back to article WTF PDF: If at first you don't succeed, you may be Adobe re-patching its Acrobat, Reader patches

Adobe is taking a second crack at patching security bugs in its Acrobat and Reader PDF apps. The APSB19-13 release, out today, attempts to completely kill off vulnerability CVE-2019-7089, which a software update earlier this month tried to address but was found to have insufficiently covered the security hole. In other words, …

  1. arctic_haze

    Let's kill it finally

    Euthanasia is controversial in the case of humans but a necessity for this kind of software.

  2. mark l 2 Silver badge

    Flash - Nuke it from Orbit it's the only way to be sure.

    While your at it, drop a few bombs on the Adobe coders, as the less badly coded bloatware they release the better. I can't imagine that Photoshop is much better coded, it is just not as widely installed as Flash and Acrobat

    1. Anonymous Coward
      Anonymous Coward

      They bought themselves into...

      The flash mess.

      So at least there, it was more a wreck to begin with. They certainly did little to fix that. But Photoshop was cleaner and more streamlined, so harder to mess up more!

      1. Anonymous Coward
        Anonymous Coward

        Re: They bought themselves into...

        Photoshop was cleaner and more streamlined, so harder to mess up

        That's no defence. Given time, Adobe management will destroy it through bloat and the consequent errors of cheap coding.

        1. Anonymous Coward
          Anonymous Coward

          Re: They bought themselves into...

          I use photoshop. And your comment is too soon... too soon!!! :'(

    2. katrinab Silver badge

      Flash came from their acquisition of Macromedia, so maybe a different development team?

      1. Carpet Deal 'em

        I remember right, Flash didn't become a gaping security flaw full of security flaws until after Adobe took over - and given the track record with their other products, I'd say the relation's causal.

  3. Halfmad
    Trollface

    A second patch for the same vulnerability?

    Sheesh! I'm starting to think that security is an afterthought for Adobe..

    Troll icon for obv reasons..

  4. Velv
    Coat

    Deja view - well you want to be secure, don’t you?

  5. Gnosis_Carmot

    When asked about the decision....

    When asked about the decision, a Microsoft spokesperson told us: "We got caught and now we're going to trot out a BS response that doesn't answer why we were allowing it to run despite the clear setting that said it shouldn't."

  6. Anonymous Coward
    Anonymous Coward

    Why is it even being updated anymore?

    I don't understand how something as old, and relatively *simple* as PDF renderer (which is what.. some kind of dialect of postscript.. that thing that's been driving printers since the 1970's?) can still have critical bugs in it. Like.. wtf? How many decades? Hundreds of revisions? Does it take to build something that like.. just paginates text and draws vectors on it? Like.. please just kill the fucking thing if you can't figure it out by now. There's probably hundreds of other pdf renderers out there. Just kill it. DIE.

    1. Anonymous Coward
      Anonymous Coward

      Re: Why is it even being updated anymore?

      Why is it even being updated anymore?

      I would guess because lazy, stupid corporate customers continue to pay the licence fee, in the same way they stick with IE?

  7. elvisimprsntr

    I uninstalled everything from Adobe years ago and excommunicated M$ for my home 10+ years ago.

    Unfortunately, people will continue to use Flash well beyond the announced EOL in 2020. https://theblog.adobe.com/adobe-flash-update/

    The only real way to kill it off is if Adobe or the OS/browsers implement a master kill switch which is activated on a particular date.

  8. Anonymous Coward
    Anonymous Coward

    Since I avoid using Microsoft Browsers at all costs, and don't have a Faceache account, its not a problem. Windows 10 is just as full of M$ bloatware as anything else that preceded it - Groove? Cortana?, Edge all completely irrelevant, but irremovable. Like chewing gum on a pavement, except you can remove chewing gum if you freeze it off.

  9. Robert Helpmann??
    Childcatcher

    Better and better

    ...Microsoft quietly reduced that list to just two Facebook domains... a Microsoft spokesperson told us: "We are nearing the point where Flash is no longer part of the default experience in Microsoft Edge..."

    So at what point will they also block Facebook to further improve customer security?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like