide and more than one million customers each year. Thanks to the Avigilon Unity Video solution, the retail chain...

Is storing video no longer enough? Milestone's Sales Director for Latam speaks

Is storing video no longer enough? Milestone's Sales Director for Latam speaks

Latin America. Johana Arias, an executive at Milestone Systems, discusses how the integration of AI, natural language, and open platforms are transforming video into actionable insights for...

Anti-intrusion system described as one of Ajax's largest in South America

Anti-intrusion system described as one of Ajax's largest in South America

Argentina. The Bayron company installed a protection system with more than 85 Ajax wireless devices in the new branch of Autos del Sur S.A., Toyota's official dealership in the country.

Interview with Manuel Carlos, Senior Sales Director for Mexico at Hanwha Vision

Interview with Manuel Carlos, Senior Sales Director for Mexico at Hanwha Vision

Mexico. Manuel Carlos, an executive at Hanwha Vision, details how the company is revolutionizing electronic security by consolidating generative artificial intelligence and processing at the edge.

Prosegur presents new capabilities in cybersecurity and automation

Prosegur presents new capabilities in cybersecurity and automation

International. Prosegur Security has created two new modules, xCope and xEcute, which aim to provide companies and organizations with a new corporate digital surveillance service and another for...

Access and video platform

Access and video platform

Johnson Controls Designed to take the complexity out of legacy systems, the latest version of C•CURE IQ helps organizations achieve faster response, simplify workflows, and turn safety data into...

SIA presents the new directives of its International Relations Committee

SIA presents the new directives of its International Relations Committee

Latin America. Mariana Ramírez is the new president of the International Relations Committee of the Security Industry Association (SIA), while Vanesa Cabral assumed the role of vice president.

Access management and security in stadiums during the World Cup

Access management and security in stadiums during the World Cup

International. With the World Cup underway, stadium operation and the management of credentials and critical assets become key factors in ensuring security in high-demand environments.

Jovicard modernizes its headquarters with HID access control technology

Jovicard modernizes its headquarters with HID access control technology

Brazil. Jovicard, which specializes in physical access control, secure identity, biometrics and integrated electronic security, completed the modernization of its corporate headquarters with trusted...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter