|
|
|
You are here: News > News > Adobe and Oracle saved their products with the latest update
| » IT Security NEWS |
| » 15 April 2010 |
| Adobe and Oracle saved their products with the latest update |
A patch was released in order to remedy the 15 security flaws found in the product of Adobe. The company distributed the remedy for the two versions of Adobe Reader 9.3.2 and 8.2.2 that are compatible with three different operating systems like Windows, Mac, and Unix. The fix was also intended for the Acrobat Reader that works on Windows and Mac operating systems.
Security faults may invite unwanted guests
Twelve of the 15 vulnerabilities increase the risk of illegal access of online crooks into the systems. It permits incorporation and the activation of malicious codes into affected systems. However, the company has not yet confirmed the risks of the remaining three flaws. Thus, as of this moment, they consider the three vulnerabilities as Denial-of-Service (DOS) flaws.
In reality, opening a PDF document is not needed for a system to become affected by a malicious code. Users may easily become a victim by just pointing to a browser containing a Reader plug-in that is susceptible to attacks. And, today, no remedy has yet been formulated for the newly discovered security threat “/launch”.
Manipulation of the application’s option is necessary
In response to this problem, Adobe suggests disabling “Allow opening non-PDF file attachments with external applications” that can be found in the option within the Preferences or Trust Manager.
It is evident that there are quite a great number of vulnerabilities that needed patching up. Hence, the firm recommends that the customers install the latest version of the product.
There is an automatic patch for this latest update, according to Adobe. But then, the firm notifies their valued customers that it is advisable to just download the update manually so as to begin the process of upgrading the software.
Examination of Adobes new updater is needed in order to see whether there is an interruption on the time when the patch is being automatically downloaded. And, it is also needed in order to verify if the updater checks for the available patches at the start-up.
Released patches must be installed instantly
In Oracle’s case, updates and patch for security threats that is called the Critical Patch Update (CPU) are being done every quarter of the year. About 47 security vulnerabilities in the products were patched up by this firm. The merchandises include the database, business suites, Java System Directory Server, and the Sun Solaris.
A number of threats were considered to be critical like that of the one in the Sun Ray Server. This company also advises their consumers to install the released patches at once in order to avoid any system attacks.
For more information about us, surf through the following SecPoint links: About SecPoint, SecPoint Press, and SecPoint Awards. |