-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2013.1378
         Important: Adobe Reader - notification of end of updates
                              3 October 2013

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           Adobe Reader
Publisher:         Red Hat
Operating System:  Red Hat Enterprise Linux Server 5
                   Red Hat Enterprise Linux WS/Desktop 5
                   Red Hat Enterprise Linux Server 6
                   Red Hat Enterprise Linux WS/Desktop 6
Impact/Access:     Reduced Security -- Unknown/Unspecified
Resolution:        Alternate Program

Original Bulletin: 
   https://rhn.redhat.com/errata/RHSA-2013-1402.html

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Important: Adobe Reader - notification of end of updates
Advisory ID:       RHSA-2013:1402-01
Product:           Red Hat Enterprise Linux Supplementary
Advisory URL:      https://rhn.redhat.com/errata/RHSA-2013-1402.html
Issue date:        2013-10-02
=====================================================================

1. Summary:

Updated acroread packages that disable the Adobe Reader web browser plug-in
are now available for Red Hat Enterprise Linux 5 and 6 Supplementary.

2. Relevant releases/architectures:

Red Hat Enterprise Linux Desktop Supplementary (v. 5) - i386, x86_64
Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64
Red Hat Enterprise Linux Server Supplementary (v. 5) - i386, x86_64
Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64
Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64

3. Description:

Adobe Reader allows users to view and print documents in Portable Document
Format (PDF). Adobe Reader 9 reached the end of its support cycle on June
26, 2013, and will not receive any more security updates. Future versions
of Adobe Acrobat Reader will not be available with Red Hat Enterprise
Linux.

The Adobe Reader packages in the Red Hat Network (RHN) channels will
continue to be available. Red Hat will continue to provide these packages
only as a courtesy to customers. Red Hat will not provide updates to the
Adobe Reader packages.

This update disables the Adobe Reader web browser plug-in, which is
available via the acroread-plugin package, to prevent the exploitation of
security issues without user interaction when a user visits a malicious web
page.

4. Solution:

Red Hat advises users to reconsider further use of Adobe Reader for Linux,
as it may contain known, unpatched security issues. Alternative PDF
rendering software, such as Evince and KPDF (part of the kdegraphics
package) in Red Hat Enterprise Linux 5, or Evince and Okular (part of the
kdegraphics package) in Red Hat Enterprise Linux 6, should be
considered. These packages will continue to receive security fixes.

Red Hat will no longer provide security updates to these packages and
recommends that customers not use this application on Red Hat Enterprise
Linux effective immediately.

5. Package List:

Red Hat Enterprise Linux Desktop Supplementary (v. 5):

i386:
acroread-9.5.5-2.el5_10.i386.rpm
acroread-plugin-9.5.5-2.el5_10.i386.rpm

x86_64:
acroread-9.5.5-2.el5_10.i386.rpm
acroread-plugin-9.5.5-2.el5_10.i386.rpm

Red Hat Enterprise Linux Server Supplementary (v. 5):

i386:
acroread-9.5.5-2.el5_10.i386.rpm
acroread-plugin-9.5.5-2.el5_10.i386.rpm

x86_64:
acroread-9.5.5-2.el5_10.i386.rpm
acroread-plugin-9.5.5-2.el5_10.i386.rpm

Red Hat Enterprise Linux Desktop Supplementary (v. 6):

i386:
acroread-9.5.5-1.el6_4.1.i686.rpm
acroread-plugin-9.5.5-1.el6_4.1.i686.rpm

x86_64:
acroread-9.5.5-1.el6_4.1.i686.rpm
acroread-plugin-9.5.5-1.el6_4.1.i686.rpm

Red Hat Enterprise Linux Server Supplementary (v. 6):

i386:
acroread-9.5.5-1.el6_4.1.i686.rpm
acroread-plugin-9.5.5-1.el6_4.1.i686.rpm

x86_64:
acroread-9.5.5-1.el6_4.1.i686.rpm
acroread-plugin-9.5.5-1.el6_4.1.i686.rpm

Red Hat Enterprise Linux Workstation Supplementary (v. 6):

i386:
acroread-9.5.5-1.el6_4.1.i686.rpm
acroread-plugin-9.5.5-1.el6_4.1.i686.rpm

x86_64:
acroread-9.5.5-1.el6_4.1.i686.rpm
acroread-plugin-9.5.5-1.el6_4.1.i686.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/#package

6. References:

https://access.redhat.com/security/updates/classification/#important
http://www.adobe.com/support/products/enterprise/eol/eol_matrix.html#863

7. Contact:

The Red Hat security contact is <secalert@redhat.com>.  More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2013 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (GNU/Linux)

iD8DBQFSTIjrXlSAg2UNWIIRAuZtAJ9VMLCdj4MfqwWhbIt6SduHlU1IDgCcC3SZ
4GXQj9NmluZQt4Veic4qq8Q=
=gGrk
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBUky+hhLndAQH1ShLAQIfng/+N/q4TXuk6HMxWGPbhI8bYlE7teRzBm9z
0gJNciZluTCi+bdwwK0nzj4Zlq9YI3KyTsAYKoFl4NnCiclcNE3IBfRLC94P0xdj
9m7UmgJDUAW7yP2WZJhD8Jko8HYO1j+xRlYPFlp2WMkeydO7nOQEI5+KVCb8CSbv
utaDGN8IfDHYRh9qqWMpeHyY+VboK8Riqu9xVeBH8azWc4E0sRaF8zL7OigLzQDN
cfCpumtm8w7ocoheqIjsn/tTcbIaZywfeHqKzv2jMTADUTto+0wn9HwDCpt2bXVq
YsZCnuBmQHPfdefCxzBWkT+/azd/XApf1bESfVZV5KqSyY+6FXvhTKpACQHVen6s
FZM4N1KJheBHjKhdTkU1D9wUhgjADGxW20y3GCF/oAvyBTGnCryUupJO9JLo0jlU
6xvltqx/dCQzx5+u/hjJS+vYde1JYDa/cSBo/ZyE6CNDH0DTjs/UM4lsFP7gdq2l
sY0d4P/N0KU6TCHRjQSYF4gP8FKZwTLMa3RrC3dPw6nLecPB3s1xtcAJQgkcQvCl
faW/DI4oen9sFuUETtbcYA5qJWSMQxD89fKJo7C8geQLeDgLMLgOVxfHruXNVimI
O4lqFK2Zau5nPT8kLryg+5gTxdogghBWZU5MBNJvl+oat3drMT7eQUCE0pCTBZX3
3u8IUcN6ZNE=
=xas3
-----END PGP SIGNATURE-----