Secunia CSI7
Advisories
Research
Forums
Create Profile
Our Commitment
PSI
PSI API
CSI
OSI
xSI
Vulnerabilities
Programs
Open Discussions
My Threads
Create Thread
Statistics
About

Forum Thread: Acrobat Pro 9.3.0 > 9.3.1 update not detected

You are currently viewing a forum thread in the Secunia Community Forum. Please note that opinions expressed here are not of Secunia but solely reflect those of the user who wrote it.

This thread was submitted in the following forum:
Programs

Relating to this vendor:
Adobe Systems
And, this specific program:
Adobe Acrobat 9.x

This thread has been marked as locked.
ExWhyZee Acrobat Pro 9.3.0 > 9.3.1 update not detected
Member 18th Feb, 2010 18:07
Ranking: 0
Posts: 1
User Since: 18th Feb, 2010
System Score: N/A
Location: US
I applied the update for Acrobat Pro (http://www.adobe.com/support/downloads/detail.jsp?...) moving the version from 9.3.0 to 9.3.1 but PSI still detects it as unpatched.

It seems that PSI checks the Acrobat.dll version number in [C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat] and the patch only seems to address AcroForm.api in [C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\plug_ins] and authplay.dll in [C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat] leaving the Acrobat.dll version unchanged between 9.3.0 and 9.3.1.

Anyone else experiencing this?

ddmarshall RE: Acrobat Pro 9.3.0 > 9.3.1 update not detected
Dedicated Contributor 18th Feb, 2010 18:47
Score: 1208
Posts: 959
User Since: 8th Nov 2008
System Score: 98%
Location: UK
I have read elsewhere that yesterday the Adobe download site was still offering 9.3 and to get 9.3.1 you have to run Adobe Reader and click Help > Check for updates.

--
This answer is provided “as-is.” You bear the risk of using it.
Was this reply relevant?
+0
-0
mfhiowa RE: Acrobat Pro 9.3.0 > 9.3.1 update not detected
Member 18th Feb, 2010 19:25
Score: 0
Posts: 3
User Since: 18th Feb 2010
System Score: N/A
Location: US
Yup; same thing. Even with a reinstallation, which did not balk at the fact that I had already installed the patch.

--
"The wireless telegraph is not difficult to understand. The ordinary telegraph is like a very long cat. You pull the tail in New York, and it meows in Los Angeles. The wireless is the same, only without the cat." ~ Albert Einstein
Was this reply relevant?
+0
-0
jeangeorges1 RE: Acrobat Pro 9.3.0 > 9.3.1 update not detected
Member 18th Feb, 2010 19:27
Score: 0
Posts: 7
User Since: 15th Feb 2010
System Score: N/A
Location: LB
Hi ExWhyZee.
This morning i tried to update adobe from inside reader/Help/Update
but it wasn't avail. I downloaded the update by running the download solution suggested by PSI and it went well . Try this and rerun a PSI scan to see if it's OK.
Good luck.


--
John
HP Pavilion DV6 Win 7 64bit IE8
Bitdefender 2010 + Malwarebites
Was this reply relevant?
+0
-0
mfhiowa RE: Acrobat Pro 9.3.0 > 9.3.1 update not detected
Member 18th Feb, 2010 19:45
Score: 0
Posts: 3
User Since: 18th Feb 2010
System Score: N/A
Location: US
Unfortunately, it didn't make a difference for me. I tried going through updates in the program, downloaded it directly from Adobe and installed it & then did another scan with PSI. It was still detected as unpatched, so I clicked on the link within PSI to fix it and downloaded it & installed it that way, but PSI still detects it as being unpatched, even after rebooting & scanning once again.

--
"The wireless telegraph is not difficult to understand. The ordinary telegraph is like a very long cat. You pull the tail in New York, and it meows in Los Angeles. The wireless is the same, only without the cat." ~ Albert Einstein
Was this reply relevant?
+0
-0
jeangeorges1 RE: Acrobat Pro 9.3.0 > 9.3.1 update not detected
Member 18th Feb, 2010 20:26
Score: 0
Posts: 7
User Since: 15th Feb 2010
System Score: N/A
Location: LB
@ MFHIOWA
Use PSI in Advanced mode & click the + sign to see where the vulnerability is and then you can try to fix it and post to here again your findings.
best wishes.

