Unpatched Adobe PDF bug results in large-scale attacks
by Don Fosen on Jan.08, 2010, under Security Updates
Adobe has acknowledged a bug in their Reader and Acrobat software that is being used to conduct large-scale attacks against users. The bug was acknowledged on December 14th but Adobe decided not to fix it until January 12th at the earliest. Please be very careful about opening PDF files from unknown sources until this is resolved. I highly recommend that you disable Javascript in Reader, click here for detailed instructions on how to do this. If you running Adobe Reader 9 you should get the update automatically when it is released, if you are not running version 9 you should install it. You can also consider alternative PDF Reader software, Foxit Reader has been well reviewed. Download it here.
Additional Information:
New Adobe Reader and Acrobat Vulnerability
Large-scale attacks exploit unpatched PDF bug
Adobe probes new in-the-wild PDF bug