Sicherheitslücke in Adobe Reader & Acrobat wird aktiv ausgenutzt

Supernature

Und jetzt?
Teammitglied
In Adobes PDF-Tools Adobe Acrobat und Adobe Reader klafft ein Sicherheitsleck, welches nach Angaben des Unternehmens bereits aktiv ausgenutzt wird.
Betroffen sind alle Versionen bis hin zu aktuellen Version 9.2.
Leider liegen keine Informationen vor, welche Gefahren durch diese Sicherheitslücke drohen und wie man sich bis zum Erscheinen eines Patches, der wohl bereits in Arbeit ist, schützen kann.

New Adobe Reader and Acrobat Vulnerability - Adobe Product Security Incident Response Team (PSIRT)

Auch von vertrauenswürdigen Absendern zugesandte PDF-Dateien sind daher aktuell mit erhöhter Vorsicht zu behandeln.
 
Ein Problem mit dem natürlich jedes populäre Programm/System zu kämpfen hat.

Allerdings gibt es in diesem Fall schon lange keinen vernünftigen Grund mehr den Adobe Reader zu installieren. Es gibt etliche sehr gute Alternativen und zwei der besten (in der Windows-Welt zumindest) sind der Foxit Reader und der PDF-XChange Viewer. Beide sind dem Original überlegen. Der Foxit Reader was Geschwindigkeit und Resourcenbedarf angeht und der XChange Viewer was die Funktionalität angeht.

Beide gibt es in einer kostenlosen Standard Version und auch in einer kostenpflichtigen die dann erweitere Funktionalität bietet. Aber bereits in der Standard Version reicht der Foxit Reader zum betrachten von PDFs völlig aus und spätestens beim XChange Viewer sieht der Adobe Reader nur noch die Rücklichter seiner Konkurrenten.
 
Wer das Programm derzeit verwendet, sollte unter Bearbeiten -> Voreinstellungen -> JavaScript
den Haken bis auf weiteres entfernen.
 
Javascript ausschalten ist leider nicht immer die machbare Option beim Adobe, da damit ein paar Funktionen fliegen gehen. Man kann ihn aber auch in einer Sandbox oder VM laufen lassen, falls man mit digital signierten Dokumenten umgehen bzw. ausgefüllte Formulare speichern muss.
 
Javascript ausschalten ist leider nicht immer die machbare Option beim Adobe, da damit ein paar Funktionen fliegen gehen. Man kann ihn aber auch in einer Sandbox oder VM laufen lassen, falls man mit digital signierten Dokumenten umgehen bzw. ausgefüllte Formulare speichern muss.

Das ist natürlich richtig und soll nur bei unbekannter Herkunft ein wenig schützen,
wobei man dann selbst entscheidet, was man tut.
Die Sandbox oder VM wäre natürlich eine gute Lösung, die aber nicht weit verbreitet ist.
 
Hier die Release Notes von Adobe auf Englisch:

Release date: January 12, 2010

The Adobe® Reader® and Acrobat® 9.3 update is a quarterly update—a fully encompassing update which includes functional improvements as requested by customers and security updates encountered during the previous quarterly period. 9.3 address a number of customer workflow issues, security vulnerabilities, and more stability.

Adobe recommends that you install the latest applicable update:

•Adobe Reader 9.3

•Adobe Reader 9.3 MUI

•Adobe Acrobat 9.3 Standard

•Adobe Acrobat 9.3 Professional

•Adobe Acrobat 9.3 Pro Extended
Distribution methods

Note: This Update can be applied to Adobe Acrobat version 9.2 on Windows & Macintosh and Adobe Reader 9.2 MUI on Windows.

•Update via the automatic product update system (Windows and Macintosh Only).

•Manually download the Incremental update for Adobe Acrobat 9.3 (Windows and Macintosh) from Adobe support.

•Download the full Adobe Reader installers via Reader Download Center.

•For more information regarding enterprise Administrative Install Point (AIP) installations, please click here.


SYSTEM REQUIREMENTS

Adobe Reader 9.3 (Windows®)

•Intel® 1.3 GHz processor or equivalent

•Microsoft® Windows® 2000 with Service Pack 4, Windows Server® 2003, 2008 and 2008 R2; Windows XP® Professional, Home Edition, or Tablet PC Edition with Service Pack 2 or 3 (32-bit and 64-bit); Windows Vista® Home Basic, Home Premium, Business, Ultimate, or Enterprise Service Pack 1 or 2 (32-bit and 64-bit), Microsoft Windows 7 Starter, Home Premium, Professional, Ultimate or Enterprise (32-bit and 64-bit)

•128MB of RAM (256MB recommended)

•335MB of available hard disk space (additional space required for installation)

•Microsoft Internet Explorer 6.0, 6.0 with Service Pack 1, 7.0 or 8.0; Firefox 2.0, 3.0 or 3.5

Adobe Reader 9.3 (Macintosh)

