Showing posts with label Adobe Air. Show all posts
Showing posts with label Adobe Air. Show all posts

Tuesday, 9 August 2011

Adobe CRITICAL Security Updates for August!

Adobe released another slew of 'Critical' security updates today. Here's the lineup:

- Adobe Shockwave Player - Update to v11.6.1.629. (Be careful which version you install, either 32-bit or 64-bit, to match the bit mode being used by your web browsers. If one version fails, uninstall it and try the other). Numerous memory corruption (buffer overflow) vulnerabilities.

- Adobe Flash Media Server - Update to v4.0.3 or v3.5.7. Memory corruption (buffer overflow) vulnerability.

- Adobe AIR - Update to version v2.7.1. (Apparently required as part of the Adobe Flash Player update).

- Adobe Flash Player - Update to v10.3.186.5. Numerous memory corruption (buffer overflow) vulnerabilities and a cross-site information disclosure vulnerability.

- Adobe Photoshop CS5 - Update via CS5/CS5.1 Standard Multiplugin Update. Malicious GIF file vulnerability.

- Adobe RoboHelp / RoboHelp Server - RoboHelp v9.0.1.262 users are NOT vulnerable. Earlier RoboHelp 9 users update via APSB11-23_1.zip. RoboHelp 8 users update via APSB11-23_2.zip. Cross-site scripting attack vulnerability.

You can access links to all the security announcements and update files here:

Adobe Product Security Incident Response Team (PSIRT) Blog

--

Sunday, 17 April 2011

CRITICAL Patches for: Adobe Flash Player & Acrobat Pro & Adobe Reader & Adobe AIR (Out-Of-Band!)

--
Sorting through this flock of updates is confusing. Therefore, for the sake of simplicity, I've thrashed through the Adobe mess for you. Below you will find links to relevant Adobe announcements as well as direct links to the update installers, lead with a *:

I) Adobe Reader & Adobe Acrobat 10.0.2 Updates:

Security updates available for Adobe Reader and Acrobat


*Adobe Acrobat 10.0.2 Pro update for Macintosh

II) Adobe Flash Player 10.2.159.1 & Adobe AIR 2.6.19140 Updates:

Security update available for Adobe Flash Player [& Adobe AIR]

*Adobe Flash Player 10.2.159.1 for Macintosh


NOTE: I tacked "[& Adobe AIR]" onto the link to the Flash announcement because it is the only place you'll find it stated that an update of Adobe AIR is available and required. (0_o)

I swear there's lead in the water at Adobe. I wish they'd get their act back together.
--

Wednesday, 6 October 2010

October Adobe Security Updates: Acrobat, Reader and AIR

--
Rather quietly, in keeping with Adobe's bad PR attitude, their latest 'CRITICAL' security updates have hit the net. Below are some direct links to help you past the clickity-click-click garbage you have to endure when going through Adobe's home page.

I) Adobe Acrobat Pro v9.4.0 update

IIa) Adobe Reader v9.4.0 update - multiple languages INTEL version

IIb) Adobe Reader v9.4.0 update - multiple languages PPC version

III) Adobe AIR v2.0.4.13090 update

And of course you've already installed Adobe Flash Player v10.1.0 update from two weeks ago, right?

What's been fixed?

Adobe Acrobat and Reader:
This vulnerability (CVE-2010-2883) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild.
--Quoting from CVE-2010-2883:
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.3.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information.
Adobe AIR: Beats me! As of today, Adobe have provided NO release notes for AIR v2.0.4. Imagine my cynicism. When Adobe bother to provide release notes, they will appear HERE.

Can anyone spare Adobe an anvil? Mine's in for repair. ;-)

And now it's time for a laugh! Every month this summer Adobe have had 'CRITICAL' security flaws discovered and patched in Acrobat, Reader and Flash Player. There have also been two updates to Adobe Air. Despite this situation, Adobe still hold to the bizarro naive notion of 'quarterly updates'. Here is their message to the world regarding this situation, as of today:
Note that today�s updates represent an accelerated release of the quarterly security update originally scheduled for October 12, 2010. With this accelerated schedule, Adobe will not release additional updates for Adobe Reader and Acrobat on October 12, 2010. The next quarterly security updates for Adobe Reader and Acrobat are scheduled for February 8, 2011.
Right. So we'll all meet back here on February 8th. Sure. Everything will be safe and sound until then! Uh huh.

We know better. See you back here next month!
;-P
--

Friday, 13 August 2010

Adobe Flash, AIR, PDF, Acrobat and Reader: Security Statistics Sources

--
Earlier today, I was helping out a reader at MacDailyNews.com who had the following question:
'BSOD' asks: "Does anyone have statistics on exactly how many security holes have been opened up by Flash, Air, and PDF? I think that we need to see that stat."
My answer is of general interest. Therefore, I am posting it here for your reading pleasure:
You can dig around at the CVE site for each of them. CVE stands for Common Vulnerabilities and Exposures. It keeps track of each reported software security problem:

http://cve.mitre.org/

Wikipedia.org also covers each of them and gives a general description of their security:

Adobe Flash: "As of May 17, 2010, The Flash Player has 77 CVE entries, 34 of which have been ranked with a high severity (leading to arbitrary code execution), and 40 ranked medium."