--
John
HP Pavilion DV6 Win 7 64bit IE8
Bitdefender 2010 + Malwarebites
Was this reply relevant?
+0
-0
cbeima RE: Acrobat Pro 9.3.0 > 9.3.1 update not detected
Member 18th Feb, 2010 20:43
Score: -2
Posts: 5
User Since: 29th Jan 2010
System Score: N/A
Location: US
Same problem. After update, Acrobat.dll is still 9.3.0.148.
Was this reply relevant?
+0
-0
Anthony Wells RE: Acrobat Pro 9.3.0 > 9.3.1 update not detected
Expert Contributor 18th Feb, 2010 21:13
Score: 2437
Posts: 3,323
User Since: 19th Dec 2007
System Score: N/A
Location: N/A
Last edited on 18th Feb, 2010 21:21
Two points , Secunia do not necessarily use the files you think they do for their deection rules :eg: my correctly updated Reader 9.3.1.0 stll has the AcroRd32.dll and .exe files unchanged as version 9.3.0.148 . In the past they have used the Annots.api file in the plug_ins folder , this is unchanged this time round.

PSI show the "installation path" as the AcroRd32.exe file ; this is not the file in their detection rules , it just takes you to the Adobe folder .

Secunia have problems selecting files due tu Adobe's update system. On the last few updates they have got Reader "right" fairly quickly after earlier nightmares .

Acrobat (Pro) has usually taken quite a bit longer and needed email contact with support@secunia.com ; if nothing is resolved by Monday , you might think of advising them of the problem.

On occassion , the "repair adobe installation" in the programme's "help" tab dropdown menu has worked ;
If "about" is showing 9.3.1.0. then you would "appear" to be updated .

Hope this helps.

Anthony

--


It always seems impossible until its done.
Nelson Mandela
Was this reply relevant?
+0
-0
cbeima RE: Acrobat Pro 9.3.0 > 9.3.1 update not detected
Member 18th Feb, 2010 22:32
Score: -2
Posts: 5
User Since: 29th Jan 2010
System Score: N/A
Location: US
I believe that everyone was stating Acrobat.dll because that is the file Secunia references.

Adobe Acrobat 9.x
This installation of Adobe Acrobat 9.x is insecure and potentially exposes your system to security threats!

Secunia strongly recommends that you update this program by installing the update that is provided by the vendor of this program.
Installation Path
C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat.dll Extra Information / Known Issues with Adobe Acrobat 9.x
This update can be applied to Adobe Acrobat version 9.1.3
Users with version 9.1.3 can upgrade to version 9.3.0 by downloading and installing the MSP file.
Users with version 9.1.2 should first upgrade to 9.1.3 before applying this update.
After downloading the MSP update file, double-click the file to begin the update process.Fix It!
1) Click the "Download Solution" button below.
2) Select, accept, and run the proposed update.
3) Follow the guidelines as provided by the vendor, after pressing run.

Congratulations! If everything went as planned this program should now be patched and removed from this page within minutes.

Alternatively, if you are not using this program, you might consider uninstalling it from your computer.
Was this reply relevant?
+0
-0
Stecyk RE: Acrobat Pro 9.3.0 > 9.3.1 update not detected
Member 19th Feb, 2010 01:14
Score: 0
Posts: 3
User Since: 17th Sep 2009
System Score: N/A
Location: CA
Like others, I hit the download button and upgraded. Still says unsecure and shows version as 9.3.0.148. Yet, on my Adobe Pro Extended, it say 9.3.1. So how is this problem solved?
Was this reply relevant?
+0
-0
This user no longer exists RE: Acrobat Pro 9.3.0 > 9.3.1 update not detected
Member 19th Feb, 2010 01:44
I'm having the same problem with Adobe Acrobat Standard 8.2.1 update not being detected by PSI. I've downloaded the update multiple times, rebooted and rescanned and still get the 1 program insecure notice. In this case, the file path from Secunia doesn't seem to help me. In the past you've helped with the Adobe Flash Player updates and clearing the insecure message with PSI so I'm hoping you can help me now.

