PDF files are often used for exchanging documents between corporations and individuals, and are also being used for publishing documents on the web, as most web browsers are able to read PDF documents (after installing plug-ins).
Critical vulnerabilities have been identified in Adobe Reader 9.3.1 and earlier versions, and Adobe Acrobat 9.3.1 and earlier versions.
Critical is Adobe's highest vulnerability rating and could when exploited allow malicious native-code to execute, potentially without a user being aware.
Patches for these vulnerabilities are available. More information is available in Adobe's security bulletin 10-09.
The vulnerability in the PDF specification, discussed in Norman's software advisory 7 April, is not addressed in these patches.
Users of Adobe Acrobat and Reader can utilize the products' automatic update feature or download the relevant updates from links in Adobe's security bulletin.
Norman recommends that users update their Adobe Acrobat/Reader installations as soon as possible.