Results 1 to 10 of 10
  1. #1
    Moderator
    Overall activity: 73.0%

    Join Date
    Dec 2008
    Location
    Italy
    Posts
    6,895
    Liked
    1067 times
    Points
    71,755

    Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat [Update]

    Update:

    We are in the process of finalizing a fix for the issue and expect to provide an update for Flash Player 10.x for Windows, Macintosh, Linux and Solaris by November 4, 2010.




    Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat

    Release date: October 28, 2010

    Platform: All Platforms


    Summary

    A critical vulnerability exists in Adobe Flash Player 10.1.85.3 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems; Adobe Flash Player 10.1.95.2 and earlier versions for Android; and the authplay.dll component that ships with Adobe Reader 9.4 and earlier 9.x versions for Windows, Macintosh and UNIX operating systems, and Adobe Acrobat 9.4 and earlier 9.x versions for Windows and Macintosh operating systems.

    This vulnerability (CVE-2010-3654) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against Adobe Reader and Acrobat 9.x. Adobe is not currently aware of attacks targeting Adobe Flash Player.


    We are in the process of finalizing a fix for the issue and expect to provide an update for Flash Player 10.x for Windows, Macintosh, Linux, and Android by November 9, 2010. We expect to make available an update for Adobe Reader and Acrobat 9.4 and earlier 9.x versions during the week of November 15, 2010.


    Affected software versions

    * Adobe Flash Player 10.1.85.3 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems
    * Adobe Flash Player 10.1.95.2 and earlier for Android
    * Adobe Reader 9.4 and earlier 9.x versions for Windows, Macintosh and UNIX*
    * Adobe Acrobat 9.4 and earlier 9.x versions for Windows and Macintosh


    Mitigations

    Adobe Reader and Acrobat 9.x - Windows
    Deleting, renaming, or removing access to the authplay.dll file that ships with Adobe Reader and Acrobat 9.x mitigates the threat for those products, but users will experience a non-exploitable crash or error message when opening a PDF file that contains Flash (SWF) content.

    The authplay.dll that ships with Adobe Reader and Acrobat 9.x for Windows is typically located at C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll for Adobe Reader or C:\Program Files\Adobe\Acrobat 9.0\Acrobat\authplay.dll for Acrobat.

    Read more
    Last edited by leofelix; 11-04-2010 at 10:21 PM.
    Roger and out

  2. #2
    The Specialist *
    Overall activity: 76.0%

    Join Date
    May 2010
    Location
    KOLKATA
    Posts
    5,162
    Liked
    731 times
    Points
    47,580
    Thank you leo for the notification .
    I don't need to know everything, I just need to know where to find it, when I need it.

  3. #3
    Classic Auto Buff
    Overall activity: 2.0%

    Join Date
    Apr 2009
    Location
    United States
    Posts
    2,039
    Liked
    179 times
    Points
    377
    Thanks for the headsup Leo!
    There may be a bit of snow on the roof, but there is still a fire blazing in the hearth!

  4. #4
    Junior Techie
    Overall activity: 0%

    Join Date
    Mar 2009
    Posts
    118
    Liked
    4 times
    Points
    2,865
    Secunia also shows the Adobe Shockwave program to be insecure also, though this may be a different venerability

  5. #5
    Experienced User
    Overall activity: 0%

    Join Date
    May 2010
    Posts
    3,271
    Liked
    155 times
    Points
    6,541
    Thanks leofelix for Security Advisory notification
    Windows 7 SP1 Ultimate x86 + KIS 2011 (11.0.2.556 b.a.c.d) + Sandboxie Paid (3.54) + Deep Freeze Standard (7.20.020.3398)

  6. #6
    *nix Technical Support
    Overall activity: 35.0%

    Join Date
    Jan 2009
    Location
    /home/hellnoire
    Posts
    9,845
    Liked
    319 times
    Points
    26,077
    Quote Originally Posted by Anakey View Post
    Secunia also shows the Adobe Shockwave program to be insecure also, though this may be a different venerability
    Isn't Shockwave... long dead?
    pacman -Syyu life not found in sync db

  7. #7
    Junior Techie
    Overall activity: 0%

    Join Date
    Mar 2009
    Posts
    118
    Liked
    4 times
    Points
    2,865
    idk, you can still download it from adobe so there must be something out there that still uses it

  8. #8
    Moderator
    Overall activity: 73.0%

    Join Date
    Dec 2008
    Location
    Italy
    Posts
    6,895
    Liked
    1067 times
    Points
    71,755
    Quote Originally Posted by Anakey View Post
    Secunia also shows the Adobe Shockwave program to be insecure also, though this may be a different venerability
    Didn't they already fix it?

    http://forum.raymond.cc/security-bulletin/24357-adobe-shockwave-player-11-5-9-615-a.html

  9. #9
    Experienced User
    Overall activity: 0%

    Join Date
    Sep 2010
    Posts
    848
    Liked
    201 times
    Points
    21,839
    Acrobat does not exist on my computer. What needs to change only Reader. Apart from Flash, Shock and Air.

  10. #10
    Moderator
    Overall activity: 73.0%

    Join Date
    Dec 2008
    Location
    Italy
    Posts
    6,895
    Liked
    1067 times
    Points
    71,755
    Adobe security advisor has been updated


    Update:

    We are in the process of finalizing a fix for the issue and expect to provide an update for Flash Player 10.x for Windows, Macintosh, Linux and Solaris by November 4, 2010.

 

 

Similar Threads

  1. Replies: 4
    Last Post: 04-13-2011, 11:42 AM
  2. Replies: 6
    Last Post: 02-07-2011, 05:29 AM
  3. Replies: 3
    Last Post: 11-15-2010, 02:30 AM
  4. Security Advisory for Flash Player, Adobe Reader and Acrobat
    By leofelix in forum Security Bulletin
    Replies: 4
    Last Post: 06-08-2010, 08:04 PM
  5. Security Advisory for Adobe Reader and Acrobat
    By leofelix in forum Spyware/Viruses
    Replies: 6
    Last Post: 04-16-2010, 07:00 AM

Tags for this Thread

All times are GMT +8. The time now is 07:51 AM.