Showing posts with label Adobe Flash Player. Show all posts
Showing posts with label Adobe Flash Player. Show all posts

Wednesday, 15 February 2012

Adobe Flash Player: Critical Security Update to v11.1.102.62

--
And then Adobe released a critical security update for their Flash Player! Be sure to update ASAP to Adobe Flash Player version 11.1.102.62. You can 1-step download the update from here:

http://get.adobe.com/flashplayer/?promoid=BUIGP

The update includes six security patches relevant to Mac OS X users. You can read Adobe's provided details here:


For those interested, three of the security patches involve memory corruption. Two of the patches repair security bypass vulnerabilities. One of the patches is for a cross-site scripting vulnerability.

Don't forget to update to yesterday's new critical security update version of Adobe Shockwave Player as well!
--

Tuesday, 9 August 2011

Adobe CRITICAL Security Updates for August!

Adobe released another slew of 'Critical' security updates today. Here's the lineup:

- Adobe Shockwave Player - Update to v11.6.1.629. (Be careful which version you install, either 32-bit or 64-bit, to match the bit mode being used by your web browsers. If one version fails, uninstall it and try the other). Numerous memory corruption (buffer overflow) vulnerabilities.

- Adobe Flash Media Server - Update to v4.0.3 or v3.5.7. Memory corruption (buffer overflow) vulnerability.

- Adobe AIR - Update to version v2.7.1. (Apparently required as part of the Adobe Flash Player update).

- Adobe Flash Player - Update to v10.3.186.5. Numerous memory corruption (buffer overflow) vulnerabilities and a cross-site information disclosure vulnerability.

- Adobe Photoshop CS5 - Update via CS5/CS5.1 Standard Multiplugin Update. Malicious GIF file vulnerability.

- Adobe RoboHelp / RoboHelp Server - RoboHelp v9.0.1.262 users are NOT vulnerable. Earlier RoboHelp 9 users update via APSB11-23_1.zip. RoboHelp 8 users update via APSB11-23_2.zip. Cross-site scripting attack vulnerability.

You can access links to all the security announcements and update files here:

Adobe Product Security Incident Response Team (PSIRT) Blog

--

Sunday, 17 April 2011

CRITICAL Patches for: Adobe Flash Player & Acrobat Pro & Adobe Reader & Adobe AIR (Out-Of-Band!)

--
Sorting through this flock of updates is confusing. Therefore, for the sake of simplicity, I've thrashed through the Adobe mess for you. Below you will find links to relevant Adobe announcements as well as direct links to the update installers, lead with a *:

I) Adobe Reader & Adobe Acrobat 10.0.2 Updates:

Security updates available for Adobe Reader and Acrobat


*Adobe Acrobat 10.0.2 Pro update for Macintosh

II) Adobe Flash Player 10.2.159.1 & Adobe AIR 2.6.19140 Updates:

Security update available for Adobe Flash Player [& Adobe AIR]

*Adobe Flash Player 10.2.159.1 for Macintosh


NOTE: I tacked "[& Adobe AIR]" onto the link to the Flash announcement because it is the only place you'll find it stated that an update of Adobe AIR is available and required. (0_o)

I swear there's lead in the water at Adobe. I wish they'd get their act back together.
--

Tuesday, 15 March 2011

Mac Security Status Report, Part II

--
Internet Privacy Tools

One of the quietly astounding developments on the Mac platform is the arrival of terrific tools for establishing real privacy on the Internet. 2010 was rife with stories about how our privacy and even our identity was being stripped away by everyone from the Corporate Oligarchy to the legitimate US federal government. You'd think we were still living under the thrall of The Bush League Era, the assault on privacy has been so persistent and thorough. But serious tools for reestablishing US Constitution guaranteed privacy rights are here and they work. I would go so far as to say that 2010 established an Internet revolution of user privacy. I could not be more pleased.

Here are a few of the wonderful privacy tools and events from 2010. Keep in mind that much of this has been in the works for years and that there are more privacy tools on the way:

1) The Onion/Tor/Vidalia Project: The "Onion Router" project began back in 2002 as a method for concealing Internet user's identity and network activity, preventing surveillance and traffic analysis. Amazingly, the project was originally supported by the US Naval Research Laboratory. In 2004 the Electronic Frontier Foundation (EFF) began supporting the project, providing important guidance and solidification of the project's manifesto. In 2006 the Tor Project was established as a non-profit organization gathering and providing all financial support.

There are a number of FREE pieces of software that make use of the Tor Network. The prime program is Vidalia, aka 'Tor'. This is the software that runs the show. If you use Firefox, you will also need to install the Tor Button add-on. The next useful tool is a web page called "Check". It will verify for you whether you have Tor properly running on your system and web browser. Of side interest are a few other tools such as the Tor Browser Bundle (currently in beta for Mac OS X), and the Firefox add-on FoxyProxy.

