By George Norman - Software News Editor
Added on 03 Nov 2008(768 Views)
According to an Adobe Systems Inc. security advisory, there were two security holes in its PageMaker software that needed plugging. I used the past tense because these two vulnerabilities have been beautifully addressed by Adobe. Now if only they could get cracking on the third one, one could use their software program with more confidence.

The vulnerabilities in question, which have been dubbed CVE-2007-6432 and CVE-2007-5394, affect the following platforms: Adobe PageMaker 7.0.1 and PageMaker 7.0.2. What are the risks of using the previously mentioned programs without patching? To put it simply, someone with malicious intent could assume control of your system by exploiting said vulnerabilities from a remote location. Yes, the vulnerabilities are exploitable and they do allow remote code execution.


The third vulnerability that I was talking about, entitled CVE-2007-6021, although acknowledged by Adobe, has yet to be patched. The only means of protecting yourself is to upgrade (so as to at least deal with the first two security holes), and be weary of PageMaker files that originate from untrusted sources.

Just to put things into perspective, Adobe uses a 4 tier rating system: low, moderate, important and critical. Adobe has attributed the latter rating to the three vulnerabilities. Secunia, company that specializes in providing security software solutions, has gone one further and categorized them as “highly critical”.

There is one additional means of staying protected: giving up on PageMaker 7.0. Adobe has let go of the 23 year old software (initially released back in 1985) and moved on, so why no do the same? So forget about PageMaker 7.0, which no longer benefits from maintenance support, and switch to Adobes InDesign CS4 (Creative Suite 4) which shipped out in the middle of October, 2008.





Don't forget to:

RSS


Tags: Adobe, PageMaker 7.0

Link to this article:



Add comment:
Name(Required)
Email(Required - Never shown)
Website(Optional)
Comment(Required):

Insert the following code:
Software News
This Week Only: One Opera Unite App per Day
Opera Software, the company behind the innovative Opera web browser has just announced the release of Opera 10.10 as a final, stable software application. That is good news for Opera users, but here comes one better...
23 Nov 2009
Reinvent the Web: Opera 10.10 Final with Opera Unite
Earlier this year Opera Software announced that it would “reinvent the web” – then on the 16th of June do this (reinvent the world I mean) with Opera Unite, a new technology that makes the old client-server computing model look outdated....
23 Nov 2009
Palm Delivers WebOS 1.3.1 to European Customers
Palm recently announced that it updated the WebOS (the operating system that powers the Palm Pre and the Palm Pixi) to version 1.3.1 and that it released it to its...
23 Nov 2009
Chromium OS Goes Open-Source
This summer Google let the world know that it is working on a new operating system meant for the user that spends most of his time online. The operating system – aptly named Chrome OS because it is a natural extension...
20 Nov 2009
Office 2010 Beta Downloads Available to the Public
Earlier this week Redmond-based software giant Microsoft announced that Office 2010 became available for download as a Beta. The catch was that only ...
20 Nov 2009
Mozilla Releases: Firefox 3.6 Beta 3
The development process of the Firefox 3.6 browser is moving along rapidly. The first Beta version was released at the start of the month; Beta 2 was released about two weeks after Beta 1. About a week has passed since...
20 Nov 2009
Recommended Tools

Top Downloads