Author Topic: Security Advisory & Mitigations: Adobe Flash Player, Adobe Reader & Acrobat  (Read 1112 times)

0 Members and 1 Guest are viewing this topic.

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11540
  • "Stronger than the past, united in our goal."
    • Security Garden
Security Advisory CVE-2010-1297 has been posted due to a critical vulnerability in Adobe Flash Player 10.0.45.2 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems. The advisory includes the authplay.dll component that ships with Adobe Reader and Acrobat 9.x for Windows, Macintosh and UNIX operating systems.

This vulnerability could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against both Adobe Flash Player, and Adobe Reader and Acrobat.

Adobe's Product Security Incident Response Team (PSIRT) has confirmed that the 8.x versions of Adobe Reader and Acrobat are not vulnerable in this instance. However, there are other vulnerabilities affecting the 8.x versions. The PSIRT also reports that the Flash Player 10.1 Release Candidate does not appear to be vulnerable.

Release date: June 4, 2010
Vulnerability identifier: APSA10-01
CVE number: CVE-2010-1297

PSIRT: Security Advisory for Flash Player, Adobe Reader and Acrobat
Adobe Security Advisories:  Security Advisory for Flash Player, Adobe Reader and Acrobat

Mitigations:

Reports are that exploitation of the critical vulnerability in Adobe Flash player is growing rapidly. This vulnerability can also be vectored through malicious PDF files to invoke Flash.  See Adobe Flash/Reader Vulnerability Mitigation Options.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11540
  • "Stronger than the past, united in our goal."
    • Security Garden
The Flash Player update is available.  Direct download:  http://fpdownload.adobe.com/get/flashplayer/current/install_flash_player_ax.exe

After install, verify Flash Player version for each browser installed at About Flash Player page.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11540
  • "Stronger than the past, united in our goal."
    • Security Garden
So much for the recent Adobe Reader update. Even with all the vulnerabilities addressed in the update, it wasn't completely successful, apparently due to a feature Adobe was not willing to alter. See the complete explanation atAdobe PDF Reader "Launch" vulnerability still exploitable
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline faith_michele

  • Visiting Experts
  • Newbie
  • *****
  • Posts: 2
Thanks for the update.   :thumbsup:

Offline Eric the Red

  • ISO/IEC 27001:2005
  • Administrator
  • Hero Member
  • *****
  • Posts: 1611
  • Would somebody please pass me a beer!
But, of course, the fact that the recent update did not address every issue is not a reason to ignore the update, th Blackhats will always try and target the older versions as shown on this comment from the Internet Storm Center.

In short, get the updates offered (but always be sure to make a System Restore Point before installing anything!).
"The time to start running is around about the "e" in "Hey, you!" "
Proud member Since 2004 

The information I provide is provided "AS IS" without warranty, and confers no rights.