Learning how to use Tor is difficult. Try to find someone who understands it to help you out. It is very much 'geek' level technology with meagre documentation and lots of obscure tricks required to use it to the fullest. With patience you'll find that Tor is astounding, effective and important for maintaining real Net Neutrality and user privacy.

In the near future I will be providing a long promised Mac specific article about how to use Tor for overcoming media marketing blackouts on the Internet. Keep an eye on my MacSmarticles blog. If you wish very hard, you may find me providing a series of articles about how to use Tor, translating geek-speak into intermediate Mac user lingo.

2) Ghostery: This is a FREE tracking cookie and web-bug tracking system. The tracker list is frequently updated and is very thorough from my experience. It runs on-the-fly killing off inter-website tracking systems. As you move from page to page it provides you with a small window listing all the detected and blocked tracking sources. As you use Ghostery you will seriously astounded at the amount of tracking/surveillance being perpetrated at you. Maybe you don't care. Maybe you're in marketing and you believe anti-tracking tools are evil. Personally, I love Ghostery and won't leave my home page without it.

Here is what the Ghostery developers have to say about it:
Be a web detective.

Ghostery is your window into the invisible web � tags, web bugs, pixels and beacons that are included on web pages in order to get an idea of your online behavior.

Ghostery tracks the trackers and gives you a roll-call of the ad networks, behavioral data providers, web publishers, and other companies interested in your activity...
There are THREE versions of Ghostery that work on Mac. One is the Firefox add-on. Another is the Safari extension. The last version is for Google Chrome. You can access all versions of Ghostery HERE.

3) Safari Cookies: This is an indispensable FREE add-on for Safari. It works great with Ghostery and provides further functionality. It has three main functions:
  • It allows you to create a website Cookie white list while killing off everything else.
  • It allows you to create a Flash Cookie white list while killing off everything else.
  • It allows you to create a website Database white list while killing off everything else. (I bet you didn't even know that websites could dump database information into your web browser! Very nasty).
Important: Do NOT use versions 1.6.4 - 1.6.7 of Safari Cookies. I've been in contact with the developer about their bugs and he most kindly has overcome them all with version 1.6.8 onwards. Now that it is working again, I cannot recommend Safari Cookies enough. Many thanks to SweetP Productions!

4) ECMAScript/JavaScript Prevention Tools: JavaScript is both a boon and a plague on the Internet. JavaScript allows such nifty things as Ajax coding on web pages. And yet, frequent readers of this blog know that I would very much enjoy JavaScript being erased from history and replaced with a scripting language that is actually and reliably SECURE. IOW: JavaScript is a gateway for malware and OS pwning. The blame for this catastrophic mess lies with three sources:
  1. Netscape, who invented Mocha, renamed LiveScript, the original name of 'JavaScript' before marketing-morons were allowed to license and inflict the utterly confusing and wrong 'Java' name into its title. (I despise marketing-morons. Have you noticed that? I worked with them every day for five long, stressful, infuriating years at Eastman Kodak, gawd help me. But I rant...).
  2. Microsoft, who inflicted their own typical insecure crapcode into JavaScript in the form of a monstrosity they call 'JScript'. Until recently, if you had attempted to resolve a web page that was designed using Microsoft's worst-in-class web design program 'FrontPage' you found the result to be a disaster. JScript was the main culprit. These days most web browsers comprehend JScript. But it remains a prime cause of hit-and-run website malware infections. Microsoft trolls will find this statement infuriating I exaggerate not. Just be glad that Mac users don't also have to contend with ActiveX, yet-another insecure Microsoft scripting language. (The Mozilla Project used to support Active-X but a couple years back banned it from any of their browsers for the benefit of their users and future generations of Internet users, amen).
  3. Adobe, who own what was once Macromedia, who perpetrated an insecure scripting language called ActionScript. It is mainly used in Flash and SWF embedded web pages, is one reason why Flash hacking is well known as a prime method for pwning Mac OS X. It is also one of the many reasons why Apple wisely banned Flash from their iDevices. It is also a prime source of malware for the Google Android OS.
Preventing this toxic brew of dangerous scripting languages from ruining your Internet browsing experience has become increasingly crutial. That is why I champion browser add-ons that let you choose when or whether to load JavaScript. Here are a few of the JavaScript prevention tools for Mac web browsers:

� NoScript: This celebrated FREE Firefox add-on from InformAction is brilliant. It is frequently updated to keep up with the lastest in scripting crapcode. And it not only protects you from evil JavaScript! It also protects you from evil Java, Flash and other insecure web plug-in code that may be out to infect or pwn you. This add-on is one of the prime reasons to dump all your other web browsers and go 100% Firefox. I kid you not. Much as I like Safari, when I want first class web security, I use Firefox with both NoScript and Ghostery running. Get it. Use it. Enjoy!

� JavaScript Blacklist: This is a rather meagre FREE Open Source add-on JavaScript killer for Safari. It allows you to block JavaScript from any web domain. Sadly, it is little more than proof-of-concept with a teeny-weeny 2.5 inch text box for inputting  your blocked website list. The best way to use it is to create your list in a text editor then copy and paste it into the teeny-weeny box. Whenever you want to add to your list, edit your text file then copy and paste again. There is no point in bothering to do any editing within JavaScript Blacklist itself. If you can deal with its shortcomings, this is a nice add-on for Safari fans like myself.

If you're ambitious, there are places to find lists of websites know to be infected with dangerous JavaScript. Ideally you could hack together a list from NoScript. But you'll find the task arduous. Don't bother.

5) Open Wi-Fi Router Defense Tools:

HTTPS Everywhere

This is a Firefox extension/add-on that specifically counters the hackware Firesheep extension/add-on. You can read about Firesheep here:

Firesheep

The general concept of this hacker war is that every website must stop using mere http connections and move over to https, SSL encrypted connections. HTTPS forces on SSL at websites exploited by Firesheep that are known to offer it.

6) Evercookie Defense Tools:

The 'Evercookie' is a concept developed this past year that threatens even the most obsessive of personal privacy web surfers. You can read about it here:

Evercookie

The basic concept is that there are multiple files tossed onto our computer as we surf the Internet. What we call browser 'cookies' are only one form. Using the Everycookie concept, a personal privacy parasite needs only one of these several files to track us across the Internet. And any one of these files can be used to respawn all the others. Therefore, with the Evercookie system, real personal privacy requires deleting every single one of these tracking files from your web browser

The best tool to combat the Evercookie so far, that I am aware of, is the BetterPrivacy extension/add-on for Firefox. You can read about hit and download it here:

