openSUSE Security Update: acroread security update ______________________________________________________________________________ Announcement ID: openSUSE-SU-2010:0706-1 Rating: critical References: #638466 Cross-References: CVE-2010-2883 CVE-2010-2884 CVE-2010-2887 CVE-2010-2889 CVE-2010-2890 CVE-2010-3619 CVE-2010-3620 CVE-2010-3621 CVE-2010-3622 CVE-2010-3623 CVE-2010-3624 CVE-2010-3625 CVE-2010-3626 CVE-2010-3627 CVE-2010-3628 CVE-2010-3629 CVE-2010-3630 CVE-2010-3631 CVE-2010-3632 CVE-2010-3656 CVE-2010-3657 CVE-2010-3658 Affected Products: openSUSE 11.3 openSUSE 11.2 openSUSE 11.1 ______________________________________________________________________________ An update that fixes 22 vulnerabilities is now available. It includes one version update. Description: Specially crafted PDF documents could crash acroread or lead to execution of arbitrary code (CVE-2010-2883, CVE-2010-2884, CVE-2010-2887, CVE-2010-2889, CVE-2010-2890, CVE-2010-3619, CVE-2010-3620, CVE-2010-3621, CVE-2010-3622, CVE-2010-3623, CVE-2010-3624, CVE-2010-3625, CVE-2010-3626, CVE-2010-3627, CVE-2010-3628, CVE-2010-3629, CVE-2010-3630, CVE-2010-3631, CVE-2010-3632, CVE-2010-3656, CVE-2010-3657, CVE-2010-3658). Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 11.3: zypper in -t patch acroread-3275 - openSUSE 11.2: zypper in -t patch acroread-3275 - openSUSE 11.1: zypper in -t patch acroread-3275 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 11.3 (i586) [New Version: 9.4]: acroread-9.4-0.1.1 - openSUSE 11.2 (noarch) [New Version: 9.4]: acroread-cmaps-9.4-0.1.1 acroread-fonts-ja-9.4-0.1.1 acroread-fonts-ko-9.4-0.1.1 acroread-fonts-zh_CN-9.4-0.1.1 acroread-fonts-zh_TW-9.4-0.1.1 - openSUSE 11.2 (i586) [New Version: 9.4]: acroread-9.4-0.1.1 - openSUSE 11.1 (noarch) [New Version: 9.4]: acroread-cmaps-9.4-0.1.1 acroread-fonts-ja-9.4-0.1.1 acroread-fonts-ko-9.4-0.1.1 acroread-fonts-zh_CN-9.4-0.1.1 acroread-fonts-zh_TW-9.4-0.1.1 - openSUSE 11.1 (i586) [New Version: 9.4]: acroread-9.4-0.1.1 References: http://support.novell.com/security/cve/CVE-2010-2883.html http://support.novell.com/security/cve/CVE-2010-2884.html http://support.novell.com/security/cve/CVE-2010-2887.html http://support.novell.com/security/cve/CVE-2010-2889.html http://support.novell.com/security/cve/CVE-2010-2890.html http://support.novell.com/security/cve/CVE-2010-3619.html http://support.novell.com/security/cve/CVE-2010-3620.html http://support.novell.com/security/cve/CVE-2010-3621.html http://support.novell.com/security/cve/CVE-2010-3622.html http://support.novell.com/security/cve/CVE-2010-3623.html http://support.novell.com/security/cve/CVE-2010-3624.html http://support.novell.com/security/cve/CVE-2010-3625.html http://support.novell.com/security/cve/CVE-2010-3626.html http://support.novell.com/security/cve/CVE-2010-3627.html http://support.novell.com/security/cve/CVE-2010-3628.html http://support.novell.com/security/cve/CVE-2010-3629.html http://support.novell.com/security/cve/CVE-2010-3630.html http://support.novell.com/security/cve/CVE-2010-3631.html http://support.novell.com/security/cve/CVE-2010-3632.html http://support.novell.com/security/cve/CVE-2010-3656.html http://support.novell.com/security/cve/CVE-2010-3657.html http://support.novell.com/security/cve/CVE-2010-3658.html https://bugzilla.novell.com/638466