Does APSB08-19 apply to Acrobat 7.1.0 Pro?

The bulletin says the vulnerability applies to:
Adobe Reader 8.1.2 and earlier versions
Adobe Acrobat Professional, 3D and Standard 8.1.2 and earlier versions
It does not specifically say Adobe Acrobat 7.x is not vulnerable.
Support can't answer the question for me.
Has anyone found a specific answer for this question and Acrobat 7.x?

From: <[email protected]><br /><br />| David,<br /><br />| Please do not post links not related to the topic at hand. Here it is considered spam<br />| or advertising, is against forum policy and is generally frowned upon.<br /><br />| Your understanding and cooperation is appreciated. Thanks!<br /><br />| Neil<br />| Forum Host<br /><br />Realize that I am using a news client accessing the NNTP server and I am bouncing all <br />over;  Usenet, Adobe server, Gmane, Microsoft, yada, yada...<br /><br />As forum host, how about answering Elaine_Lung's query about what versions of Acrobat are <br />vulnerable.  Is there even an Adobe group specific to handling Information Assurance <br />concerns ?<br /><br />I am seeing 100's of PDF exploits using the Collab.collectEmailInfo() function created by <br />a dozen or so "kits" such as El Fiesta.<br />Now I am also seeing exploits using util.printf()  Gotta love those highly obfuscated <br />shellcodes in the exploitation vector.<br />Do you realize the SHEAR NUMBER of people getting infected through these exploits ?<br /><br />How about the fact that Acrobat 9 LifeCycle Designer includes a very vulnerable version of <br />Sun Java when it could very well use the Sun Java installed into the OS ?  I called <br />Techical Support and left my OFFICIAL email address and I have an open Adobe Ticket <br />number.  Nobody has ever contacted me in regards to my open ticket.  My PC is using Sun <br />Java v6 update 10.  Acrobat 9 installs v5 update 11 !<br /><br />I could also bring up the inclusion of Adobe Air where "Exploitation of this vulnerability <br />may allow a remote attacker to execute JavaScript code with elevated privileges." <br />http://www.adobe.com/support/security/bulletins/apsb08-23.html<br />C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Air<br /><br />Which is also bundled in Adobe Reader v9 without the knowledge of those who download it <br />and the vulnerable version is STILL available on the FTP server ftp:// <br />ftp.adobe.com/pub/adobe/reader/win/9.x/9.0/enu/AdbeRdr90_en_US.exe<br /><br />And there's Adobe Flash...  It it has be updated for IA complaince so often my head spins.<br /><br />Those links that are considered "spam" are for all those people on the Internet who have <br />to remove malware created by malicious actors taking advantage of all those <br />vulnerabilities.<br /><br />I have manually removed my URLs from my signature.  I will see if it is possible to base <br />my posting signature upon what News Server I post to.<br /><br />-- <br />Dave

Similar Messages

  • This.print(pp) with interactive type silent or automatic does not work  after upgrade acrobat reader 9 to acrobat reader 11

