Adobe Reader and Acrobat
Release date: October 22, 2007
Vulnerability identifier: APSB07-18
CVE number: CVE-2007-5020
Platform: Windows XP (Vista users are not affected) with Internet Explorer 7 installed
Affected software versions: Adobe Reader 8.1 and earlier, Adobe Reader 7.0.9 and earlier
Adobe Acrobat Professional, 3D and Standard 8.1 and earlier versions, Adobe Acrobat Professional, Standard, 3D and Elements 7.0.9 and earlier
Thanks for that Humpty, still on me toes.
Anyone using the Adobe Reader 8.1 Lite, this update works fine.
I had to download the full installer because the integrated updater didn't find any relevant updates.
There's now a malicious .pdf attachment spreading, that utilizes this new Acrobat vulnerability. File can be named, i.e. as: report.pdf. Email can be named, i.e. as: Your credit report, Personal Financial Statement, Balance Report and Your Credit File.
What if you have, but don't use Adobe Reader?
The only time I use it is when I'm off line, Version:7.0.9