|
Adobe announced a critical vulnerability for its Flash Player 9.0.159.0 and 10.0.22.87 and earlier, along with the authplay.dll component in its Reader and Acrobat 9.x., that goes across platforms in Windows, Macintosh, Linux and Solaris.
System crashes and exploits are possible as a result. The CVE-2009-1862 vulnerability is already causing exploits in Adobe Reader, according to the Adobe security bulletin. The reports of these "limited, targeted attacks" are currently under Windows only.
Adobe is venturing to fix this problem for the Flash Player 9 and 10 release on July 30 for all platforms except Solaris, which should come a bit later. Reader and Adobe 9.1.2 should be addressed July 31 for Windows, Mac and UNIX.
A workaround in the meantime is to remove or rename authplay.dll in Reader and Acrobat, although a non-exploitable crash or error message could then occur when opening a PDF with Small Web Format (SWF) content, such as animated vector graphics. Adobe cautions about browsing untrusted websites (keeping antivirus definitions up to date) or even advises uninstalling the software.
|
| FREE Live Streaming Video from ApacheCon US 2009 |
|---|
Watch our free Video Archive from Apachecon US 2009. Archive provided by The Apache Foundation, COLLABNET, and Linux Pro MagazineDrawing internationally renowned thought-leaders, contributors, and organizations in the Open Source community, ApacheCon offers insight into the culture and community that develops and shepherds industry-leading Open Source projects, including Apache HTTP Server – the world's most popular Web server software for more than 10 years. |
Comments