Added on 14 Oct 2009(1264 Views)
Yesterday, the 13th of October, both Adobe and Microsoft released patches and fixes for their products. Adobe released 1 security bulletin that addressed a total of 29 security vulnerabilities plaguing Adobe Reader and Adobe Acrobat 9.1.3 (and previous versions 8.1.6 and 7.1.3). Microsoft released 13 security bulletins which address 34 security holes affecting a variety of software products: Windows, Internet Explorer, Office, Silverlight, Forefront, Developer Tools, and SQL Server. Today we take a closer look at these updates.Starting with Adobe, the California-based company that specializes in creating multimedia and creativity software products, it released Adobe Reader and Acrobat 9.2, 8.1.7 and 7.1.4 to address the following 29 security vulnerabilities:
- CVE-2009-3459 - Heap overflow vulnerability that could lead to code execution
- CVE-2009-2985 - Memory corruption issue that could potentially lead to code execution
- CVE-2009-2986 - Multiple heap overflow vulnerabilities that could potentially lead to code execution
- CVE-2009-2990 - Invalid array index issue that could potentially lead to code execution
- CVE-2009-2991 - Remote exploitation issue specific to the Mozilla plug-in that could potentially allow an attacker to execute arbitrary code with the privileges of the current user
- CVE-2009-2993 - Multiple input validation vulnerabilities that could potentially lead to code execution
- CVE-2009-2994 - Buffer overflow issue that could potentially lead to code execution
- CVE-2009-2997 - Heap overflow vulnerability that could potentially lead to code execution
- CVE-2009-2998 - Input validation issue that could potentially lead to code execution
- CVE-2009-3458 - Input validation issue that could potentially lead to code execution
- CVE-2009-3460 - Memory corruption issue that could potentially lead to code execution (Acrobat only)
- CVE-2009-2989 - Integer overflow that could potentially lead to code execution (Acrobat only)
- CVE-2009-2983 - Memory corruption issue that leads to a Denial of Service (DoS); arbitrary code execution is possible but has not been demonstrated
- CVE-2009-2980 - Integer overflow that leads to a Denial of Service (DoS); arbitrary code execution is possible but has not been demonstrated
- CVE-2009-2996 - Memory corruption issue that leads to a Denial of Service (DoS); arbitrary code execution is possible but has not been demonstrated
- CVE-2009-3462 - Unix-only format bug when running in Debug mode that could lead to arbitrary code execution
- CVE-2009-2984 - image decoder issue that leads to a Denial of Service (DoS); arbitrary code execution is possible but has not been demonstrated (Acrobat only)
- CVE-2009-2981 - Input validation issue that could potentially lead to a bypass of Trust Manager restrictions
- CVE-2009-3461 - Issue that could allow a malicious user to bypass file extension security controls (Acrobat 9.X only)
- CVE-2009-2982 - Certificate that if compromised could potentially be used in a social engineering attack
- CVE-2009-3431 - Stack overflow issue that could potentially lead to a Denial of Service (DoS) attack
- CVE-2009-2979 - XMP-XML entity expansion issue that could lead to a Denial of Service (DoS) attack
- CVE-2009-2987 - Remote denial of service issue in the ActiveX control specific to the Windows OS
- CVE-2009-2988 - Input validation issue that could lead to a Denial of Service (DoS) issue
- CVE-2009-2992 - Input validation issue specific to the ActiveX control that could lead to a Denial of Service (DoS) attack
- CVE-2009-2995 - Integer overflow in that leads to a Denial of Service (Acrobat only)
- CVE-2009-2564 - Third party web download product that Adobe Reader uses that could potentially lead to local privilege escalation
- CVE-2007-0048 and CVE-2007-0045 - Cross-site scripting issue when the browser plugin is used with Google Chrome and Opera browsers
Please note that support for Adobe Reader 7.X and Acrobat 7.X will end this December. Adobe Reader and Acrobat 7.1.4 is the last scheduled update. You are well advised to upgrade to a supported version.
