Adobe Reader 9.0 buffer overflow issue(APSA09-01, CVE-2009-0658)

Bug #332503 reported by Fumihito YOSHIDA
254
Affects Status Importance Assigned to Milestone
Ubuntu Japanese Kaizen Project
Fix Released
High
Unassigned

Bug Description

see http://www.adobe.com/support/security/advisories/apsa09-01.html

Adobe said "Adobe expects to make available an update for Adobe Reader 9 and Acrobat 9 by March 11th"

> Release date: February 19, 2009
>
> Vulnerability identifier: APSA09-01
>
> CVE number: CVE-2009-0658
>
> Platform: All platforms
>

> Summary
>
> A critical vulnerability has been identified in Adobe Reader 9 and Acrobat 9 and earlier
> versions. This vulnerability would cause the application to crash and could potentially
> allow an attacker to take control of the affected system. There are reports that this
> issue is being exploited.

> Adobe is planning to release updates to Adobe Reader and Acrobat to resolve the relevant
> security issue. Adobe expects to make available an update for Adobe Reader 9 and Acrobat 9
> by March 11th, 2009. Updates for Adobe Reader 8 and Acrobat 8 will follow soon after, with
> Adobe Reader 7 and Acrobat 7 updates to follow. In the meantime, Adobe is in contact with
> anti-virus vendors, including McAfee and Symantec, on this issue in order to ensure the
> security of our mutual customers. A security bulletin will be published on
> http://www.adobe.com/support/security as soon as product updates are available.
>
> All documented security vulnerabilities and their solutions are distributed through the
> Adobe security notification service. You can sign up for the service at the following
> URL: http://www.adobe.com/cfusion/entitlement/index.cfm?e=szalert

> Affected software versions
>
> Adobe Reader 9 and earlier versions
> Adobe Acrobat Standard, Pro, and Pro Extended 9 and earlier versions

> Severity rating
>
> Adobe categorizes this as a critical issue and recommends that users update their
> virus definitions and exercise caution when opening files from untrusted sources.

CVE References

Fumihito YOSHIDA (hito)
Changed in ubuntu-jp-improvement:
importance: Undecided → High
status: New → Triaged
Revision history for this message
Fumihito YOSHIDA (hito) wrote :

Adobe will release patch for Adobe Reader 9 at Mar 11, for Adobe Reader 8 at Mar 18(maybe).

Revision history for this message
Fumihito YOSHIDA (hito) wrote :

Adobe Reader 9.1 is released, but these are not for Linux.
http://www.adobe.com/support/security/bulletins/apsb09-03.html

We have to wait for newer Adobe Reader 8.x.

Revision history for this message
Fumihito YOSHIDA (hito) wrote :

and,
> Adobe recommends users of Adobe Reader and Acrobat 9 update to Adobe Reader 9.1
> and Acrobat 9.1. Adobe is planning to make available updates for Adobe Reader 7
> and 8, and Acrobat 7 and 8, by March 18. In addition, Adobe plans to make
> available Adobe Reader 9.1 for Unix by March 25.

9.1 for Linux?

Revision history for this message
Fumihito YOSHIDA (hito) wrote :

Basically test is OK, 8.1.3 => 8.1.4 can bumps. here is debdiff(FYI).

Revision history for this message
Jun Kobayashi (jkbys) wrote :

ありがとうございます。8.1.4のパッケージをアップロードしました。

Fumihito YOSHIDA (hito)
Changed in ubuntu-jp-improvement:
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.