March Patch Tuesday followed by PDF viewer patches

Posted by   Virus Bulletin on   Mar 12, 2009

Major kernel issue and PDF problems fixed, spreadsheet software remains vulnerable.

Microsoft released the March security bulletin this week, with the monthly Patch Tuesday updates rather lighter than usual. On the same day, Adobe released some important patches for its widely used PDF viewing software.

From Microsoft came a single 'critical' fix for the Windows kernel, covering a possible remote-access exploit, alongside two 'important' patches for problems in the SChannel systems and DNS and WINS server software. To the disappointment of many, a patch for some serious vulnerabilities in Excel was not forthcoming.

Meanwhile, Adobe issued patches for its Acrobat 9 and Reader 9 software, addressing some of the PDF exploitation problems which have become rife in recent months, and has promised further updates for other versions of its products in the next few weeks.

The official Microsoft bulletin is here, and the Adobe announcement here. Comment on the patches - and the lack of patches - is at ESET here, with a detailed breakdown at Symantec here.

F-Secure is continuing a campaign to persuade users to diversify to a wider range of PDF-viewing software, to reduce the threat surface. The company is giving equal billing to updates for the speedy Foxit reader on its blog here.

Posted on 12 March 2009 by Virus Bulletin

twitter.png
fb.png
linkedin.png
hackernews.png
reddit.png

 

Latest posts:

VB2020 TIPS presentations: cybercrime in the DACH region and ransomware in LATAM

As part of VB2020 localhost we were proud to co-host the Threat Intelligence Practitioners' Summmit (TIPS), put together by the Cyber Threat Alliance. In a series of blog posts we highlight some of the talks presented in the Summit and the important…

VB2020 TIPS presentation: Intelligence Sharing for Supply Chain Security

As part of VB2020 localhost we were proud to co-host the Threat Intelligence Practitioners' Summmit (TIPS), put together by the Cyber Threat Alliance. In a series of blog posts we highlight some of the talks presented in the Summit and the important…

VB2020 localhost is over, but the content is still available to view!

VB2020 localhost - VB's first foray into the world of virtual conferences - took place last week, but you can still watch all the presentations.

New additions complete the VB2020 localhost programme

The programme for VB2020 localhost - the first virtual, and entirely free to attend VB conference - is now complete, with new additions to both the live programme and the on-demand programme.

VB2020 localhost call for last minute papers: a unique opportunity

Why VB2020 localhost presents a unique opportunity for you to share your research with security experts around the globe.

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.