I'm running Windows XP Professional, SP 3 and all my Microsoft patches are up to date.
Was this reply relevant?
+0
-0
This user no longer exists RE: Acrobat Pro 9.3.0 > 9.3.1 update not detected
Member 22nd Feb, 2010 15:57
Hi,

We have corrected our rules for Adobe Acrobat. This should now work. If not, please write us at support@secunia.com

hope this helps.
Was this reply relevant?
+0
-0
pg111 RE: Acrobat Pro 9.3.0 > 9.3.1 update not detected
Member 22nd Feb, 2010 16:12
Score: 2
Posts: 2
User Since: 22nd Feb 2010
System Score: N/A
Location: FR
Thanks. It works here.

Cheers.

P. Germain
Was this reply relevant?
+0
-0
mfhiowa RE: Acrobat Pro 9.3.0 > 9.3.1 update not detected
Member 22nd Feb, 2010 16:25
Score: 0
Posts: 3
User Since: 18th Feb 2010
System Score: N/A
Location: US
Working here, too. Thanks!

--
"The wireless telegraph is not difficult to understand. The ordinary telegraph is like a very long cat. You pull the tail in New York, and it meows in Los Angeles. The wireless is the same, only without the cat." ~ Albert Einstein
Was this reply relevant?
+0
-0
narrsecunia RE: Acrobat Pro 9.3.0 > 9.3.1 update not detected
Member 22nd Feb, 2010 22:31
Score: 0
Posts: 4
User Since: 14th Oct 2009
System Score: N/A
Location: N/A
Emil,

I think your rules are still wrong for Acrobat 8.

I have twice upgraded -- once using the Adobe Updater, which always works well, and then again using the stand-alone updater your Secunia tool refers to.

I indicate 8.2.1. But Secunia says my software is still unsafe.

Thanks for fixing this.

Regards

on 22nd Feb, 2010 15:57, wrote:
Hi,

We have corrected our rules for Adobe Acrobat. This should now work. If not, please write us at support@secunia.com

hope this helps.

Was this reply relevant?
+0
-0
Anthony Wells RE: Acrobat Pro 9.3.0 > 9.3.1 update not detected
Expert Contributor 22nd Feb, 2010 22:59
Score: 2437
Posts: 3,323
User Since: 19th Dec 2007
System Score: N/A
Location: N/A

@narrsecunia ,

You need to email your information to support@secunia.com (as requested inyour quote of Emil Petersen).

Anthony

--


It always seems impossible until its done.
Nelson Mandela
Was this reply relevant?
+0
-0
narrsecunia RE: Acrobat Pro 9.3.0 > 9.3.1 update not detected
Member 22nd Feb, 2010 23:53
Score: 0
Posts: 4
User Since: 14th Oct 2009
System Score: N/A
Location: N/A
Emil,

Another false positive from Secunia PSI.

Secunis is reporting that Adobe Flash CS3 Professional is vulnerable, on version 9.0.0.494.

Flash CS3 is the _development environment_ for Flash. It is called Flash.exe, and it is not a player. I have the latest version of this Adobe Flash CS3 environment, and that is indeed 9.0.0.494.

I had also already updated the debug and standard Players for this development environment, using the Adobe download for that, 11 Feb 2010.

The version number for those updated development players is 9.0.262.0, as it is supposed to be, upon checking them in the Players directory.

Perhaps Secunia is looking at the Flash.exe which is at the root level for Adobe Flash CS3 Professional, and comparing the …0.494 number for the development environment with the proper …262.0 indicator for the development players?|

In any case, this looks strongly to be a second false positive.

on 22nd Feb, 2010 15:57, wrote:
Hi,

We have corrected our rules for Adobe Acrobat. This should now work. If not, please write us at support@secunia.com

hope this helps.

Was this reply relevant?
+0
-0
Anthony Wells RE: Acrobat Pro 9.3.0 > 9.3.1 update not detected
Expert Contributor 23rd Feb, 2010 00:20
Score: 2437
Posts: 3,323
User Since: 19th Dec 2007
System Score: N/A
Location: N/A

Hello narrsecunia

This is a separate problem and has been raised already elsewhere , in this thread :-

http://secunia.com/community/forum/thread/show/350...

Anthony

--


It always seems impossible until its done.
Nelson Mandela
Was this reply relevant?
+0
-0

This thread has been marked as locked.


 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Reports
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2014 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability