dslreports logo
 
    All Forums Hot Topics Gallery
spc
Search similar:


uniqs
4103

chachazz
Premium Member
join:2003-12-14

2 recommendations

chachazz

Premium Member

Security Advisory:Adobe Flash Player/Reader/Acrobat

quote:
March 14, 2011 - Adobe PSIRT
Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat (APSA11-01)

A Security Advisory (APSA11-01) has been posted in regards to an issue in Adobe Flash Player (CVE-2011-0609). A critical vulnerability exists in Adobe Flash Player 10.2.152.33 and earlier versions (Adobe Flash Player 10.2.154.13 and earlier for Chrome users) for Windows, Macintosh, Linux and Solaris operating systems, Adobe Flash Player 101.106.16 and earlier versions for Android, and the authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.1) and earlier 10.x and 9.x versions for Windows and Macintosh operating systems. There are reports that this vulnerability is being exploited in the wild in targeted attacks via a Flash (.swf) file embedded in a Microsoft Excel (.xls) file delivered as an email attachment. At this time, Adobe is not aware of attacks targeting Adobe Reader and Acrobat.

We are in the process of finalizing a fix for the issue and expect to make available an update for Flash Player 10.x and earlier versions for Windows, Macintosh, Linux, Solaris and Android, and an update for Adobe Acrobat X (10.0.1) and earlier 10.x and 9.x versions for Windows and Macintosh, Adobe Reader X (10.0.1) for Macintosh, and Adobe Reader 9.4.2 and earlier 9.x versions during the week of March 21, 2011.

Because Adobe Reader X Protected Mode would prevent an exploit of this kind from executing, we are currently planning to address this issue in Adobe Reader X for Windows with the next quarterly security update for Adobe Reader, currently scheduled for June 14, 2011.

We will continue to provide updates on this issue via the Security Advisory section of the Adobe website as well as the Adobe PSIRT blog.

Blackbird
Built for Speed
Premium Member
join:2005-01-14
Fort Wayne, IN

Blackbird

Premium Member

Hmm. I wonder if the end objective somehow is for Adobe to perform daily vulnerability updates for its stable of programs like an AV updates its signature files and engines. /sarcasm

chachazz
Premium Member
join:2003-12-14

chachazz

Premium Member

Background on APSA11-01 Patch Schedule
March 14, 2011 - Brad Arkin, Senior Director, Product Security and Privacy
quote:
Let me provide some additional background on the decision not to update Adobe Reader X at this time. We evaluated a number of different options. In the end, we determined that the above patch schedule would allow us to provide the best balance of risk mitigation and admin/update costs for our customers. Here are some points we considered in developing this schedule:

• Reports that we’ve received thus far indicate the attack is targeted at a very small number of organizations and limited in scope. The current attack leverages a malicious Flash (.swf) file inside a Microsoft Excel (.xls) file. The .xls file is used to set up machine memory to take advantage of a crash triggered by the corrupted .swf file. The final step of the attack is to install persistent malware on the victim’s machine.

• We have not received reports or malicious samples of attacks leveraging this vulnerability via .pdf files. However, attackers have leveraged these type of Flash Player vulnerabilities in the past via .pdf files to attack the embedded authplay.dll component shipping with Adobe Reader and Acrobat v9. Out of a preponderance of caution we took the decision to ship out-of-cycle updates for Adobe Reader and Acrobat v9, and Acrobat X to mitigate the risk of attackers shifting the attack from an .xls container to a .pdf container.

• Adobe Reader X Protected Mode (aka “sandboxing”) is designed to prevent the type of exploit we are currently seeing in the .swf/.xls attack from executing. Even if an attacker made the transition to a .pdf container for the exploit, the sandbox would prevent the final step of malicious software installation on the victim’s machine.

• We considered providing an out-of-cycle update for Adobe Reader X as well, which would have delayed the current patch release schedule by about another week. However, given the mitigation provided by the Adobe Reader X sandbox and the absence of attacks via PDF, we determined that an out-of-cycle update would incur unnecessary churn and patch management overhead on our users not justified by the associated risk, in particular for customers with large managed environments.
.
Full article at Adobe ASSET
(Adobe Secure Software Engineering Team)
chachazz

chachazz

Premium Member

Security Advisory (APSA11-01)
Release date: March 14, 2011
Last updated: March 17, 2011

•March 17, 2011 - Added Mitigations section
•March 14, 2011 - Updated Chrome Flash Player version information (changed from 10.2.154.13 to 10.2.154.18)

»www.adobe.com/support/se ··· -01.html

siljaline
I'm lovin' that double wide
Premium Member
join:2002-10-12
Montreal, QC

siljaline to chachazz

Premium Member

to chachazz
A Technical Analysis on the CVE-2011-0609 Adobe Flash Player Vulnerability
doppler
join:2003-03-31
Blue Point, NY

1 recommendation

doppler to chachazz

Member

to chachazz

Another issue about adobe read X

O.K., I had version 8. Yea it's an older version. But today as I opened a PDF. A pop-up requested a to update to version X. Why not. So I when thur the motions. Using firefox browser the adobe DLM manager was installed into fox. But here is the rub... So was Mcafee security advisor. Without a single "Do you want it or NOT!!"

Adobe should know better than to install without permission anything. Saying yes to install the reader did not imply yes to mcafee. They are two seperate products form different companies. Or did I miss the fact Apple bought out Mcafee?

Look out this update comes with baggage. Yes I did uninstall Mcafee.
DrDemento
join:2005-07-25
Brick, NJ

1 recommendation

DrDemento

Member

Same thing here-i really resent when they piggyback some other installation. I also uninstalled McAfee immediately.
DrDemento

DrDemento to doppler

Member

to doppler
Deleted-accidental second post

siljaline
I'm lovin' that double wide
Premium Member
join:2002-10-12
Montreal, QC

2 recommendations

siljaline to chachazz

Premium Member

to chachazz

Re: Security Advisory:Adobe Flash Player/Reader/Acrobat

Adobe Flash Player 10.2.153.1 now available >
*Beware of third party offerings such as Google Toolbar*
»get.adobe.com/flashplaye ··· ersions/

NICK ADSL UK
MVM
join:2004-02-22
united kingd

1 recommendation

NICK ADSL UK to chachazz

MVM

to chachazz
Security updates available for Adobe Reader and Acrobat - March 21, 2011

A critical vulnerability has been identified in the authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.1) and earlier 10.x and 9.x versions for Windows and Macintosh operating systems. This vulnerability (CVE-2011-0609), as referenced in Security Advisory APSA11-01, could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being exploited in the wild in targeted attacks via a Flash (.swf) file embedded in a Microsoft Excel (.xls) file delivered as an email attachment. At this time, Adobe is not aware of attacks targeting Adobe Reader and Acrobat. Adobe Reader X Protected Mode mitigations would prevent an exploit of this kind from executing.

Adobe recommends users of Adobe Reader X (10.0.1) for Macintosh update to Adobe Reader X (10.0.2). For users of Adobe Reader 9.4.2 for Windows and Macintosh, Adobe has made available the update, Adobe Reader 9.4.3. Adobe recommends users of Adobe Acrobat X (10.0.1) for Windows and Macintosh update to Adobe Acrobat X (10.0.2). Adobe recommends users of Adobe Acrobat 9.4.2 for Windows and Macintosh update to Adobe Acrobat 9.4.3. Because Adobe Reader X Protected Mode would prevent an exploit of this kind from executing, we are planning to address this issue in Adobe Reader X for Windows with the next quarterly security update for Adobe Reader, currently scheduled for June 14, 2011.

(Note: Adobe Reader 9.x for UNIX, Adobe Reader for Android, and Adobe Reader and Acrobat 8.x are not affected by this issue.)

The next quarterly security updates for Adobe Reader and Acrobat are currently scheduled for June 14, 2011. Today's security updates are out-of-cycle updates.

»www.adobe.com/support/se ··· -06.html

chachazz
Premium Member
join:2003-12-14

1 recommendation

chachazz

Premium Member

APSB11-05 - Security update available for Adobe Flash Player

Version X (10.x ) :
APSA11-01 - Security advisory for Adobe Flash Player, Adobe Reader and Acrobat
Somersett
join:2004-12-04
Scotland

Somersett to chachazz

Member

to chachazz
I installed Adobe Flash Player 10.2.153.1 a few minutes ago. I then attempted to alter some settings using the Flash Player Settings Manager but was unsuccessful. If I click on any of the setting headings ( Global Privacy through to Peer Assisted ) the Settings Manager Panel remains blank and I am unable to adjust anything.

My system is Windows XP/Service Pack 2/Internet Explorer 9.
rdhw
join:2002-09-21
Cambridge UK

1 recommendation

rdhw

Member

said by Somersett:

My system is Windows XP/Service Pack 2/Internet Explorer 9.

Are you sure about that?
Somersett
join:2004-12-04
Scotland

Somersett

Member

Mistake on my part. System is Windows Vista/Service Pack 2 ( I have XP on an old Laptop.) Apologies.

I cannot figure out why the Flash Player Settings Manager is not allowing me to alter my settings after installing the update.

rcdailey
Dragoonfly
Premium Member
join:2005-03-29
Rialto, CA

1 recommendation

rcdailey to doppler

Premium Member

to doppler

Re: Another issue about adobe read X

There's always a check box on the download page which you can "uncheck" to avoid whatever product they are trying to bundle. However, once you start the download, it's too late to unbundle. Be careful and uncheck whatever you don't want _before_ you download.
art22gg
Premium Member
join:2005-02-16
Courtenay, BC

2 edits

art22gg to chachazz

Premium Member

to chachazz

Re: Security Advisory:Adobe Flash Player/Reader/Acrobat

Hi,
I,m noticing also that when I go to the flash player settings mgr.,that some of the settings are not sticking,,,,in particular,,,, the "notify me when an update is available"...by default it is set to 7 days,and WON,T allow me to untick it----not good...also on the Peer Assisted panel where the setting to "disableP2P uplink for all",won,t stick if you want to enable it...
Did a clean install of this new version and rebooted.Win Xp sp3.

