Hash: SHA1

             AUSCERT External Security Bulletin Redistribution

                    ESB-2008.0132 -- [Win][UNIX/Linux]
   Adobe Reader 8.1.2 update addresses a number security vulnerabilities
                              8 February 2008


        AusCERT Security Bulletin Summary

Product:              Adobe Reader 8.1.1 and prior
Publisher:            Adobe
Operating System:     Windows
                      UNIX variants (UNIX, Linux, OSX)
Impact:               Reduced Security
Access:               Remote/Unauthenticated

Original Bulletin:    http://www.adobe.com/go/kb403079

Comment: Adobe has not released the specific details about vulnerabilities in
         Adobe Reader prior to 8.1.2.

- --------------------------BEGIN INCLUDED TEXT--------------------

Adobe Reader 8.1.2 Release Notes


   The Adobe Reader 8.1.2 update addresses a number of customer workflow
   issues and security vulnerabilities while providing more stability.


   Windows 2000 Service Pack 4, Windows XP Service Pack 2, Windows 2003
   Server, Windows Vista and Macintosh 10.4.3


   Windows/Macintosh/Linux: English, French, German, Japanese,
   Portuguese/Brazilian, Chinese (Simplified), Chinese (Traditional),
   Danish, Dutch, Finnish, Italian, Korean, Norwegian, Spanish and
   Swedish Solaris: English, French, German and Japanese


   Windows: Intel Pentium III or equivalent processor, Microsoft Windows
   Vista, Windows XP Professional, Home Edition, or Tablet PC Edition
   with Service Pack 2, Microsoft Windows 2000 with Service Pack 4,
   Windows 2003 Server, 128MB of RAM (256MB recommended for complex forms
   or large documents), Microsoft Internet Explorer 6.0 or 7.0, Firefox
   1.5 or 2.0, Mozilla 1.7, AOL 9

   Macintosh: PowerPC G3, G4, G5 or Intel processor, Mac OS X 10.4.3 to
   10.4.9, 10.5.0 and 10.5.1, 128MB of RAM (256MB recommended for complex
   forms or large documents), 170MB of available hard-disk space, Safari

   Linux: 32-bit Intel Pentium processor or equivalent, LSB (Linux
   Standard Base) 3.1 compliant systems including Red Hat Linux WS 5,
   SUSE Linux Enterprise Desktop (SLED) 10 and Ubuntu 6.10, GNOME or KDE
   Desktop Environment, 512 MB of RAM (1 GB recommended), 125 MB of
   available hard disk space (additional 75 MB required for having all
   supported font packs), GTK+ (GIMP Toolkit) user interface library,
   version 2.6 or higher, Firefox 1.5 or higher; Mozilla 1.7.3 or higher

   Solaris: UltraSPARC or UltraSPARC IIIi processor, Solaris 9 or 10,
   GNOME or KDE Desktop Environment (GNOME only for Solaris 10), 512 MB
   of RAM (1 GB recommended), 175 MB of available hard disk space
   (additional 75 MB required for having all supported font packs), GNU C
   library (glibc) version 2.3 or higher, GTK+ (GIMP Toolkit) user
   interface library, version 2.6 or higher (On Solaris 10, works with
   GTK 2.4.9 also), Firefox 1.5 or higher; Mozilla 1.7.3 or higher,
   OpenGL library, OpenSSL 0.9.7, OpenLDAP, and CUPS libraries, libstdc++

Resolved Issues

     * 1556556 Recognition of blank space for accessibility
     * 1557564 Search functionality corrected for dynamic forms using
       direct rendering
     * 1563874 Corrected behavior for protected expandable fields in
       dynamic forms
     * 1570947 Corrected page flow when orientation changes (i.e.
       portrait to landscape)
     * 1570960 Re-calculate event in XFA forms improved
     * 1572817 Improved color output when converting to PDF/X via
       ?short-cut? button
     * 1573793 Improved behavior of Reader enabled forms usage rights
       1574838 Improved printing on HP-based printers
     * 1576437 Enhanced stability when opening dynamic forms
     * 1592861 Corrected behavior for ?read only? fields when using
       direct rendering
     * 1605375 Improved behavior when adding sub-forms
     * 1607532 Added PCL print improvements
     * 1611771 Improved temp file clean-up after printing
     * 1618289 Support for new Adobe Extensions per ISO 32000
     * 1619714 Improved behavior of Reader enabled rights within
       LiveCycle Workspace
     * 1623197 Improved behavior when posting data with Safari on the
       Macintosh and Firefox on Windows
     * 1623539 Corrected screen reader behavior for converted German tags
     * 1623797 Improved decimal field behavior for dynamic XFA using
       direct rendering
     * 1623829 Improved decimal field behavior for dynamic XFA using
       direct rendering
     * 1624413 Improved stability on dynamic forms
     * 1635763 Improved stability on certified dynamic forms
     * 1639564 Corrected truncation error on metadata
     * 1643223 Improved review tracker display of email IDs
     * 1645404 Improved behavior of 3D annotations
     * 1648534 Improved behavior of meshes in 3D
     * 1650281 Improved behavior of name spaces in metadata
     * 1624848 Enhanced capability to handle multiple browser windows
       with similar javascript calls

TechNote Details

   Last Update:    02-05-2008
   ID:             kb403079
   Permanent Link: http://www.adobe.com/go/kb403079

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:


If you believe that your computer system has been compromised or attacked in 
any way, we encourage you to let us know by completing the secure National IT 
Incident Reporting Form at:


Australian Computer Emergency Response Team
The University of Queensland
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.

Comment: http://www.auscert.org.au/render.html?it=1967