BetterPrivacy

~~~~~~~~~~~~~

There are further Internet privacy tools a plenty! But this shortlist covers the best of them and will get you going. I know! These tools don't fully solve the 'Evercookie' dilemma. But I don't know anything that does, not yet anyway. Hopefully an Evercookie killing tool is in store for us in 2011.

Coming up in Part III will be my version of a comprehensive list of currently active malware for Mac OS X, including all their various names. All of them are either Trojan horses or hacker tools. I am also looking forward to putting together an article on Mac OS X 10.7 Lion security, which so far sounds like a decent improvement. Stay tuned!
--

CRITICAL Zero-Day Security Exploit In-The-Wild: Adobe Flash & Adobe Acrobat & Adobe Reader

--
Q: So Adobe! How's that quarterly 'in-band' update schedule working for you?
A: Um...

After a nice break from The Summer Of Security Holes, we are back on track with CRITICAL Adobe zero-day exploits. This one hits ALL versions of Adobe Flash (v10.2.152.33 on down) on ALL OS platforms, except of course Apple's iOS which does not allow Flash content. Now perhaps skeptics can understand why. It also hits versions 10.0.1 on down through v9.x of Adobe Reader and Adobe Acrobat on Mac and Windows.

Here is the security advisory from Adobe.
This vulnerability (CVE-2011-0609) could cause a crash and potentially allow an attacker to take control of the affected system. 
Here is an article by Electronista.
Given the popularity of the Flash platform, it would seem that this could be a somewhat difficult situation to manage.
Here is the advisory from Adobe's PSIRT (Adobe Product Security Incident Response Team) blog.
We are in the process of finalizing a fix for the issue and expect to make available an update . . . during the week of March 21, 2011.
And here are even more details from yet-another Adobe security blog, this time called ASSET (Adobe Secure Software Engineering Team).
We currently plan to address CVE-2011-0609 in Adobe Reader X with the next quarterly security update for Adobe Reader, currently scheduled for June 14, 2011.... We determined that the above patch schedule would allow us to provide the best balance of risk mitigation and admin/update costs for our customers.
Translation: Watch for patches of Adobe Flash Player, Adobe Acrobat and Adobe Reader v9.x (not 10.x) the week of March 21, 2011. There will be NO patch for Acrobat Reader v10.x until the scheduled quarterly "in-band" date of June 14, 2011. There is an explanation of this inexplicable schedule in the ASSET article.

The currently known exploit is a Microsoft Excel (XLS) file sent via email to victims. Embedded within this file is a Trojan horse Flash file (SWF). Adobe does not explicitly state that this specific file is directed only at Windows users. However, the details they provide refer only to using 'Protected Mode' in Adobe Reader, which is a Windows-only feature. Therefore, I can infer that this is a Windows-only exploit file.

Other exploits are possible. Therefore, until Adobe patch this hole, beware of Flash in general, either as straight Flash files OR embedded in another file type.

My solutions:

A) Use one of the many Flash blocking extensions in your web browsers AT ALL TIMES.

B) As a corollary of The Second Rule Of Computing:
  1. Only open files emailed to you AFTER you have verified that their source is legitimate.
  2. Only click on embedded Flash on web sites that have been verified to be legitimate.
C) Don't use Adobe Reader. Use Apple's Preview application.

D) If you just 'have to' use Adobe Reader: Be sure you are using 'Enhanced Security' inside the Preferences. You'll find it listed under 'Security (Enhanced)'. Note that this is enabled by default when you first install Adobe Reader.

E) Or to be totally safe: Remove Adobe Flash, Adobe Acrobat and Adobe Reader from your computer.

Q: Does this make the Internet more dangerous than ever?
A: You bet!

Q: Why does the Internet have to be such an annoying pain?
A: Bad coding practices by developers as well as poor code documentation, critical to cleaning up bad code.

Theoretically, newer coding students are being taught how to avoid computer memory security holes. However, even if they are diligent at writing 'perfect' code, other problems persist in the code languages themselves. For example, the Java code language was created specifically to never be able to exploit the user's computer. And yet it does. As I ever rant: We are still in The Stone Age Of Computing.

Q: Are Mac users really vulnerable to this security exploit?
A: Absolutely!

Keep in mind that this is not an Apple or Mac OS X problem. This is an Adobe problem. It is their software that is being exploited and ends up damaging the computer. There is nothing Apple can do to prevent Flash exploits apart from ban Flash, which is thankfully the case with all Apple iOS devices.

Meanwhile, whether this exploit will be targeted specifically at Macs is entirely up to the evil scumbag hackers writing the exploit code. If I hear of a Mac specific exploit file, I will post here.
--

Thursday, 4 November 2010

Adobe Flash Player 10.1.102.64 CRITICAL Update

--
THIS MONTH'S critical Adobe Flash Player update for Mac OS X is available a few days ahead of schedule. Thank you Adobe! It patches 18 security holes.

Security update available for Adobe Flash Player
Critical vulnerabilities have been identified in Adobe Flash Player 10.1.85.3 and earlier versions for Windows, Macintosh, Linux, and Solaris, and Adobe Flash Player 10.1.95.1 for Android. These vulnerabilities, including CVE-2010-3654 referenced in Security Advisory APSA10-05, could cause the application to crash and could potentially allow an attacker to take control of the affected system.

Adobe recommends users of Adobe Flash Player 10.1.85.3 and earlier versions for Windows, Macintosh, Linux, and Solaris update to Adobe Flash Player 10.1.102.64. We expect to make available an update for Flash Player 10.x for Android by November 9, 2010. . .
The download link is HERE.

NOTE: We're still waiting for CRITICAL security updates for Adobe Reader 9.4 and Adobe Acrobat 9.4. You can read details about the ongoing security problems HERE.
--

Thursday, 28 October 2010

Adobe Flash, Reader and Acrobat CRITICAL Security Hole Of The Month Club

--
Another month, and other Adobe software security hole exploit. If you still use Flash, pay attention! This security hole is currently being exploited In-The-Wild.

Affected:

-> Adobe Flash Player 10.1.85.3 and earlier

-> Adobe Reader 9.4 and earlier 9.x versions

-> Adobe Acrobat 9.4 and earlier 9.x versions

Hackers exploit newest Flash zero-day bug
Those reports came from Mila Parkour, an independent security researcher who notified Adobe early today after spotting and then analyzing a malicious PDF file. According to Parkour, the rigged PDF document exploits the Flash bug in Reader, then drops a Trojan horse and other malware on the victimized machine.
Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat

This issue is described in CVE-2010-3654.

Adobe provide a workaround in their 'Security Advisory' article linked above. They have promised to fix the security hole by November 9th.

Darn, Adobe blew their quarterly update schedule yet again. Can you comprehend why Adobe still believe in 'scheduled' security updates?
(o_0)

Wednesday, 6 October 2010

October Adobe Security Updates: Acrobat, Reader and AIR

--
Rather quietly, in keeping with Adobe's bad PR attitude, their latest 'CRITICAL' security updates have hit the net. Below are some direct links to help you past the clickity-click-click garbage you have to endure when going through Adobe's home page.

I) Adobe Acrobat Pro v9.4.0 update

IIa) Adobe Reader v9.4.0 update - multiple languages INTEL version

IIb) Adobe Reader v9.4.0 update - multiple languages PPC version

III) Adobe AIR v2.0.4.13090 update

And of course you've already installed Adobe Flash Player v10.1.0 update from two weeks ago, right?

What's been fixed?

Adobe Acrobat and Reader:
This vulnerability (CVE-2010-2883) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild.
--Quoting from CVE-2010-2883:
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.3.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information.
Adobe AIR: Beats me! As of today, Adobe have provided NO release notes for AIR v2.0.4. Imagine my cynicism. When Adobe bother to provide release notes, they will appear HERE.

Can anyone spare Adobe an anvil? Mine's in for repair. ;-)

And now it's time for a laugh! Every month this summer Adobe have had 'CRITICAL' security flaws discovered and patched in Acrobat, Reader and Flash Player. There have also been two updates to Adobe Air. Despite this situation, Adobe still hold to the bizarro naive notion of 'quarterly updates'. Here is their message to the world regarding this situation, as of today:
Note that today�s updates represent an accelerated release of the quarterly security update originally scheduled for October 12, 2010. With this accelerated schedule, Adobe will not release additional updates for Adobe Reader and Acrobat on October 12, 2010. The next quarterly security updates for Adobe Reader and Acrobat are scheduled for February 8, 2011.
Right. So we'll all meet back here on February 8th. Sure. Everything will be safe and sound until then! Uh huh.

We know better. See you back here next month!
;-P
--

Tuesday, 21 September 2010

Adobe Flash Player Updated is to v10.1.85.3

--
Adobe has successfully hidden from the public, apart from at their two security pages, the fact that a 'Critical' security update was posted to to their website on Monday. The Adobe website simply says you're downloading version 10.1, same as last weeek, which is a worthless statement!

So, grumble, let me do their job for them and let you know that:

A) The current version of Adobe Flash Player for Mac that is up on the Adobe website IS indeed the promised updated version.

B) The previous version of 'Flash Player.plugin' was 10.1.82.76.

C) The new updated version you're installing is 10.1.85.3.

The inevitable rant:

Why this has to be a secret is beyond comprehension. I sniff the scent of some Marketing Moron at Adobe in the air who is attempting spin control by hiding the fact that Adobe has had to provide 'out of band' security updates to Adobe Flash Player EVERY MONTH THIS SUMMER. Sorry marketing kiddies, but facts are facts. You are directly damaging customers by hiding updates from them. This is why I call you Marketing Morons! Get it? Drop an anvil on your head, or whatever it takes, and turn yourselves into beneficial Marketing Mavens and HELP YOUR CUSTOMERS! Otherwise get out of the business and benefit the world by your absence.
--

Saturday, 18 September 2010

Adobe Flash Player Security Update: Moved Up To Monday, September 20th

--
Adobe have announced that they've moved up the critical security update for Flash Player to Monday, September 20, 2010.

Be sure to grab the update ASAP as the security hole it patches (CVE-2010-2884) is being exploited in-the-wild on at least Windows boxes. So far no known exploit is being used on Mac OS X.

You can read Adobe's announcement here:

Schedule Update to Security Advisory for Adobe Flash Player (APSA 10-03)

Meanwhile, the critical security updates for Adobe Reader and Acrobat remain scheduled for the week of October 4, 2010.

--

Tuesday, 14 September 2010

NEWEST-New CRITICAL Adobe Security Holes d�j� vu d�j� vu d�j� vu...


--
Question: What is the point of 'in band' quarterly Adobe security updates when this stuff keeps repeating month after month after month?

SHORT VERSION:

Don't use Adobe Reader, Adobe Acrobat, or Adobe Flash until yet-another-nother set of 'out-of-band' security updates are available. Each of these applications have NEW security holes that are being exploited IN THE WILD.

[...Hysterical laughter is heard from some distant room...]

Temporary fix options:

A) PDF Viewing

Use Preview, provided with Mac OS X, for all PDF file reading.

Delete the Adobe PDF Viewer Internet plug-in. You will find it here:
/Library/Internet Plug-ins/AdobePDFViewer.plugin
Delete Adobe Reader 9. You will find it here:
/Library/Applications/Adobe Reader 9
B) Flash Playing

Control Flash in your web browser and/or delete Flash Player:

There are several options for taking control of Flash in your web browser. I personally use ClickToFlash for Safari and other WebKit browsers, as well as Flashblock for FireFox.

OR

Just delete Adobe Flash Player from your computer.

How to remove Adobe Flash Player:

Check to see if you have the 'uninstall_flash_player_osx.dmg' file and run it. It should be located here:
/Applications/Adobe Flash Player/uninstall_flash_player_osx.dmg
OR

You can find and remove the Flash web plug-in files here:
/Library/Internet Plug-Ins/Flash Player.plugin

/Library/Internet Plug-ins/flashplayer.xpt
After deleting Adobe Flash Player files, be sure to Quit then restart your web browsers in order to clean Flash Player out of memory.

~~~~~~~~~~~~~~

LONG VERSION:

Just when you thought your Adobe apps were safe, this dark sense of wariness creeps into your subconsciousness followed by a sense of d�j� vu as you read the latest news. I'll let Adobe give you the bad news. Here are the two pages at Adobe where you can find their security announcements:

Adobe Product Security Incident Response Team (PSIRT)

Adobe Security Bulletins and Advisories

The latest Adobe bad news d�j� vu d�j� vu d�ja vu (with added emphasis mine):


I) Security Advisory for Adobe Reader and Acrobat (APSA10-02)
Release date: September 8, 2010

Last updated: September 13, 2010

Vulnerability identifier: APSA10-02

CVE number: CVE-2010-2883

Platform: All

SUMMARY

A critical vulnerability exists in Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2883) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild.

We are in the process of finalizing a fix for the issue and expect to provide updates for Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 for Windows and Macintosh during the week of October 4, 2010.

Please note that these Adobe Reader and Acrobat updates represent an accelerated release of the next quarterly security update originally scheduled for October 12, 2010. With this accelerated schedule, we do not plan to release any new updates for Adobe Reader and Acrobat on October 12, 2010.

AFFECTED SOFTWARE VERSIONS

Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX
Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh

MITIGATIONS

Current exploits in the wild target the Windows platform. Customers using Adobe Reader or Acrobat 9.3.4 or earlier on Windows can utilize Microsoft's Enhanced Mitigation Evaluation Toolkit (EMET) to help prevent this vulnerability from being exploited. For more information on EMET and implementing this mitigation, please refer to the Microsoft Security Research and Defense blog. Note that due to the time-sensitive nature of this issue, testing of the functional compatibility of this mitigation has been limited. Therefore, we recommend that you also test the mitigation in your environment to minimize any impact on your workflows.

SEVERITY RATING

Adobe categorizes this as a critical issue.

DETAILS

A critical vulnerability exists in Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2883) could cause a crash and potentially allow an attacker to take control of the affected system. Adobe is aware of public exploit code for this vulnerability.

Adobe actively shares information about this and other vulnerabilities with partners in the security community to enable them to quickly develop detection and quarantine methods to protect users until a patch is available. As always, Adobe recommends that users follow security best practices by keeping their anti-malware software and definitions up to date.

We are in the process of finalizing a fix for the issue and expect to provide updates for Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 for Windows and Macintosh during the week of October 4, 2010. These updates will also address the issue referenced in Security Advisory APSA10-03 (CVE-2010-2884).

Please note that these Adobe Reader and Acrobat updates represent an accelerated release of the next quarterly security updates originally scheduled for October 12, 2010. With this accelerated schedule, we do not plan to release any new updates for Adobe Reader and Acrobat on October 12, 2010.

Users may monitor the latest information on the Adobe Product Security Incident Response Team blog at the following URL: http://blogs.adobe.com/psirt or by subscribing to the RSS feed here: http://blogs.adobe.com/psirt/atom.xml.

ACKNOWLEDGMENTS

Adobe would like to thank Mila Parkour of http://contagiodump.blogspot.com for working on this issue with Adobe to help protect our customers.

REVISIONS

September 13, 2010 - Updated information on the release schedule, and that the releases represent the next quarterly security update (originally scheduled for October 12, 2010).
September 10, 2010 - Added the Mitigations section with instructions for a mitigation option for Windows users.
September 8, 2010 - Advisory released.

II) Security Advisory for Adobe Flash Player (APSA 10-03)
Release date: September 13, 2010

Vulnerability identifier: APSA10-03

CVE number: CVE-2010-2884

Platform: All

SUMMARY

A critical vulnerability exists in Adobe Flash Player 10.1.82.76 and earlier versions for Windows, Macintosh, Linux, Solaris, and Adobe Flash Player 10.1.92.10 for Android. This vulnerability also affects Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2884) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against Adobe Flash Player on Windows. Adobe is not aware of any attacks exploiting this vulnerability against Adobe Reader or Acrobat to date.

We are in the process of finalizing a fix for the issue and expect to provide an update for Adobe Flash Player for Windows, Macintosh, Linux, Solaris, and Android operating systems during the week of September 27, 2010. We expect to provide updates for Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 for Windows and Macintosh during the week of October 4, 2010.

AFFECTED SOFTWARE VERSIONS

Adobe Flash Player 10.1.82.76 and earlier versions for Windows, Macintosh, Linux, Solaris, and Adobe Flash Player 10.1.92.10 for Android
Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX
Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh

SEVERITY RATING

Adobe categorizes this as a critical issue.

DETAILS

A critical vulnerability exists in Adobe Flash Player 10.1.82.76 and earlier versions for Windows, Macintosh, Linux, Solaris, and Adobe Flash Player 10.1.92.10 for Android. This vulnerability also affects Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2884) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against Adobe Flash Player on Windows. Adobe is not aware of any attacks exploiting this vulnerability against Adobe Reader or Acrobat to date.

We are in the process of finalizing a fix for the issue and expect to provide an update for Adobe Flash Player for Windows, Macintosh, Linux, Solaris, and Android operating systems during the week of September 27, 2010. We expect to provide updates for Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 for Windows and Macintosh during the week of October 4, 2010.

Adobe actively shares information about this and other vulnerabilities with partners in the security community to enable them to quickly develop detection and quarantine methods to protect users until a patch is available. As always, Adobe recommends that users follow security best practices by keeping their anti-malware software and definitions up to date.

