Hallo Jens
Im Moment wird nur ein Windows-Update angeboten. Hier noch etwas über die Änderungen:
-----------
This update provides improved security. It also addresses known issues associated with forms and viewing PDF files using a Weblink plug-in. For more information, read the security advisories.
XML External Entity vulnerability (Adobe Reader and Acrobat 7.0-7.0.1)
Advisory Name: XML External Entity vulnerability in Adobe Reader and Adobe Acrobat
Release Date: June 15th, 2005
Product: Adobe Reader 7.0 and 7.0.1, Adobe Acrobat 7.0 and 7.0.1
Platform: Macintosh and Windows
Vulnerability Identifier: CAN-2005-1306
Overview: A vulnerability within Adobe Reader and Adobe Acrobat has been identified. Under certain circumstances, using XML scripts it is possible to discover the existence of local files.
Adobe has solutions available that can rectify these issues. Please refer to the Recommendations section for further information.
Effect: If exploited it may be possible to discover the existence of local files on an end-user system.
Details: The vulnerability is within the Adobe Reader control. If an XML script is embedded in JavaScript, it is possible to discover the existence of local files. An attacker could then use the information gathered for malicious purposes.
However the impact is minimized due to the fact that the existence of local files can only be discovered if the complete filenames and paths are known in advance by the attacker.
Recommendations:
Perform one of the following tasks:
-- If you use Adobe Reader 7.x on Windows, download the update to Adobe Reader 7.0.2 from the Adobe website at
http://www.adobe.com/support/downloads/ .
-- If you use Adobe Acrobat 7.x on Windows, download the update to Adobe Acrobat 7.0.2 from the Adobe website at
http://www.adobe.com/support/downloads/ .
-- Adobe will release an update for Mac OS shortly. Until that update is available, disable any Acrobat JavaScript to protect your system from this vulnerability. To disable JavaScript in Acrobat, choose Adobe > Preferences >JavaScript and deselect Enable Acrobat JavaScript.
Caveats: None
Vulnerability Identifier Cross-Reference: CVE ID: CAN-2005-1306
Acknowledgment: Adobe would like to thank Sverre H. Huseby, thathost.com, for reporting the issue.
-----------
Update für den Mac soll noch kommen.
Gruss, Bernd D.
System: Windows 2000/SP4; QXP6.5; QXP6.5 ME; ID CS; Acrobat 7 Pro.
***---***---***---***---***
Helfen Sie mit, werden Sie Mitglied.
Info unter:
http://www.hilfdirselbst.ch/info/