    After an upgrade of acrobat reader 9 to acrobat reader 11 the automatic printing of a pdf. The pdf is opened, but the print does not happen. With acrobat reader 9 it works. But with acrobat reader 11 the printing does not happen.
    I discovered when you specify pp.constants.interactionLevel.full it works on acrobat reader 11. But when you specify pp.constants.interactionLevel.silent or pp.constants.interactionLevel.automatic it does not work on acrobat reader 11. But with the full option we have a dialog  print box
    we do not want.
    In our jsp we load a pdf document and create a message handler to detect the print events of a pdf document that is in an <object> tag.
    In the pdf document we add
    package be.post.lpo.util;
    import org.apache.commons.lang.StringEscapeUtils;
    import org.apache.commons.lang.StringUtils;
    public class AcrobatJavascriptUtil {  
        public String getPostMessageToHostContainer(String messageName, String messageBody){
            return "var aMessage=['"+messageName+ "', '"+ messageBody+"'];this.hostContainer.postMessage(aMessage);";
        public String getAutoPrintJavaScript(String interactiveType, String printerName,String duplexType) {    
            String interactiveTypeCommand = "";
            if (StringUtils.isNotBlank(interactiveType)){
                interactiveTypeCommand = "pp.interactive = " + interactiveType + ";";
            String duplexTypeCommand = "";
            if (StringUtils.isNotBlank(duplexType)){
                duplexTypeCommand = "pp.DuplexType = " + duplexType + ";";
            return "" + // //
                    "var pp = this.getPrintParams();" + // //
                    // Nointeraction at all dialog, progress, cancel) //
                    interactiveTypeCommand + //
                    // Always print to a printer (not to a file) //
                    "pp.printerName = \"" + StringEscapeUtils.escapeJavaScript(printerName) + "\";" + //
                    // Never print to a file. //
                    "pp.fileName = \"\";" + //
                    // Print images using 600 DPI. This option MUST be set or some barcodes cannot //
                    // be scanned anymore. //
                    "pp.bitmapDPI = 600;" + //
                    // Do not perform any page scaling //
                    "pp.pageHandling = pp.constants.handling.none;" + //
                    // Always print all pages //
                    "pp.pageSubset = pp.constants.subsets.all;" + //
                    // Do not autocenter //
                    "pp.flags |= pp.constants.flagValues.suppressCenter;" + //
                    // Do not autorotate //
                    "pp.flags |= pp.constants.flagValues.suppressRotate;" + //
                    // Disable setPageSize i.e. do not choose paper tray by PDF page size //
                    "pp.flags &= ~pp.constants.flagValues.setPageSize;" + //
                    // Emit the document contents. Document comments are not printed //
                    "pp.printContent = pp.constants.printContents.doc;" + //
                    // printing duplex mode to simplex, duplex long edge, or duplex short edge feed //
                    duplexTypeCommand +
                    // Print pages in the normal order. //
                    "pp.reversePages = false;" + //
                    // Do the actual printing //
                    "this.print(pp);";
    snippets for java code that adds
    package be.post.lpo.util;
    import org.apache.commons.lang.StringUtils;
    import com.lowagie.text.Document;
    import com.lowagie.text.DocumentException;
    import com.lowagie.text.pdf.PdfAction;
    import com.lowagie.text.pdf.PdfDestination;
    import com.lowagie.text.pdf.PdfImportedPage;
    import com.lowagie.text.pdf.PdfName;
    import com.lowagie.text.pdf.PdfReader;
    import com.lowagie.text.pdf.PdfWriter;
    import java.io.IOException;
    import java.io.InputStream;
    import java.io.OutputStream;
    import java.util.ArrayList;
    import java.util.Iterator;
    import java.util.List;
    public class PdfMergerUtil{
        private static final PdfName DID_PRINT = PdfName.DP;
        private static final PdfName WILL_PRINT = PdfName.WP;
        private List<PdfActionJavaScriptHolder> actionJavaScripts = new ArrayList<PdfActionJavaScriptHolder>();
        private class PdfActionJavaScriptHolder{
            private final PdfName actionType;
            private final String javaScript;
            public PdfActionJavaScriptHolder(PdfName actionType, String javaScript) {
                super();
                this.actionType = actionType;
                this.javaScript = javaScript;
            public PdfName getActionType(){
                return this.actionType;