Users may monitor the latest information on the Adobe Product Security Incident Response Team blog at the following URL:

http://blogs.adobe.com/psirt

or by subscribing to the RSS feed here:

http://blogs.adobe.com/psirt/atom.xml

ACKNOWLEDGMENTS

Adobe would like to thank Steven Adair of the Shadowserver Foundation for working with us on this issue with Adobe to help protect our customers.

~~~~~~~~~~~

And now for another rant:

This past week we learned that the first version of Adobe Flash Player had been released for the Google Android OS for smartphones. We also learned that it is a dreadfully buggy, slow, battery consuming POS. Now we learn, if you read through the Adobe bulletins above, that Flash for Android has a 'critical' security hole.

These two Adobe Flash problems were known over a year ago. Dr. Charlie Miller warned us that Flash is the single biggest source of pwnage security holes on the Mac OS X platform. Steve Jobs made it clear that Flash for Mac is a resource hog, verifiable by anyone with a brain (which apparently is not the case with Adobe's current CEO). It is no surprise that Flash turns out to be a resource hog, running as slow as a one-legged dog on Android.

Conclusion: It's time for Flash to die.

Then what?

Contrary to popular mythology, there is no perfect replacement for Flash. The HTML5 video spec promises to replace one niche for Flash with a totally free-forever video playing alternative. (Yes kids. The patent holders for H.264 are giving it away for everyone forever). However, actual Flash applications will be more difficult to replace. These include games, slideshows, web page embedded applications, etc.

Once upon a time we dreamed that Java would take up these roles, and perhaps it may someday. But for now, Java is considered much more difficult to program than Flash, slow to run, and Java has its own security problems. Ideally a Java app building program, as easy as Flash, will appear and will use stringent security protocols, secure memory management and decent speed along with restrained CPU access. It could happen! For all I know, such a Java app builder already exists. Please post a comment if you have related information.

In the meantime, I'm supported the death sentence for Adobe Flash.

Share and Enjoy,

:-Derek
--

Friday, 13 August 2010

Adobe Flash, AIR, PDF, Acrobat and Reader: Security Statistics Sources

--
Earlier today, I was helping out a reader at MacDailyNews.com who had the following question:
'BSOD' asks: "Does anyone have statistics on exactly how many security holes have been opened up by Flash, Air, and PDF? I think that we need to see that stat."
My answer is of general interest. Therefore, I am posting it here for your reading pleasure:
You can dig around at the CVE site for each of them. CVE stands for Common Vulnerabilities and Exposures. It keeps track of each reported software security problem:

http://cve.mitre.org/

Wikipedia.org also covers each of them and gives a general description of their security:

Adobe Flash: "As of May 17, 2010, The Flash Player has 77 CVE entries, 34 of which have been ranked with a high severity (leading to arbitrary code execution), and 40 ranked medium."

Adobe PDF: "On March 30, 2010 security researcher Didier Stevens reported an "exploit" that causes an arbitrary executable to be run when a PDF file is opened, after the user accepts a warning prompt. The exploit works in several different PDF viewers including Adobe Reader and Foxit Reader."

And, earlier this year Adobe were embarrassed into creating the Adobe Product Security Incident Response Tearm (PSIRT). You can keep up with their blog here:

http://blogs.adobe.com/psirt/

Adobe maintain their Security Bulletins and Advisories page, going back to 2005, here:

http://www.adobe.com/support/security/

� There are approximately 88 Adobe Flash security bulletins.
� There are 6 Adobe PDF security bulletins.
� There are over 100 Adobe Acrobat security bulletins.
� There are over 100 Adobe Reader security bulletins.
� The only Adobe AIR related bulletin is the Adobe Flash bulletin from June 10, 2010.

Wednesday, 11 August 2010

New CRITICAL Adobe Flash Player v10.1.82.76 & Adobe Air v2.0.3 Updates

--
Today Adobe updated Flash Player to version 10.1.82.76 and Adobe Air to version 2.0.3. The updates patch 6 CRITICAL security holes. Here are the security patch details:
Critical vulnerabilities have been identified in Adobe Flash Player version 10.1.53.64 and earlier. These vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system.

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-0209).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2188).

This update resolves multiple memory corruption vulnerabilities that could lead to code execution (CVE-2010-2213).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2214).

This update resolves a vulnerability that could lead to a click-jacking attack. (CVE-2010-2215).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2216).

Adobe recommends users of Adobe Flash Player 10.1.53.64 and earlier versions update to Adobe Flash Player 10.1.82.76. Adobe recommends users of Adobe AIR 2.0.2.12610 and earlier versions update to Adobe AIR 2.0.3.
The download links are provided on Adobe's Security Bulletin page HERE.

Lately, Adobe's Flash Player has been considered the most dangerous application for Mac OS X from a security point of view. It is important to keep track of ALL Adobe updates at this point in time. We are still waiting for NEW updates to Adobe Acrobat and Adobe Reader that patch security holes announced last week HERE.
