Multiboxing.com - Multiboxing in World of Warcraft and more!
          

Go Back   Multiboxing in World of Warcraft and Beyond! > All Gaming Forums > General Discussions

Reply
 
LinkBack Thread Tools Display Modes
Old 06-08-2010, 06:53 AM   #1
Senior Member
 
Poyzon's Avatar
 
Join Date: Jul 2009
Posts: 1,295
Blog Entries: 38
Default Security Advisory for Flash Player, Adobe Reader and Acrobat

Source: Adobe - Security Advisories: Security Advisory for Flash Player, Adobe Reader and Acrobat

Adobe Downloads Page: Adobe Labs - Downloads: Flash Player 10 Prereleases

WoW Forums post: World of Warcraft - English (NA) Forums -> We're vulnerable, too!!!

Quote:
Originally Posted by Adobe
Release date: June 4, 2010

Last updated: June 7, 2010

Vulnerability identifier: APSA10-01

CVE number: CVE-2010-1297

Platform: All

SUMMARY

A critical vulnerability exists in Adobe Flash Player 10.0.45.2 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems, and the authplay.dll component that ships with Adobe Reader and Acrobat 9.x for Windows, Macintosh and UNIX operating systems. This vulnerability (CVE-2010-1297) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against both Adobe Flash Player, and Adobe Reader and Acrobat.

We are in the process of finalizing a fix for the issue, and expect to provide an update for Flash Player 10.x for Windows, Macintosh, and Linux by June 10, 2010. The patch date for Flash Player 10.x for Solaris is still to be determined. We expect to provide an update for Adobe Reader and Acrobat 9.3.2 for Windows, Macintosh and UNIX by June 29, 2010.

AFFECTED SOFTWARE VERSIONS

Adobe Flash Player 10.0.45.2, 9.0.262, and earlier 10.0.x and 9.0.x versions for Windows, Macintosh, Linux and Solaris
Adobe Reader and Acrobat 9.3.2 and earlier 9.x versions for Windows, Macintosh and UNIX

Note:
The Flash Player 10.1 Release Candidate available at Adobe Labs - Adobe Flash Player 10.1 is confirmed not vulnerable.
Adobe Reader and Acrobat 8.x are confirmed not vulnerable.

MITIGATIONS

Adobe Flash Player
The Flash Player 10.1 Release Candidate available at Adobe Labs - Adobe Flash Player 10.1 is confirmed not vulnerable.

Adobe Reader and Acrobat - Windows
Deleting, renaming, or removing access to the authplay.dll file that ships with Adobe Reader 9.x and Acrobat 9.x mitigates the threat for those products, but users will experience a non-exploitable crash or error message when opening a PDF file that contains SWF content.

The authplay.dll that ships with Adobe Reader 9.x and Acrobat 9.x for Windows is typically located at C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll for Adobe Reader or C:\Program Files\Adobe\Acrobat 9.0\Acrobat\authplay.dll for Acrobat.

Adobe Reader 9.x - Macintosh

1) Go to the Applications->Adobe Reader 9 folder.
2) Right Click on Adobe Reader
3) Select Show Package Contents
4) Go to the Contents->Frameworks folder
5) Delete or move the AuthPlayLib.bundle file

Acrobat Pro 9.x - Macintosh

1) Go to the Applications->Adobe Acrobat 9 Pro folder.
2) Right Click on Adobe Acrobat Pro
3) Select Show Package Contents
4) Go to the Contents->Frameworks folder
5) Delete or move the AuthPlayLib.bundle file
Adobe Reader 9.x- UNIX
1) Go to installation location of Reader (typically a folder named Adobe)
2) Within it browse to Reader9/Reader/intellinux/lib/ (for Linux) or Reader9/Reader/intelsolaris/lib/ (for Solaris)
3) Remove the library named "libauthplay.so.0.0.0"

SEVERITY RATING

Adobe categorizes this as a critical issue.

DETAILS

A critical vulnerability exists in Adobe Flash Player 10.0.45.2 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems, and the authplay.dll component that ships with Adobe Reader and Acrobat 9.x for Windows, Macintosh and UNIX operating systems. This vulnerability (CVE-2010-1297) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against both Adobe Flash Player, and Adobe Reader and Acrobat.

The Flash Player 10.1 Release Candidate available at Adobe Labs - Adobe Flash Player 10.1 is confirmed not vulnerable.

Adobe Reader and Acrobat 8.x are confirmed not vulnerable. Mitigation is available for Adobe Reader and Acrobat 9.x customers as detailed above.

Adobe actively shares information about this and other vulnerabilities with partners in the security community to enable them to quickly develop detection and quarantine methods to protect users until a patch is available. As always, Adobe recommends that users follow security best practices by keeping their anti-malware software and definitions up to date.

