This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Adobe Reader v6, v7 vuln - update available

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI… new:

- http://secunia.com/advisories/23483/
Release Date: 2007-01-03
Critical: Less critical
Impact: Cross Site Scripting
Where: From remote
Solution Status: Unpatched
Software: Adobe Reader 6.x, Adobe Reader 7.x
…This can be exploited to execute arbitrary script code in a user's browser session in context of an affected site… The vulnerability is confirmed in version 6.0.1 for Windows via Internet Explorer 6 and version 7.0.8 for Windows via Firefox 2.0.0.1. Other versions may also be affected.
Solution: Upgrade to version 8.0.0*…"

* http://forums.tomcoyote.org/index.php?show…mp;#entry336514

:ph34r:
FYI…

- http://www.techweb.com/article/printableAr…p;site_section=
January 04, 2007
"…Adobe said that Reader 8.0, which was launched a month ago, was invulnerable to the cross-site scripting (XSS) bug, and recommended that all users update to that version immediately. "We encourage all users to update to this latest version of Adobe Reader," an Adobe spokesman wrote in an e-mailed statement. "[We are] also working on updates to previous versions that will resolve this issue." Fixes will be posted to Adobe's security site* when they are completed, he added…"

* http://www.adobe.com/support/security/

- http://www.adobe.com/support/security/advi…/apsa07-01.html
Release date: January 4, 2007
FYI…

Update available for vulnerabilities in versions 7.0.8 and earlier of Adobe Reader and Acrobat
- http://www.adobe.com/support/security/bull…/apsb07-01.html
Release date: January 9, 2007
"…Solution: Adobe Reader on Windows
Adobe strongly recommends upgrading to Adobe Reader 8, available from the following site:
http://www.adobe.com/go/getreader .
Users with Adobe Reader 7.0 through 7.0.8, who cannot upgrade to Reader 8, should upgrade to Reader 7.0.9. Adobe Reader 7.0.9 is available as a full installation package and not a patch. It can be installed on top of any older version of Reader 7 and user preferences will be preserved: http://www.adobe.com/go/getreader .

Windows
Adobe Acrobat 7.0.9 Standard/Professional/3D update - multiple languages
* http://www.adobe.com/support/downloads/new.jsp
1/9/2007

Server-side workarounds to prevent potential cross-site scripting vulnerability in versions 7.0.8 and earlier…
- http://www.adobe.com/support/security/advi…/apsa07-02.html
Release date: January 9, 2007

.
FYI…

- http://www.adobe.com/support/security/bull…/apsb07-01.html
January 16, 2007 — "…Updated to reflect the availability of Adobe Reader and Acrobat 6.0.6* for Windows… Users with Adobe Reader 7.0 through 7.0.8, who cannot upgrade to Reader 8, should upgrade to Reader 7.0.9. Adobe Reader 7.0.9 is available as a full installation package and not a patch. It can be installed on top of any older version of Reader 7 and user preferences will be preserved: http://www.adobe.com/go/getreader.

If customers are using Adobe Reader 6.0–6.0.5 and are unable to upgrade to version 8 or 7.0.9 due to Operating System constraints for example, Adobe recommends upgrading to version 6.0.6 either via a series of patches from: http://www.adobe.com/support/downloads/pro…latform=Windows
-or- by using the auto-update mechanism within the product when prompted…"

> http://www.adobe.com/products/acrobat/read…llversions.html

.