Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg

Adobe Flash Player and Reader with Critical Security Advisory

Jul 24, 2009

Adobe announced a critical vulnerability for its Flash Player 9.0.159.0 and 10.0.22.87 and earlier, along with the authplay.dll component in its Reader and Acrobat 9.x., that goes across platforms in Windows, Macintosh, Linux and Solaris.

System crashes and exploits are possible as a result. The CVE-2009-1862 vulnerability is already causing exploits in Adobe Reader, according to the Adobe security bulletin. The reports of these "limited, targeted attacks" are currently under Windows only.

Adobe is venturing to fix this problem for the Flash Player 9 and 10 release on July 30 for all platforms except Solaris, which should come a bit later. Reader and Adobe 9.1.2 should be addressed July 31 for Windows, Mac and UNIX.

A workaround in the meantime is to remove or rename authplay.dll in Reader and Acrobat, although a non-exploitable crash or error message could then occur when opening a PDF with Small Web Format (SWF) content, such as animated vector graphics. Adobe cautions about browsing untrusted websites (keeping antivirus definitions up to date) or even advises uninstalling the software.

(Ulrich Bantle)

Comments


Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg
Related Articles
Security Issue with FLAC Audio Codec
Thunderbird 2.0.0.12 Cures Vulnerabilities
JavaScript Security Bug in Opera
Vulnerabilities in OpenSSL
CUPS Print Server Vulnerabilities Removed
Vulnerability Discovered in Rsync
FREE Live Streaming Video from ApacheCon US 2009

Watch our free Video Archive from Apachecon US 2009. Archive provided by The Apache Foundation, COLLABNET, and Linux Pro Magazine

Drawing internationally renowned thought-leaders, contributors, and organizations in the Open Source community, ApacheCon offers insight into the culture and community that develops and shepherds industry-leading Open Source projects, including Apache HTTP Server – the world's most popular Web server software for more than 10 years.

Find out more

 

In the US and Canada, Linux Magazine is known as Linux Pro Magazine.
Entire contents © 2010 [Linux New Media USA, LLC]
Linux New Media web sites:
North America: [Linux Pro Magazine]
UK/Worldwide: [Linux Magazine]
Germany: [Linux-Magazin] [LinuxUser] [EasyLinux] [Linux-Community] [Linux Technical Review]
Eastern Europe: [Linux Magazine Poland] [Linux Community Poland]
International: [Linux Magazine Brazil] [EasyLinux Brazil] [Linux Magazine Spanish]
Corporate: [Linux New Media AG]