Moving on to Microsoft, the Redmond-based software developer on Tuesday released the following 13 bulletins (that fix 34 vulnerabilities).
- MS09-050 - Vulnerabilities in SMBv2 Could Allow Remote Code Execution; 3 critical vulnerabilities.
- MS09-051 - Vulnerabilities in Windows Media Runtime Could Allow Remote Code Execution; 2 critical vulnerabilities.
- MS09-052 - Vulnerability in Windows Media Player Could Allow Remote Code Execution; 1 critical vulnerability.
- MS09-054 - Cumulative Security Update for Internet Explorer (974455); 4 critical vulnerabilities.
- MS09-055 - Cumulative Security Update of ActiveX Kill Bits; 1 critical vulnerability.
- MS09-060 - Vulnerabilities in Microsoft Active Template Library (ATL) ActiveX Controls for Microsoft Office Could Allow Remote Code Execution; 3 critical vulnerabilities.
- MS09-061- Vulnerabilities in the Microsoft .NET Common Language Runtime Could Allow Remote Code Execution; 3 critical vulnerabilities.
- MS09-062 - Vulnerabilities in GDI+ Could Allow Remote Code Execution; 8 critical vulnerabilities.
- MS09-053 - Vulnerabilities in FTP Service for Internet Information Services Could Allow Remote Code Execution; 2 important vulnerabilities.
- MS09-056 - Vulnerabilities in Windows CryptoAPI Could Allow Spoofing; 2 important vulnerabilities.
- MS09-057- Vulnerability in Indexing Service Could Allow Remote Code Execution; 1 important vulnerability.
- MS09-058 - Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege; 3 important vulnerabilities.
- MS09-059 - Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service; 1 important vulnerability.
The Microsoft Security Response Center has provided these visual representations of the October 2009 Patch Tuesday update.
Additional details about the Adobe update are available here.
Additional details about the Microsoft update are available here.
Don't forget to:
RSSTags: Patch Tuesday, Microsoft, Adobe, Security
Link to this article:
Add comment:
Software News
Chromium OS Goes Open-Source
This summer Google let the world know that it is working on a new operating system meant for the user that spends most of his time online. The operating system – aptly named Chrome OS because it is a natural extension...
20 Nov 2009
Office 2010 Beta Downloads Available to the Public
Earlier this week Redmond-based software giant Microsoft announced that Office 2010 became available for download as a Beta. The catch was that only ...
20 Nov 2009
Mozilla Releases: Firefox 3.6 Beta 3
The development process of the Firefox 3.6 browser is moving along rapidly. The first Beta version was released at the start of the month; Beta 2 was released about two weeks after Beta 1. About a week has passed since...
20 Nov 2009
New Labs Feature for Gmail: Green Robot!
The software developers at Google have announced the release of a new Gmail Labs offering called Green Robot! This new offering is meant to improve the Gmail Chat user experience by letting the ...
20 Nov 2009
Opera Mobile 10 Beta for Windows Mobile Is Out Also
Opera Software, the company that we all know for making the innovative and feature rich Opera web browser, has released Opera Mobile 10 Beta for Windows Mobile-powered devices. This release follows in the...
19 Nov 2009
Beta Testing is Over, Stable Version of Trillian for iPhone Released
The focus so far has been on desktop version of this multiprotocol instant messaging software application, Trillian Astra (version 4.1). Today is time to switch focus away from the desktop version and onto something a bit more...
19 Nov 2009
Recommended Tools
Registry Booster 2010 Enhanced, deeper and faster error scan performance. Now also in 5 languages! Free Scan
Driver Scanner 2009
Fast and easy, it boosts performance by scanning for, downloading & installing driver updates
Fast and easy, it boosts performance by scanning for, downloading & installing driver updates
SpeedUpMyPC 2009
How fast is your PC really running? Turbo-charge your Internet and PC performance here
How fast is your PC really running? Turbo-charge your Internet and PC performance here