We are in the process of finalizing a fix for the issue, and expect to provide an update for Flash Player 10.x for Windows, Macintosh, and Linux by June 10, 2010. The patch date for Flash Player 10.x for Solaris is still to be determined. We expect to provide an update for Adobe Readerand Acrobat 9.3.2 for Windows, Macintosh and UNIX by June 29, 2010. Users may monitor the latest information on the Adobe Product Security Incident Response Team blog at the following URL: Adobe Product Security Incident Response Team (PSIRT) or by subscribing to the RSS feed here: Adobe Product Security Incident Response Team (PSIRT).

REVISIONS

June 7, 2010 - Update schedule information added, instructions for Macintosh and UNIX added to 'Mitigations' section
June 4, 2010 - Advisory released.
Poyzon is offline   Reply With Quote
Old 06-08-2010, 08:20 AM   #2
Tim
Administrator
 
Tim's Avatar
 
Join Date: Jun 2009
Location: USA
Posts: 6,767
Default Re: Security Advisory for Flash Player, Adobe Reader and Acrobat

Whoa, an update to adobe reader and acrobat by the 29th? That is INSANE! I recommend everybody uninstall acrobat and adobe reader until then. The reason is that most major browsers (firefox, chrome, ie, etc) will auto-launch those readers if a webpage calls for it, which can happen by merely embedding into the website. Basically it means any website or flash can take advantage of the acrobat/reader vulnerability.
Tim is offline   Reply With Quote
Old 06-08-2010, 08:45 AM   #3
Senior Member
 
TheMuffinMan's Avatar
 
Join Date: Dec 2009
Location: Oklahoma, US
Posts: 1,421
Send a message via AIM to TheMuffinMan Send a message via MSN to TheMuffinMan Send a message via Yahoo to TheMuffinMan
Default Re: Security Advisory for Flash Player, Adobe Reader and Acrobat

Good thing I don't use Adobe Reader for opening PDFs. =) (and I updated my Flash)
__________________
TheMuffinMan is offline   Reply With Quote
Old 06-09-2010, 06:10 AM   #4
Super Moderator
 
Nghtmr9999's Avatar
 
Join Date: Aug 2009
Location: Minnesota, US
Posts: 1,662
Blog Entries: 6
Default Re: Security Advisory for Flash Player, Adobe Reader and Acrobat

omgs, we should totally move to HTML5

</apple>
__________________
Nghtmr9999 is offline   Reply With Quote
Old 06-09-2010, 03:22 PM   #5
Senior Member
 
Join Date: Nov 2009
Location: Vancouver, Canada.
Posts: 2,420
Default Re: Security Advisory for Flash Player, Adobe Reader and Acrobat

Kind of funny, after doing this security update, my dvd drive would not read a Stargate Atlantis disc which was already in the drive. Watch an episode last night, do the update, and then try to watch another one later that same evening.

Got the message that my current video driver would not allow the dvd to play protected content on the disc.

And then a video driver update done, and all is good again.

Just odd.
__________________
Google: Ualaa's guide to IS Boxer
Streaming in HD: www.twitch.tv/ualaa
Ualaa is offline   Reply With Quote
Old 06-09-2010, 04:23 PM   #6
Iru
Senior Member
 
Iru's Avatar
 
Join Date: Nov 2009
Posts: 221
Default Re: Security Advisory for Flash Player, Adobe Reader and Acrobat

Steve Balmer is messing with you.....
__________________
Iru is offline   Reply With Quote
Old 06-09-2010, 04:47 PM   #7
Senior Member
 
TheMuffinMan's Avatar
 
Join Date: Dec 2009
Location: Oklahoma, US
Posts: 1,421
Send a message via AIM to TheMuffinMan Send a message via MSN to TheMuffinMan Send a message via Yahoo to TheMuffinMan
Default Re: Security Advisory for Flash Player, Adobe Reader and Acrobat

Quote:
Originally Posted by Ualaa View Post
Kind of funny, after doing this security update, my dvd drive would not read a Stargate Atlantis disc which was already in the drive. Watch an episode last night, do the update, and then try to watch another one later that same evening.

Got the message that my current video driver would not allow the dvd to play protected content on the disc.

And then a video driver update done, and all is good again.

Just odd.
/offtopic
One of my favorite shows =) Cannot wait for them to bust out some Direct2DVD movies.
__________________
TheMuffinMan is offline   Reply With Quote
Reply

Tags
flash, hacking, security, trojan, update, vulnerability

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Sony Vegas or Adobe Premiere or Other? Psylence Off Topic 4 05-17-2010 07:47 AM
Update your Flash Player (to version 10,0,45,2) Poyzon General Discussions 1 02-16-2010 12:43 PM
Update your Flash - Now! Tim General Discussions 6 01-28-2010 05:49 PM
Long time boxer, short time reader... Zzyzxx71 General Discussions 7 10-28-2009 10:53 PM
Can a macro or addon target a player based on health? Tim World of Warcraft - Macros, UIs, Mods, Addons 26 07-25-2009 01:19 AM


SEO by vBSEO 3.3.2