Adobe Reader and Acrobat

Adobe Reader and Acrobat

Release date: October 22, 2007

Vulnerability identifier: APSB07-18

CVE number: CVE-2007-5020

Platform: Windows XP (Vista users are not affected) with Internet Explorer 7 installed

Affected software versions: Adobe Reader 8.1 and earlier, Adobe Reader 7.0.9 and earlier

Adobe Acrobat Professional, 3D and Standard 8.1 and earlier versions, Adobe Acrobat Professional, Standard, 3D and Elements 7.0.9 and earlier

Article

Thanks for that Humpty, still on me toes. :D

Anyone using the Adobe Reader 8.1 Lite, this update works fine.

I had to download the full installer because the integrated updater didn't find any relevant updates.

There's now a malicious .pdf attachment spreading, that utilizes this new Acrobat vulnerability. File can be named, i.e. as: report.pdf. Email can be named, i.e. as: Your credit report, Personal Financial Statement, Balance Report and Your Credit File.

What if you have, but don't use Adobe Reader?

The only time I use it is when I'm off line, Version:7.0.9