Adobe confirms PDF zero-day, security update soon

By siliconindia   |   Monday, 09 August 2010, 18:49 IST   |    2 Comments
Printer Print Email Email
Bangalore: Adobe recently said that it would issue an emergency patch from august 16 to fix the critical flaw in its Reader and Acrobat software.The bug was disclosed by researcher Charlie Miller at last month's Black Hat security conference when he demonstrated how the open-source BitBlaze toolkit could be used to boost bug-hunting productivity 10-fold. Miller, an analyst with Baltimore-based Independent Security Evaluators, is well-known for finding vulnerabilities in Adobe's popular Reader PDF viewer. "Its just a coincidence that they are both bugs in the way programs parse fonts in PDFs," Miller said in an e-mail. Adobe announced it would release a rush, planning for a security update soon. Company hinted that the out-of-band update will include fixes for vulnerabilities other than the one Miller uncovered. The company also said it would still ship its next regularly-scheduled quarterly update on Oct. 12. The push to come up with a fix for the latest Reader zero-day will not affect work on the next major upgrade to the program, Adobe said.