You are here: silicon.com > Software > Security Strategy

Security Strategy

Flash hole fix coming next week, says Adobe

SeaMonkeys taking on Trojan horses

Tags: trojan horse, flash, adobe, firefox

By Elinor Mills

Published: 24 July 2009 08:59 GMT

Adobe said Thursday that it will issue fixes next week for a critical hole in Flash that is being exploited in attacks against Adobe Reader version 9 on Windows.

The vulnerability exists in current versions of Flash Player for Windows, Macintosh, and Linux and the authplay.dll component that ships with Adobe Reader and Acrobat v9.x for those same platforms, Adobe said in an advisory.

The vulnerability could cause a system to crash or allow an attacker to take control of the computer, Adobe said.

An update for Flash Player v9 and v10 for Windows, Mac, and Linux will be released by 30 July, while a fix for Solaris is pending. Adobe should have an update for Reader and Acrobat v9.1.2 for Windows, Macintosh, and Unix by 31 July.

An attacker can exploit the vulnerability by luring someone to a website hosting a specially crafted Shockwave Flash file, US-Cert said in an advisory on Thursday.

Cert said: "The Adobe Flash browser plug-in is available for multiple web browsers and operating systems, any of which could be affected.

"An attacker could also create a PDF document that has an embedded SWF file to exploit the vulnerability. This vulnerability is being actively exploited."

The vulnerabilities can be mitigated by disabling the Flash plug-in or by using the NoScript extension for Mozilla Firefox or SeaMonkey to whitelist sites that can access the Flash plug-in, Cert said.

Windows Vista users can mitigate the impact of the exploit by enabling UAC (User Access Control), according to Adobe. Flash Player users should be careful when browsing unfamiliar websites.

Researchers on Wednesday reported that they had uncovered attacks in the wild in which malicious Acrobat PDF files were exploiting a vulnerability in Flash and dropping a Trojan onto computers.

The bug used in the exploit has been around since December 2008.

Original article: Adobe to fix critical Flash hole next week from CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...

Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech


  • Jobs
Senior Web Designer; CSS XHTML SEO Adobe Flash Photoshop Illustrator

JQuery • Search Engine Optimisation (SEO) In addition you will have solid experience of the Adobe Creative Suite (CS3) to include the ...

Flash Developer - E-Learning Sector

Flash Developer - E-Learning Sector Location: Cambridgeshire Salary: 19K - 25K Necessary Requirements: The successful applicant to the post of Flash ...

Web Developer Co Clare

Keywords:Web developer web designer web Specialist front end intranet job role career Co Clare Shannon Ennis Clare Limerick west coast west-coast ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: