Adobe Reader X 10.1.1
Adobe Reader 10.1.1 is uitgebracht. Deze uitgave van de meestgebruikte pdf lezer bevat dertien pleisters voor kritieke lekken die tot crashes kunnen leiden en die kunnen worden uitgebuit door kwaadwillenden.
Behalve de beveiligingslekken zijn ook diverse bugs opgelost en is de stabiliteit van Adobe Reader verbeterd.
Adobe Reader 10.1.1 is te verkrijgen voor Windows en Mac OS X. Updaten gaat het makkelijkst met de ingebouwde update-functie van Adobe onder Help. Een Linux-versie verschijnt in november pas. Een volgende ronde met reguliere beveiligingsupdates voor Adobe Reader staat gepland voor 13 december.
Release notes:
These updates resolve a local privilege-escalation vulnerability (Adobe Reader X (10.x) on Windows only) (CVE-2011-1353).
These updates resolve a security bypass vulnerability that could lead to code execution (CVE-2011-2431).
These updates resolve a buffer overflow vulnerability in the U3D TIFF Resource that could lead to code execution (CVE-2011-2432).
These updates resolve a heap overflow vulnerability that could lead to code execution (CVE-2011-2433).
These updates resolve a heap overflow vulnerability that could lead to code execution (CVE-2011-2434).
These updates resolve an buffer overflow vulnerability that could lead to code execution (CVE-2011-2435).
These updates resolve a heap overflow vulnerability in the Adobe image parsing library that could lead to code execution (CVE-2011-2436).
These updates resolve a heap overflow vulnerability that could lead to code execution (CVE-2011-2437).
These updates resolve three stack overflow vulnerabilities in the Adobe image parsing library that could lead to code execution (CVE-2011-2438).
These updates resolve a memory leakage condition vulnerability that could lead to code execution (CVE-2011-2439).
These updates resolve a use-after-free vulnerability that could lead to code execution (CVE-2011-2440).
These updates resolve two stack overflow vulnerabilities in the CoolType.dll library that could lead to code execution (CVE-2011-2441).
These updates resolve a logic error vulnerability that could lead to code execution (CVE-2011-2442).
These updates also incorporate the Adobe Flash Player updates as noted in Security Bulletin APSB11-21.

Reageren