Security Initiative: Adobe Mimics Microsoft's Patch Tuesday Program
Article by George Norman
On 25 May 2009
It seems that Adobe is getting tired with all the security vulnerabilities and security holes affecting its software applications and consequently has announced the fact that it is launching a program similar to Microsoft’s Patch Tuesday (patches and fixes are released every second Tuesday of the month). The move is a welcomed one, if you keep in mind that just a couple of weeks ago Adobe Acrobat 9.1.1 and Adobe Reader 9.1.1 were released in order to address a 0-day security hole affecting all currently supported shipping versions of Adobe’s products. You should also keep in mind that targeted attacks against Adobe’s products have seen a considerable increase (see the image below, provided by F-Secure).

Director of Product Security and Privacy, Brad Arkin, explains: “Starting this summer we plan to release security updates for all major supported versions and platforms of Adobe Reader and Acrobat on a quarterly basis. Based on feedback from our customers, who have processes and resources geared toward Microsoft’s “Patch Tuesday” security updates, we will make Adobe’s quarterly patches available on the same days.”

Advertising

Adobe’s “Patch Tuesday” program is part of a larger security initiative that is meant to eliminate or at least mitigate some of the security risks that plague Adobe’s software; the security initiative is also meant to improve Adobe’s ability to respond to vulnerabilities in Reader and Acrobat discovered by external security researchers.

Adobe’s security initiative is focused on 3 major areas: the Patch Tuesday program, as mentioned above, code hardening and incident response process enhancement. “An initiative in the current security effort has been focused on hardening at-risk areas of the legacy code,” explained Brad Arkin. “We’ve applied the latest SPLC [Secure Product Lifecycle] techniques against these prioritized sections of each application. Even in cases where no immediate vulnerability was identified, we have been strengthening input validation on a best-practice basis. Experience shows such validation is a powerful tool in preventing as-yet unidentified security holes.”

Regarding the incident response process enhancement topic, Arkin says external security researchers can expect to see a faster incident response process on Adobe’s part, timelier incident related communications, and faster turn-around times on patch releases. When updates are released, you can also expect Adobe to release patches for multiple affected versions.






Tags: Adobe Acrobat , Adobe Reader, Security Initiative, Patch Tuesday
About the author: George Norman
George is a leading software reviewer at FindMySoft, he is pasionate about technology and he likes to write about IT news
You can follow him on Google+, Facebook or Twitter
I Hope you LIKE this blog post! Thank you!
What do YOU have to say about this
blog comments powered by Disqus
Popular News
By George Norman on 10 Feb 2012
With the release of Wolfram|Alpha Pro, the team behind the popular computational knowledge engine took a very big step forward
By George Norman on 10 Feb 2012
Microsoft has just announced that this February, as part of the Patch Tuesday program, it will roll out a grand total of 9 security bulletins to all customers all over the world.
Related News
By George Norman on 14 Sep 2011
Below you can check out the information Redmond-based software giant Microsoft released about the 5 security bulletins it rolled out this September as part of its Patch Tuesday program. The
By George Norman on 09 Sep 2011
Redmond-based software giant Microsoft has recently announced that this September, as part of its Patch Tuesday program, it will roll out 5 security bulletins to its customers all over the world. All five
By George Norman on 11 Oct 2011
Today, October 11th, is the second Tuesday of the month, which means that Microsoft will roll out patches for its products as part of the Patch Tuesday program
By George Norman on 04 Nov 2011
Redmond-based software giant Microsoft has recently announced that next week, as part of the Patch Tuesday program, it will roll out a four security bulletins. The aforementioned bulletins are meant to plug
Advertising
Hot Software Updates
Top Downloads
Become A Fan!
Link To Us!
Security Initiative: Adobe Mimics Microsoft's Patch Tuesday Program
HTML Linking Code