•PowerPC® G4, G5 or Intel processor

•PPC: Mac OS X v10.4.11–10.5.8. Intel: Mac OS X v10.4.11–10.6

•128MB of RAM (256MB recommended)

•405MB of available hard-disk space (additional space required for installation)

•Safari® 3.0.4 or later

Adobe Reader 9.3 MUI (Windows)

•Intel 1.3 GHz processor or equivalent

•Microsoft Windows 2000 with Service Pack 4, Windows Server 2003, 2008 and 2008 R2 (32-bit and 64-bit); Windows XP Professional, Home Edition, or Tablet PC Edition with Service Pack 2 or 3 (32-bit and 64-bit); Windows Vista® Home Basic, Home Premium, Business, Ultimate, or Enterprise Service Pack 1 or 2 (32-bit and 64-bit), Microsoft Windows 7 Starter, Home Premium, Professional or Ultimate or Enterprise (32-bit and 64-bit)

•128MB of RAM (256MB recommended)

•335MB of available hard disk space (additional space required for installation)

•Microsoft Internet Explorer 6.0, 6.0 with Service Pack 1, 7.0 or 8.0; Firefox 2.0, 3.0 or 3.5

Adobe Reader 9.3 (Linux)

•32-bit Intel Pentium® processor or equivalent

•Red Hat® Linux WS 5, SUSE® Linux Enterprise Desktop (SLED) 10 SP2 or Ubuntu™ 7.10

•GNOME or KDE Desktop Environment

•512MB of RAM (1GB recommended)

•150MB of available hard-disk space (additional 75MB required for all supported font packs)

•GTK+ (GIMP Toolkit) user interface library, version 2.6 or later

•Firefox 2.0 or later

•OpenLDAP and CUPS libraries

Adobe Reader 9.3 (Solaris)

•32-bit Intel Pentium processor or equivalent

•Solaris™ 10 u5 or OpenSolaris™ 2008.11

•GNOME or KDE Desktop Environment (GNOME only for Solaris 10)

•512MB of RAM (1GB recommended)

•200MB of available hard-disk space (additional 75MB required for all supported font packs)

•GTK+ (GIMP Toolkit) user interface library, version 2.6 or later (on Solaris 10; also works with GTK 2.4.9)

•Firefox 2.0 or later

•OpenLDAP and CUPS libraries

Adobe Acrobat 9.3 Professional, Standard and Pro Extended (Windows)

•Intel 1.3 GHz processor or equivalent

•Microsoft Windows XP Home, Professional, or Tablet PC Edition with Service Pack 2 or 3 (32-bit and 64-bit); Windows Server 2003 (with Service Pack 2 for 64-bit); Windows Vista® Home Basic, Home Premium, Business, Ultimate, or Enterprise with Service Pack 1 or 2 (32-bit and 64-bit), Microsoft Windows Server 2008 or 2008 R2; Microsoft Windows 7 Starter, Home Premium, Professional, Ultimate or Enterprise (32-bit or 64-bit)

•256 MB of installed RAM (512 MB recommended)

•2.14 GB of available hard-disk space

•1024 x 768 screen resolution

•Microsoft Internet Explorer 6.0, 6.0 with Service Pack 1, 7.0, or 8.0; Firefox 2.0, 3.0 or 3.5

•Video hardware acceleration (optional)

Adobe Acrobat 9.3 Professional (Macintosh)

•PowerPC G4, G5 or Intel processor

•PPC: Mac OS X v10.4.11–10.5.8. Intel: Mac OS X v10.4.11–10.6

•256 MB of installed RAM (512 MB recommended)

•1.42 GB of available hard-disk space

•1024 x 768 screen resolution

•Safari 3.0.4 or above


LANGUAGES

Adobe Reader 9.3 (Windows), Adobe Acrobat 9.3 Professional (Windows), Adobe Acrobat 9.3 Standard (Windows)

* English, French, German, Japanese, Spanish, Italian, Dutch, Brazilian Portuguese, Swedish, Danish, Finnish, Norwegian, Chinese Simplified, Chinese Traditional, Korean, Czech, Hungarian, Polish, Slovak, Romanian, Ukrainian, Russian, Turkish, Bulgarian, Croatian, Slovenian, Estonian, Latvian and Lithuanian (Reader also includes Catalan and Basque)

Adobe Reader 9.3 MUI (Windows)

* English, French, German, Japanese, Spanish, Italian, Dutch, Brazilian Portuguese, Swedish, Danish, Finnish, Norwegian, Chinese Simplified, Chinese Traditional, Korean

Adobe Reader 9.3 (Linux and Solaris)

* English, French, German, Japanese

Adobe Reader 9.3 (Macintosh), Adobe Acrobat 9.3 Professional (Macintosh)

* English, French, German, Japanese, Spanish, Italian, Dutch, Brazilian Portuguese, Swedish, Danish, Finnish, Norwegian, Chinese Simplified, Chinese Traditional, Korean, Czech, Hungarian, Polish, Romanian, Ukrainian, Russian and Turkish

Adobe Acrobat 9.3 Pro Extended (Windows)

