Adobe/Acrobat 0-day in the wild?
According to our friends over at Shadowserver, There is a new Acrobat 0-day in the wild. They say you can avoid it by turning off Javascript inside of your Adobe Acrobat products.
Please see Shadowserver's write up: here for more information
UPDATE: Another great VRT Blog post. These guys keep pumping them out! Check it out here.
UPDATE Shadowserver has released important mitigation information. You can see that post at the url below.
http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20090221
UPDATE: Sourcefire VRT has published a "homebrew" patch for the vuln. PLEASE TEST THIS BEFORE DEPLOYING IN ANY ENVIRONMENT!!! SANS ISC has NOT verified the effectiveness of this "homebrew patch", and as such we cannot make any claims or comments on its effectiveness or any unintended consequences of using this modified software. As some of you may remember ZERT in the past has done similar, and there are obviously caveats involved with this approach. (both technical and possibly legal) So please do educate your self, and if need be discuss with your legal team before deploying third party modified software into your environment.
Information on patch:
http://vrt-sourcefire.blogspot.com/2009/02/homebrew-patch-for-adobe-acroreader-9.html
Information on ZERT:
Disclosure: Joel works for Sourcefire, but does not work for the VRT.
UPDATE 2: Based on the comments to this diary entry something needs to be cearly stated. Java has NO relation to this exploit, javascript is utilized by the attackers to massage memory structures to build a more reliable exploit. Disabling javascript will remove this ability and make a reliable exploit much harder to build. - Andre L
-- Joel Esler http://www.joelesler.net
-- Andre L
Comments
Excuse my french - wtf...!
Brian
Feb 20th 2009
1 decade ago
Lee
Feb 20th 2009
1 decade ago
In this specific case it is, but, as far as i understand, JAVA is not needed to exploit the mentioned issue.
So other working exploits will come up, not using JAVA, but getting a lot of users into trouble.
Manuel
Feb 21st 2009
1 decade ago
And you should really disclose relationships before you brag up VRT.
Ken
Feb 21st 2009
1 decade ago
Joel
Feb 22nd 2009
1 decade ago
Andre
Feb 23rd 2009
1 decade ago
Jason
Feb 23rd 2009
1 decade ago