Adobe PDF: "On March 30, 2010 security researcher Didier Stevens reported an "exploit" that causes an arbitrary executable to be run when a PDF file is opened, after the user accepts a warning prompt. The exploit works in several different PDF viewers including Adobe Reader and Foxit Reader."

And, earlier this year Adobe were embarrassed into creating the Adobe Product Security Incident Response Tearm (PSIRT). You can keep up with their blog here:

http://blogs.adobe.com/psirt/

Adobe maintain their Security Bulletins and Advisories page, going back to 2005, here:

http://www.adobe.com/support/security/

� There are approximately 88 Adobe Flash security bulletins.
� There are 6 Adobe PDF security bulletins.
� There are over 100 Adobe Acrobat security bulletins.
� There are over 100 Adobe Reader security bulletins.
� The only Adobe AIR related bulletin is the Adobe Flash bulletin from June 10, 2010.

Wednesday, 11 August 2010

New CRITICAL Adobe Flash Player v10.1.82.76 & Adobe Air v2.0.3 Updates

--
Today Adobe updated Flash Player to version 10.1.82.76 and Adobe Air to version 2.0.3. The updates patch 6 CRITICAL security holes. Here are the security patch details:
Critical vulnerabilities have been identified in Adobe Flash Player version 10.1.53.64 and earlier. These vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system.

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-0209).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2188).

This update resolves multiple memory corruption vulnerabilities that could lead to code execution (CVE-2010-2213).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2214).

This update resolves a vulnerability that could lead to a click-jacking attack. (CVE-2010-2215).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2216).

Adobe recommends users of Adobe Flash Player 10.1.53.64 and earlier versions update to Adobe Flash Player 10.1.82.76. Adobe recommends users of Adobe AIR 2.0.2.12610 and earlier versions update to Adobe AIR 2.0.3.
The download links are provided on Adobe's Security Bulletin page HERE.

Lately, Adobe's Flash Player has been considered the most dangerous application for Mac OS X from a security point of view. It is important to keep track of ALL Adobe updates at this point in time. We are still waiting for NEW updates to Adobe Acrobat and Adobe Reader that patch security holes announced last week HERE.
--

Friday, 31 July 2009

Adobe Releases Security Patched Reader and Acrobat v9.1.3

--
As promised, on Friday, July 31, Adobe released security patched versions of Acrobat and Adobe Reader. The links in the previous article about the subject should get you started, but I've provided them again below.

NOTE: verify that you are downloading and installing versions 9.1.3 of Reader and Acrobat and not an earlier version. The download page for the Acrobat 9.1.3 update is clear regarding versions. However, the Acrobat Reader page is NOT. Therefore, after you download and install "the latest version" of Reader, go under the Help menu to "Check for Updates...". Otherwise you may have only installed an earlier version of Reader without the new security patches.

Those patch download links again:

1) Adobe Flash Player v10.0.32.18. There is a special patch for version 9 users to v9.0.246.0.

2) Adobe Air v1.5.2.

3) Adobe Reader v9.1.3.

4) Acrobat v9.1.3.

Glad to be of service!
--

Thursday, 30 July 2009

Critical Adobe Security Patches Arrive, Again

--
I just gotta rant for a couple paragraphs:

The most disappointing thing I learned this week is that Adobe knew about this current crop of security holes last December, 2008. So why are we only learning about it now and only getting patches now. Didn't I say Adobe sucks?

And isn't it amusing that Adobe patched up one slew of security holes last month, and waited on this slew of further security holes. What do they do over at their offices? Argue about whether to patch? How to patch? When to patch? How long can they delay it without people saying 'Adobe sucks"? I know they have a messed up work culture over there. Get with it dummies!

The Patches:

1) Adobe Flash Player v10.0.32.18. There is a special patch for version 9 users to v9.0.246.0.

2) Adobe Air v1.5.2

3) Adobe Reader v9.1.3 - Theoretically available Friday, July 31

4) Acrobat v9.1.3 - Theoretically available Friday, July 31

NOTE: Verify which version you have downloaded. Adobe often don't mark what specific version you are downloading. Instead they may tell you that you are downloading "the latest version" when in fact you are NOT. You need to DIY update whatever you downloaded to the actual 'latest version'. Adobe provide no warning whatsoever. Adobe know about this problem and maybe will stop this practice in the future.

As I say ad nauseam: We're still in the Stone Age of Computing, and in the future they will pity us for the clunky junky stuff we had to put up with. (o_0)
--

Search