            public String getJavaScript(){
                return this.javaScript;
        public void writePdfs(OutputStream outputStream, List<InputStream> documents, String documentLevelJavaScript) throws Exception {
            Document document = new Document();
            try {          
              // Create a writer for the outputstream
              PdfWriter writer = PdfWriter.getInstance(document, outputStream);
              document.open();      
              // Create Readers for the pdfs.
              Iterator<PdfReader> iteratorPDFReader = getPdfReaders(documents.iterator());
              writePdfReaders(document, writer, iteratorPDFReader);
              if (StringUtils.isNotBlank(documentLevelJavaScript)){
                  writer.addJavaScript(documentLevelJavaScript);
              addAdditionalActions(writer);
              outputStream.flush();      
            } catch (Exception e) {
                e.printStackTrace();
                throw e;
            } finally {
                if (document.isOpen()){
                    document.close();
                try {
                    if (outputStream != null){
                        outputStream.close();
                } catch (IOException ioe) {
                    ioe.printStackTrace();
                    throw ioe;
        public void addAdditionalDidPrintAction(String javaScript){
            actionJavaScripts.add(new PdfActionJavaScriptHolder(DID_PRINT, javaScript));   
        public void addAdditionalWillPrintAction(String javaScript){
            actionJavaScripts.add(new PdfActionJavaScriptHolder(WILL_PRINT, javaScript));   
        private void writePdfReaders(Document document, PdfWriter writer,
                Iterator<PdfReader> iteratorPDFReader) {
            int pageOfCurrentReaderPDF = 0;      
              // Loop through the PDF files and add to the output.
              while (iteratorPDFReader.hasNext()) {
                PdfReader pdfReader = iteratorPDFReader.next();
                // Create a new page in the target for each source page.
                while (pageOfCurrentReaderPDF < pdfReader.getNumberOfPages()) {
                  document.newPage();
                  pageOfCurrentReaderPDF++;          
                  PdfImportedPage page = writer.getImportedPage(pdfReader, pageOfCurrentReaderPDF);
                  writer.getDirectContent().addTemplate(page, 0, 0);          
                pageOfCurrentReaderPDF = 0;
        private void addAdditionalActions(PdfWriter writer) throws DocumentException{
            if (actionJavaScripts.size() != 0 ){
                PdfAction action = PdfAction.gotoLocalPage(1, new PdfDestination(PdfDestination.FIT), writer);
                writer.setOpenAction(action);
                for (PdfActionJavaScriptHolder pdfAction : actionJavaScripts ){
                    if (StringUtils.isNotBlank(pdfAction.getJavaScript())){
                        action = PdfAction.javaScript(pdfAction.getJavaScript(), writer);
                        writer.setAdditionalAction(pdfAction.getActionType(), action);
        private Iterator<PdfReader> getPdfReaders(Iterator<InputStream> iteratorPDFs) throws IOException {
            List<PdfReader> readers = new ArrayList<PdfReader>();
              while (iteratorPDFs.hasNext()) {
                InputStream pdf = iteratorPDFs.next();
                PdfReader pdfReader = new PdfReader(pdf);
                readers.add(pdfReader);        
            return readers.iterator();
    JSP code
    <script type="text/javascript" src="<bean:message key="scripts.js.internal.jquery" bundle="app"/>"></script>
        <script language="javascript">
        function goToDidPrintUrl(){
            var url = "<%=didPrintUrl%>";
            window.location.assign(url);
        function createMessageHandler() {
            var PDFObject = document.getElementById("myPdf");
            PDFObject.messageHandler = {
                onMessage: function(msg) {
                     if (msg[0] == "WILL_PRINT"){      
                        $("#printingTransitFeedBackMessage").text('<%=willPrintMessage%>');                   
                     if(msg[0] == "DID_PRINT"){
                        $("#printingTransitFeedBackMessage").text('<%=didPrintMessage%>');               
                        setTimeout('goToDidPrintUrl()',4000);
                onError: function(error, msg) {
                    alert(error.message);
        </script>
    </head>
    <body onLoad="createMessageHandler();">
    <div id="printingTransitFeedbackArea">
      <div class="info" id="printingTransitFeedBackMessage"><%=documentOpenMessage%></div>
    </div>
    <object id="myPdf" type="application/pdf" width="100%" height="100%"  data="<%=toBePrintedUrl%>">
    </object>
    </body>

