Adobe solventa por fin la gravísima vulnerabilidad descubierta hace algún tiempo de en su Reader.
Vunerabilidad de Adobe y su actualizacion critica con su solucion ... Descubierta por Petko D. Petkov de GNUCitizen.org, la vulnerabilidad
podría permitir a un hacker malicioso hacerse con el sistema mediante
un PDF especialmente confeccionado.
Un parche de seguridad que deberán aplicar los usuarios de Windows Xp
que dispongan de Adobe Reader 8.1 y anteriores, Adobe Reader 7.0.9 y
anteriores Adobe Acrobat Professional, 3D y Standard 8.1 y anteriores,
Adobe Acrobat Professional, Standard, 3D y Elements 7.0.9.
Solución en Adobe.com
Adobe strongly recommends upgrading to
Adobe Reader 8.1.1 or Acrobat 8.1.1. The Adobe Reader 8.1.1 update
files can be manually downloaded and installed from:
http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows
The Acrobat 8.1.1 update files can be downloaded and installed from:
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows
Microsoft may also be providing an update to resolve this issue at a later date. Please refer to Microsoft Security Advisory 943521 for more information.
Adobe
will be providing an update to Adobe Reader 7.0.9 and Acrobat 7.0.9 at
a later date. For customers who can not upgrade to Adobe Reader 8.1.1
or Acrobat 8.1.1, administrators can disable the mailto: option in
Acrobat, Acrobat 3D and Adobe Reader by modifying the application
options in the Windows registry. Additionally, these changes can be
added to network deployments to Windows systems.
Disclaimer:
This procedure involves editing the registry. Adobe doesn't provide
support for editing the registry, which contains critical system and
application information. Make sure to back up the registry before
modifying it. For more information about the registry, refer to Windows
Help.
- Exit Adobe Reader or Acrobat.
- Open RegEdit. On Windows XP, go to Start > Run, type in regedit and click OK.
- Choose File > Export.
- Select Local Disk C for the Save in: location.
- Type backup for File Name.
- Choose All for the Export Range.
- Click Save.
- Navigate to the appropriate registry key:
Acrobat:
HKEY_LOCAL_MACHINESOFTWAREPoliciesAdobeAdobe Acrobat8.0FeatureLockDowncDefaultLaunchURLPerms
Reader:
HKEY_LOCAL_MACHINESOFTWAREPoliciesAdobeAcrobat Reader8.0FeatureLockDowncDefaultLaunchURLPerms - If tSchemePerms is set as follows:
version:1|shell:3|hcp:3|ms-help:3|ms-its:3|ms-
itss:3|its:3|mk:3|mhtml:3|help:3|disk:3|afp:3|disks:3|telnet:3|ssh:3|acrobat:2|mailto:2|file:2 - To Disable mailto (recommended)
Modify tSchemePerms by setting the mailto: value to 3:
version:1|shell:3|hcp:3|ms-help:3|ms-its:3|ms-
itss:3|its:3|mk:3|mhtml:3|help:3|disk:3|afp:3|disks:3|telnet:3|ssh:3|acrobat:2|mailto:3|file:2 - To set mailto to prompt
Modify tSchemePerms by removing the mailto: value:
version:1|shell:3|hcp:3|ms-help:3|ms-its:3|ms-
itss:3|its:3|mk:3|mhtml:3|help:3|disk:3|afp:3|disks:3|telnet:3|ssh:3|acrobat:2|file:2 - Close RegEdit.
- Restart the application.