* English, French, German, Japanese, Brazilian Portuguese, Danish, Dutch, Finnish, Italian, Norwegian, Spanish, and Swedish

SECURITY COMPONENTS

The features below are described on Application Security Library - Security and Information Assurance - Adobe Learning Resources.
Enhanced Security

This release will ship with enhanced security on by default. Adobe recommends as a best practice that you keep enhanced security enabled. Enhanced security provides two tools designed to help you protect your environment: a set of default restrictions and a method to define trusted locations that should not be subject to those restrictions. In other words, you can either block dangerous actions altogether or else selectively permit them for locations and files you trust. For more information, please click here.
Privileged Locations Improvements

Windows users can automatically trust sites that they trust for Internet Explorer by checking Automatically trust sites from my Win OS security zones. In effect, those sites become privileged locations and are exempt from enhanced security restrictions.
Cross Domain Support

Cross domain logging can be enabled via the user interface.

The cross domain log can be opened, copied, and cleared via the user interface.

Cross domain policy files support all the mime types specified in the Cross Domain Policy File Specification.
Warning Message and Dialog Improvements

A non-intrusive Yellow Message Bar (YMB) that doesn’t block workflows replaces many of the modal dialogs.

Yelow Message Bar appears when content attempts to invoke potentially risky behavior such as cross domain access, JavaScript execution, data injection, and playing legacy multimedia types (non-Flash). If the associated feature is not locked down by an administrator, the Yellow Message Bar provides an Options button that offers the user to trust the document “once” or “always” for that feature. For more information, please click here.
Multimedia Security

Legacy multimedia support is disabled by default. For media types other than Flash, support must be manually enabled by assigning trust to the file containing the multimedia.


RESOLVED ISSUES
PDF Maker

2478552: Fixed an issue where PDFMaker was loading in Office 2010 with 9.x version of Acrobat.
Viewer

2485091, 2482589: Fixed a 9.2 Snow Leopard out of memory and crash issue where the progress bar causes extreme performance problems when the progress bar of Acrobat gets refreshed a large number of times during an operation.

2445056: Fixed a 9.2 issue where closing PDF causing a Firefox crash when multiple profiles have been started. When there are multiple instances of Firefox.exe running with the profile option of –no-remote and user tries to close the instance that has a PDF document opened, the user gets “Memory could not be read” error.

2481139: Fixed a 9.2 issue where Reader loaded forms in the background but didn’t show the busy cursor.
Web Capture

2465504: Fixed a 9.2 issue where Web Capture sets check box values as checked by default. HTML tag for Checkbox "value" and State were not getting honored.
Collaboration

2465483: Fixed a 9.2 issue where a reviewer’s xml gets overwritten and comments are lost after a user exits and opens the PDF again in shared review, the previous comments were deleted.
Accessibility

2464216: Fixed an Adobe Reader 9.2 issue where it did not trigger the speech synthesizer while clicking on any text fields of the customer PDF form (Jaws 11).
XPS conversion

2458933: Fixed a 9.1.3 issue where converting XPS file with the XPS2PDF Conversion plug-in yielded an incorrect page layout and missing items in the resulting PDF file.
Security

2451794: Fixed a 9.1.3 issue where Acrobat did not display the Save As dialog when the user signs the PDF using digital signature; cannot sign using the Microsoft Base CSP.

2425955: Fixed a 9.1.2 issues where an error encountered while signing: “The Windows Cryptographic Service Provider reported an error. Error code 2148073504” after a number of digital signal signatures have been produced successfully.
3D

2460633: Fixed a 9.2 issue where importAnXFDF does not import 3D views properly when the XFDF contains views associated with a 3D annotation.
Annotations

2451592: Fixed a 9.1.3 issue where no comments can be viewed after saving a document with corrupt annotations. When user does a Save As operation on a PDF with corrupted annotations and then opens other documents in the same Acrobat session, then any annotations on these documents fail to display.
Printing

2402932: Fixed a 9.1.1 issue where files with large paper sizes are printed blank with the 7500 Xerox driver when "choose paper source as PDF size" and "use custom size when needed" are both on.

2300251: Fixed a 9.1.1 issue where the output is clipped and printed with wrong orientation when printed using "Use custom paper size when needed" and "Choose Paper Source by PDF page size" as ON.
Forms

2371660: Fixed a 9.2 issue where when the user invokes web services from within a PDF that are protected using WS Security, the SOAP header in the SOAP request that sent from the server to the PDF doesn't conform to the WSSE specification. Recommended action: No action is required in most cases. If server code was written that checked for the incorrect headers, that code may need to be revisited.

2445047: Fixed an issue in 9.2 where submitForm causes xml data to be attached as *.tmp when parameter oXML is used and cSubmitAs is set to 'XML'. Customizing the XML data using oXML parameter and then calling submitForm to email the data caused the data to be attached with .tmp attachment rather than .xml attachment. Recommended action: If a server process is receiving and parsing the attachments, look for either a ".tmp" or a ".xml" extension.
 
Oben