    From the JS API Reference of the print method:
    Non-interactive printing can only be executed during batch, console, and menu
    events.
    Outside of batch, console, and menu events, the values of bUI and of interactive are ignored
    and a print dialog box will always be presented.

  • I purchased Adobe CS4.  I am now being asked for my serial number and when I put it in the program does not recognize it for Acrobat Pro 9 though it does for PhotoShop, Bridge and the rest of the suite.  What can I do?

    I purchased Adobe CS4.  I am now being asked for my serial number and when I put it in the program does not recognize it for Acrobat Pro 9 though it does for PhotoShop, Bridge and the rest of the suite.  What can I do?

    Contact support if you have serial number issues. Otherwise start by checking this stuff:
    Sign in, activation, or connection errors
    Mylenium

  • [svn] 3130: Fix SDK-16700: Applying a matrix to a GraphicElement does not get applied immediately.

    Revision: 3130
    Author: [email protected]
    Date: 2008-09-05 15:32:13 -0700 (Fri, 05 Sep 2008)
    Log Message:
    Fix SDK-16700: Applying a matrix to a GraphicElement does not get applied immediately.
    Added explicit matrixChanged and displayObjectChanged flags to GraphicElement so we can reliably track changes to those items. Changed commitXY() to set the x and y properties directly on the display object rather than indirectly through the matrix. Setting through the matrix caused any non-rotation or scale transform to be lost.
    Reviewer: Deepa
    Checkintests: pass
    Ticket Links:
    http://bugs.adobe.com/jira/browse/SDK-16700
    Modified Paths:
    flex/sdk/trunk/frameworks/projects/flex4/src/flex/graphics/graphicsClasses/GraphicElement .as

    :/ - I just said I can't post this on the business forum as I have tried, it it says my post doesn't conform to the rules, yet there isn't anywhere where it breaks them. I will already be in talks with a lawyer but I was wondering if a more amicable solution could be reached first

  • Does Captivate 4 contain Adobe Acrobat 8.1.0?

    Does Captivate 4 contact Adobe Acrobat 8.1.0 or do you need to purchase this software separately?
    Thank you.

    Captivate 4 is sold als a separate product, but you can also find it in the eLearning Suite, which contains also Acrobat 9 Pro (but also Flash CS4, Dreamweaver CS4, Photoshop CS4, Soundbooth CS4...etc). Acrobat Reader (version 9 for the moment) is indeed completely free. Why do you ask this question: thinking about integrating Captivate in pdf-documents?

  • I have a Macbook pro Retina display, I have a small nick in my screen that is annoying especially when watching videos. What is my best option for fixing it?/does apple care apply?

    I have a Macbook pro Retina display, I have a small nick in my screen that is annoying especially when watching videos. What is my best option for fixing it?/does apple care apply?

    Did you cause the nick? Or did it just appear one day? There are reports of the retina screen having exploding pixels which leaves a hole in the screen that can be felt when you rub your finger across it. If that is what happened then it should be covered under the warranty. If you caused the nick then it is not covered and the fix will be very expensive, somewhere in the $1000 range.
    astets wrote:
    I have a Macbook pro Retina display, I have a small nick in my screen that is annoying especially when watching videos. What is my best option for fixing it?/does apple care apply?

  • Does NVMe update in 10.10.3 apply to early 2015 Retina Macbook Pro?

    I was wondering if the NVMe update in 10.10.3 applies to early 2015 Retina Macbook Pros.  It says on my hardware report that there is no NVMe device installed.

    Probably not with the current SSD. Even though NVMe has been enabled in 10.10.3, I think you need an SSD that supports it, which the 2015 rMBP does not have at the moment (it's using a samsung AHCI controller, at least in the 128gb rMBP 13" 2015 - http://www.storagereview.com/apple_macbook_pro_samsung_ssd_review_march2015). Please correct me if I'm (hopefully!) wrong.
    P.S. The drive still shows up under SATA/SATA Express

  • HT4145 Does this article apply to OS X Lion and Airport Utility 6.0?  Reason: Airport Utility cannot find my Airport Extreme (4th generation) wirelessly on my Time Capsule configured network even although the firmware in both units is up to date.

    Does this article apply to OS X Lion and Airport Utility 6.0?
    Reason: Airport Utility cannot find my Airport Extreme (4th generation) wirelessly on my Time Capsule configured network even although the firmware in both units is up to date.

