Slashdot Mirror


Adobe Warns of Critical Zero Day Vulnerability

wiredmikey writes "Adobe issued an advisory today on a zero-day vulnerability (CVE-2011-2462) that has come under attack in the wild. According to Adobe, the issue is a U3D memory corruption vulnerability that can be exploited to cause a crash and permit an attacker to hijack a system. So far, there are reports the vulnerability is being exploited in limited, targeted attacks against Adobe Reader 9.x on Windows. However, the bug also affects Adobe Reader and Acrobat 9.4.6 and earlier 9.x versions for UNIX and Macintosh computers, as well as Adobe Reader X (10.1.1) and Acrobat X (10.1.1) and earlier 10.x versions on Windows and Mac. Patches for Windows and Mac users of Adobe Reader X and Acrobat X will come on the next quarterly update, scheduled for Jan. 10, 2012."

1 of 236 comments (clear)

  1. Re:A lack of diversity... by mirix · · Score: 5, Interesting

    Evince (gtk) and Okular (ex-kpdf, iirc, Qt) both seem pretty usable to me.

    At work, I'm stuck with windows, and the Evince win32 port seems to work quite well there too. Only issue I ran into was that be default it tried to print things in landscape mode or something like that, and I didn't notice.
    A nice feature is that it does djvu and postscript as well, instead of having multiple readers (although I seem to think ps might not work with windows in default, probably relies on ghostscript or so..?).

    --
    Sent from my PDP-11