Art

Problem Solved....Deleted Flash player folder,in Adobe, AND Flash player folder in Macromedia...went back to settings mgr.,,,now settings "stick"....new folders were created!
BlueJay
join:2007-11-06

BlueJay to Somersett

Member

to Somersett
Hi Somersett, I also have Vista SP2, IE 8.. It took a while for the manager to load for me, but I was able to go through all the settings..
ciao, bj
Crypto_Bug
join:2001-05-31
Torrington, CT

Crypto_Bug to chachazz

Member

to chachazz
Did Adobe take the page down that allows you to download the Flash Player without using the garbage Adobe DLM activex. It keeps crashing and I cant seem to find the page where you can download the full flash player add-in for IE.
Somersett
join:2004-12-04
Scotland

Somersett to BlueJay

Member

to BlueJay
Bluejay, I tried the Setting Headings one at a time and gave each of them several minutes to load but the Settings Manager Panel remained blank. I am using Internet Explorer 9.

antdude
Matrix Ant
Premium Member
join:2001-03-25
US

antdude to rcdailey

Premium Member

to rcdailey

Re: Another issue about adobe read X

said by rcdailey:

There's always a check box on the download page which you can "uncheck" to avoid whatever product they are trying to bundle. However, once you start the download, it's too late to unbundle. Be careful and uncheck whatever you don't want _before_ you download.

I fell for this too. It was on the top right corner when downloading through ActiveX through IE7 in Vista (SP1 and SP2). Uninstalling it was easy and quick though!

deke40
deke40
Premium Member
join:2003-01-23
Texas

deke40 to chachazz

Premium Member

to chachazz

Re: Security Advisory:Adobe Flash Player/Reader/Acrobat

Everything worked fine on my Vista IE8 system and downloaded the latest "Full Screen Patcher".

»forum.videohelp.com/thre ··· sh-Video

Dustyn
Premium Member
join:2003-02-26
Ontario, CAN
·Carry Telecom
·TekSavvy Cable
Asus GT-AX11000
Technicolor TC4400

2 edits

Dustyn to siljaline

Premium Member

to siljaline
Click for full size
Another Flash update... awesome that it's here but, damn.
Adobe...let's re-build Flash from scratch. Right now it's like swiss cheese!

Simple installer... no toolbars, no 3rd party crap, just the latest Flash below... Enjoy!

NON-DIRECT LINKS:
Internet Explorer: h_tp://fpdownload.adobe.com/get/flashplayer/current/install_flash_player_ax.exe
Opera/Chrome/Firefox/others: h_tp://fpdownload.adobe.com/get/flashplayer/current/install_flash_player.exe
Dustyn

Dustyn to Crypto_Bug

Premium Member

to Crypto_Bug
said by Crypto_Bug:

Did Adobe take the page down that allows you to download the Flash Player without using the garbage Adobe DLM activex. It keeps crashing and I cant seem to find the page where you can download the full flash player add-in for IE.

Check out my above posting.

siljaline
I'm lovin' that double wide
Premium Member
join:2002-10-12
Montreal, QC

1 edit

1 recommendation

siljaline to Dustyn

Premium Member

to Dustyn
Click for full size
That worked for me, Dustyn See Profile all done. Others have had issues
siljaline

siljaline to Crypto_Bug

Premium Member

to Crypto_Bug
No, Adobe still require download aka DLM, direct links are within this thread.
Adobe Download Manager FAQ
Libra
Premium Member
join:2003-08-06
USA

1 recommendation

Libra to Dustyn

Premium Member

to Dustyn
Simple installer... no toolbars, no 3rd party crap, just the latest Flash below...

Hi Dustyn,

Thank you so much for providing the non-direct links.

Sincerely, Libra
Mele20
Premium Member
join:2001-06-05
Hilo, HI

1 edit

Mele20 to chachazz

Premium Member

to chachazz
Why haven't I been offered the update? I've rebooted at least three times this evening.

It seems to me that updating is willy-nilly. It should have popped up on one of the reboots. I just have it on IE6 and use it only for speed tests that require it so I'll just wait for it to show up.

I guess it is like Opera. Release to internal update is MUCH later than general download release.

EDIT: I was offered the update on a reboot earlier this evening.
daveinpoway
Premium Member
join:2006-07-03
Poway, CA

daveinpoway

Premium Member

Why not get the update manually? Whenever I hear about an update to some program that I use, I always go to the website and manually download/install the new version.

Perhaps it is not really necessarily, but I always use the Flash Uninstaller program to remove the old version and I then install the new one. This way, I am sure that the old version is gone. Doing this only takes a few extra minutes, so there doesn't seem to be much downside.

DownTheShore
Pray for Ukraine
Premium Member
join:2003-12-02
Beautiful NJ

DownTheShore to chachazz

Premium Member

to chachazz
Just got a notice from my WinPatrol program that an Adobe Flash run-once wanted to run at the next startup.

Dustyn
Premium Member
join:2003-02-26
Ontario, CAN

Dustyn to Libra

Premium Member

to Libra
You're welcome!