    I thought you were trying to Extend the network with an Express as the article mentions you pointed to...
    You can't find the Airport Extreme then...
    I woudl suggest doing a Factory reset....
    http://support.apple.com/kb/HT3728
    Then you should be able to set it up just as you did when it was new....
    Factory default reset (using reset button)
    If the AirPort Base Station or Time Capsule isn't accessible from AirPort Utility, the Factory Default reset can be accomplished by using the reset button.
    Unplug the AirPort Base Station or Time Capsule from power.
    Press and hold the reset button with a pen or pencil, then plug the AirPort Base Station or Time Capsule back in while continuing to hold the button until you see the light (LED) flash rapidly. This should happen after a few seconds.
    Release the button. This will factory default reset the AirPort Base Station or Time Capsule.

  • Does the Creative Cloud include Acrobat XI Pro?

    Does the Creative Cloud include Acrobat XI Pro?

    All the tools and services are listed here
    http://www.adobe.com/products/creativecloud/tools-and-services.html
    Acrobat XI Pro is listed at the top of the "Also included:" list in the sidebar on the right hand side.

  • Does the firewall apply also for the serial MGT?

    Hi!
    I would like to configue IPF. I��m using a v240 with an Hyperterminal cabled in the special SERIAL MGT port (RJ-45) of the server.
    My question is: does the firewall apply also for the serial MGT port?
    Because I��m not directly working on the server with keybord and monitor, I��m worried about not beeing abble to get to the server again in case that I make a mistake with the Firewall��s configuration!
    Is this SERIAL MGT port to be seen like a normal serial port or to be seen like a LAN port?
    Does the firewall��s configuration has to be loaded every time you boot (like in Linux)?
    Thanks for your help.
    XpucTo

    <table border="0" align="center" width="90%" cellpadding="3" cellspacing="1"><tr><td class="SmallText"><b>m-lennon wrote on Sat, 28 January 2006 06:46</b></td></tr><tr><td class="quote">
    These rules are normally initialized when the system is booted.
    </td></tr></table>
    Well I just found in the sun documentation the following explanations:
    "Solaris IP Filter uses the packet filtering rules that you put in to the ipf.conf file. If you locate the rules file for packet filtering in the /etc/ipf/ipf.conf file, this file is loaded when the system is booted. If you do not want the filtering rules to be loaded at boot time, put the in a file of your choice. You can then activate the rules with the ipf command."
    So I guess there would be the possibility to try the rules and to reboot in case the rules don��t allow any connection anymore.
    <table border="0" align="center" width="90%" cellpadding="3" cellspacing="1"><tr><td class="SmallText"><b>m-lennon wrote on Sat, 28 January 2006 06:46</b></td></tr><tr><td class="quote">
    On many commercial networks, network management interfaces are attached to a private network without a route to a public network, such as the Internet, this will completely eliminate the possibility of the system being compromised by an external host.
    </td></tr></table>
    But what does it mean for my concrete question?! Do I have to define a special rule for the serial MGT port? I would tend to think no because this port isn��t a network card and I would tend to think that It could be considere like a keyboard. But of course I��d like to be sure about it.
    XpucTo

  • Does 16 really applies to 4 zeros

    Please see this link http://help.sap.com/saphelp_nw04/helpdata/en/fc/eb3cf4358411d1829f0000e829fbfe/content.htm
    Q]      Does 16 really applies to 4 zeros(see output) , & Why should they be  multiple of 4 -
    Why ? Could you please explain  the things .

    For your first question: filling zeros....
    The position is defined in bytes, and the start of the file is equal to position 0. If pos contains the value -1, as of release 6.10 the file pointer is positioned at the end of the file. For all other negative values and prior to Release 6.10, the behavior is undefined.
    Please note the following special cases:
    If the file is opened for reading and the value of pos is greater than the length of the file, the file pointer is positioned outside the file. If the position is not changed, no data can be read. In a non- Unicode program, if a file is opened for reading and is then written to, the file is filled with hexadecimal 0 from the end of the file to the specified position, and the new content is written after that.
    If the file is opened for writing, the next time writing takes place, the file is filled with hexadecimal 0 from the start of the file to the specified position, and the new content is written after that.
    If the file is opened for appending, the position specification is ignored and the file pointer remains positioned at the end of the file.
    If the file is opened for changing, and the value of pos is greater than the length of the file, the next time the file is written in, it is filled with hexadecimal 0 from the end of the file to the specified position, and the new content is written after that.
    The addition POSITION cannot be specified if one of the additions FILTER or BYTE-ORDER MARK is specified at the same time.
    For your second question: Mulitple by 4.
    Yes ... it should be multiple by 4 only. Because it will be hexadecimal (4 bytes). And from the first answer you can remember postion should given in bytes...

