Adobe To Release Fix for Acrobat Security Hole

Adobe will shortly release an update to address a vulnerability in Adobe Reader and Acrobat 9.2 and earlier versions that was first reported in November.

The security hole is caused by boundary errors in the newplayer() JavaScript method in multimedia.api that can cause a computer to execute arbitrary code when a user opens a modified PDF file. The module, according to Core Security Technologies, runs a malicious Web site and waits for a user to trigger the exploit by connecting to the Web site through the PDF.

Adobe said it had reports that the vulnerability was being actively exploited. The company said updates addressing the problem would be available Jan. 12, 2010.

In other Adobe security news, the company released security patches for Illustrator CS4 and CS3 Thursday. The updates for both Mac OS X and Windows operating systems are designed to address issues that could subject systems to "arbitrary code execution," according to information released by Adobe.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • Children looking at screen displaying AI technology

    How Teachers and Administrators Can Contribute to AI Transparency

    To help students understand and use AI tools, teachers need professional development that supports them in redesigning tried-and-true assignments with an eye to teaching critical thinking.

  • students raising their hands and participating in a classroom discussion

    Report Explores Link Between Student Engagement and Learning

    Over 90% of teachers, principals, and superintendents agree that student engagement is a critical metric for understanding overall achievement, according to a new survey report from Discovery Education.

  • elementary school students using laptops displaying AI symbols and educational icons in a colorful classroom setting

    Khan Academy Revamps Platform for School Districts

    Khan Academy has reimagined its Khan Academy Districts platform, the paid partnership program that offers strategic implementation tools, data, and services for optimizing the use of Khan Academy district-wide.

  • magnifying glass highlighting a human profile silhouette, set over a collage of framed icons including landscapes, charts, and education symbols

    New AI Detector Identifies AI-Generated Multimedia Content

    Amazon Web Services and DeepBrain AI have launched AI Detector, an enterprise-grade solution designed to identify and manage AI-generated content across multiple media types. The collaboration targets organizations in government, finance, media, law, and education sectors that need to validate content authenticity at scale.