- http://secunia.com/advisories/23483/
Release Date: 2007-01-03
Critical: Less critical
Impact: Cross Site Scripting
Where: From remote
Solution Status: Unpatched
Software: Adobe Reader 6.x, Adobe Reader 7.x
…This can be exploited to execute arbitrary script code in a user's browser session in context of an affected site… The vulnerability is confirmed in version 6.0.1 for Windows via Internet Explorer 6 and version 7.0.8 for Windows via Firefox 2.0.0.1. Other versions may also be affected.
Solution: Upgrade to version 8.0.0*…"
- http://www.techweb.com/article/printableAr…p;site_section=
January 04, 2007
"…Adobe said that Reader 8.0, which was launched a month ago, was invulnerable to the cross-site scripting (XSS) bug, and recommended that all users update to that version immediately. "We encourage all users to update to this latest version of Adobe Reader," an Adobe spokesman wrote in an e-mailed statement. "[We are] also working on updates to previous versions that will resolve this issue." Fixes will be posted to Adobe's security site* when they are completed, he added…"
Update available for vulnerabilities in versions 7.0.8 and earlier of Adobe Reader and Acrobat
- http://www.adobe.com/support/security/bull…/apsb07-01.html
Release date: January 9, 2007
"…Solution: Adobe Reader on Windows
Adobe strongly recommends upgrading to Adobe Reader 8, available from the following site: http://www.adobe.com/go/getreader .
Users with Adobe Reader 7.0 through 7.0.8, who cannot upgrade to Reader 8, should upgrade to Reader 7.0.9. Adobe Reader 7.0.9 is available as a full installation package and not a patch. It can be installed on top of any older version of Reader 7 and user preferences will be preserved: http://www.adobe.com/go/getreader .
- http://www.techweb.com/article/printableAr…p;site_section=
January 10, 2007
"…Updates to Adobe Acrobat and Adobe Reader 6.x, which is also vulnerable to the cross-site scripting bug, will be forthcoming, said the company's spokesman, and should be available "soon"."
- http://www.adobe.com/support/security/bull…/apsb07-01.html
January 16, 2007 — "…Updated to reflect the availability of Adobe Reader and Acrobat 6.0.6* for Windows… Users with Adobe Reader 7.0 through 7.0.8, who cannot upgrade to Reader 8, should upgrade to Reader 7.0.9. Adobe Reader 7.0.9 is available as a full installation package and not a patch. It can be installed on top of any older version of Reader 7 and user preferences will be preserved: http://www.adobe.com/go/getreader.
If customers are using Adobe Reader 6.0–6.0.5 and are unable to upgrade to version 8 or 7.0.9 due to Operating System constraints for example, Adobe recommends upgrading to version 6.0.6 either via a series of patches from: http://www.adobe.com/support/downloads/pro…latform=Windows
-or- by using the auto-update mechanism within the product when prompted…"