  • HT1528 Does this also apply to 10.8 Mountain Lion?

    Does this also apply to 10.8 Mountain Lion?

    If you are trying to rename the Home folder it may be easier to  simply create a new user account with the name you want, make it an admin account. Log into the new account then delete the old one.
    Other things:
    Changing Your Short User Name (MacMost Now 670) - YouTube
    https://discussions.apple.com/docs/DOC-3872

  • How much does a multi-user Adobe Acrobat XI Pro cost?

    How much does a multi-user Adobe Acrobat XI Pro cost?

    It has already been said, but just to clarify the updates are what you would seem to call a minor update. The upgrades to a new major number (1>2>3>4>5>6>7>8>9>X>XI>??) are what you seem to call major updates. The upgrades are not free, but the updates are. Sorry for the numbering, I could not resist. I have been using Acrobat since version 2.

  • Does Forms Central come with Acrobat XI Pro for Educators or must it be purchased separately?

    I keep getting conflicting messages.
    Does Forms Central come with Acrobat XI Pro for Educators or must it be purchased separately?

    FormsCentral is an online subscription service.
    It is not a built-in feature of Acrobat XI.
    With that said Acrobat XI Pro does have a built-in "link" to FormsCentral and this provides an Acrobat centric user interface.
    The actual "real deal" is online (the "web" / "cloud" - whatever).
    For that you'd visit:
    https://www.acrobat.com/en_us/products/formscentral.html 
    About the subscription:
    "The FormsCentral 30 Day Opt-Out trial gives you the option to try the Basic plan features for USD $0.99.
    Simply add to cart and enter a credit card to set up your account.
    After you place your order you will have 30 days to use FormsCentral.
    At the end of the 30 day trial period your card will automatically be charged the standard monthly subscription rate of $14.99 so that you can continue to create, distribute, and manage your online forms and surveys.
    Subscriptions cancelled within the first 30 days will be refunded in full.
    To change or cancel your subscriptions, visit the My Subscriptions page on Adobe.com."
    Be well...

  • Does the guarantee apply to a broken screen?

    Last year I bought my iphone 5 and I purchased a guarantee for two years. In july my screen broke, does the guarantee apply to change my iphone?

    There is no guarentee.
    Apple offers a warranty which covers materials and workmanship.
    A broken screen is damage which is not covered.
    What you may have purchased is AppleCare+ which will replace a damaged iPhone for less then the out of warranty replacement but it is still not a guarantee.

Maybe you are looking for

  • How to export data from a Oracle table to a delimited file?

    I know how to load delimited file into a table, but how to export data from a Oracle table to a delimited file? Thanks in advance.

  • There's got to be a better way to do this (RAM preview frustration)

    I loaded a 1:20 second Full HD clip into after effects. I need to edit the video based on certain sounds in the video and see if I'm matching them up correctly by previewing it with sound. The problem is i'm getting frustrated due to After effects no

  • Can I have a SATA 600 SSD in my mac pro early 2011

    Hello, I have a Macbook Pro early 2011. And I am wondering if I can install a sata 600 SSD in my mac. I would like to place the SATA 600 SSD in my optical bay and keep my existing HDD in the normal bay. So, is this possible? Roy

  • Can't export AT ALL since 1,1,1

    Since 1,1,1 I can't export anything: I click on any option (email, version, master) and nothing happens!. Also I can't get the preference panel open nine times out of ten. Of course I TRASHED my pref, but nothing happens. So far I did not need Apertu

  • What is the "search folders" tab for and how to set it up?

    Since my scratch disk is on my external HD and my project files will be on my system drive I am wondering what location I should set the search tabs folders at. If anyone knows what this a tab does exactly I would like to know. I am under the impress