--

Tuesday, 29 June 2010

They're Here!Adobe CRITICAL Updates:Acrobat & Reader & Flash Player

--
As promised, Adobe skipped their dopey 'quarterly' security update schedule and pushed out updates to Adobe Acrobat, Reader and Flash Player before the end of June. Gee thanks. Let's hope this incident puts the 'quarterly' security update stooopidity in the grave where it belongs.

Before I send you to the sources, I get to be a grumbling curmudgeon. Be warned that Adobe made the process of updating Adobe Acrobat, Reader and Flash Player yet-another PITA with a number of pages to click through to just download the things. So apparently, whoever made Adobe updating the most heinous process in the entire computer community, has not yet been fired from the company.
What A Shame.

For your pleasure, I have dug through the pages of Adobe bureaucratic garbage for you in order to provide direct download URLs:

Acrobat 9.3.3 Pro update

Adobe Reader 9.3.3 update for Intel Macs

Adobe Reader 9.3.3 update for PPC Macs

Adobe Flash Player 10.1.53.64

The simple URL for Flash Player is courtesy of my pals at VersionTracker.com

REMINDER: If you have installed the Mac OS X 10.6.4 update and/or Apple Security Update 2010-004, you have NOT NOT NOT updated to this CRITICAL latest version of Flash Player. Apple only included the old dangerous version. Thankfully, Apple's updater does not remove the newer version if you already installed it.

THEREFORE: If you haven't already, you must DIY install the Adobe Flash Player version 10.1.53.64. Apple won't do it for you. I don't know why! They just won't.
--

Thursday, 17 June 2010

Apple's Flash Player Plug-in Update Blunderin the 10.6.4 Update

--
According to MacFixIt.com, Apple made one big preventable blunder in the Mac OS X 10.6.4 update. They included the previous, exploited in-the-wild, version of the Adobe Flash plug-in, version 10.0.45.2. My guess is that this is the version they've been using in the beta of 10.6.4 and they neglected to swap in last week's security patched version 10.1.53.64. That's a very naughty oversight by Apple!

Therefore, if you have not done so already, go grab the very latest installer for the Adobe Flash Player, v10.1.53.64, and install it. Apple didn't give it to you! You can grab it HERE.

Thankfully, Apple's 10.6.4 update installer is smart enough not to remove the updated version of the Flash Player plug-in. Mine stayed intact.

Dear Apple. Considering the well deserved abuse Adobe have had to endure for their blundering crap programming, it would be advisable to avoid blunders of your own and keep up with Adobe's updates! Until this Flash plug-in version oversight happened, Adobe had no legitimate reason to criticize Apple. Now it looks like you're ignoring Adobe's meagre efforts to put things right again. That's not good. You've also needlessly endangered the security of your customers!

Meanwhile, keep an eye out for the Acrobat and Adobe Reader security patch updates that should be showing up any week now...
(o_0)
--

Saturday, 5 June 2010

New Adobe Security Holes:Get Pwned Via Flash Player, Acrobator Adobe Reader

--
RISK: CRITICAL
--

Adobe have posted a warning that current versions of Flash Player, Acrobat and Adobe Reader have a DANGEROUS security hole that is currently being exploited out in the wild. Here are some reading sources:

Security Advisory for Flash Player, Adobe Reader and Acrobat

Adobe Warns of Critical Flaw in Flash, Acrobat & Reader

The first article above is direct from Adobe. The second article is analysis by Brian Krebs, a professional computer security journalist.

NOT affected: Version 8.x of Acrobat and Adobe Reader. If you've got them, you can dig them out and use them safely.

You can keep track of the progress in patching this latest set of Adobe holes at either of these sites:

Adobe Security Bulletins and Advisories

Adobe Product Security Incident Response Team (PSIRT)

Because this set of security holes has been found to be exploited in the wild, I can only advise that you do NOT use any of the affected Adobe products with ANY files you encounter via the Internet.

1) Get a plugin for your web browser that TURNS OFF FLASH. (They are available for both WebKit and Mozilla based browsers). Use it and don't watch any Flash until a finished update is provided by Adobe.

2) Only open your own, or verified safe PDF files via Acrobat or Adobe Reader.

If you want to be super-duper safe, trash the Adobe Flash Plugin. You will find it here on your Mac:

/Library/Internet Plug-ins/Flash Player.plugin

Wait until the finished v10.1 Flash Player plugin has been released and install it at that time. The current unsafe Mac version of Adobe Flash Player is v10.0.45.2. When the finished version of Flash Player v10.1 is available, you will find it HERE.
--

Friday, 31 July 2009

Adobe Releases Security Patched Reader and Acrobat v9.1.3

--
As promised, on Friday, July 31, Adobe released security patched versions of Acrobat and Adobe Reader. The links in the previous article about the subject should get you started, but I've provided them again below.

NOTE: verify that you are downloading and installing versions 9.1.3 of Reader and Acrobat and not an earlier version. The download page for the Acrobat 9.1.3 update is clear regarding versions. However, the Acrobat Reader page is NOT. Therefore, after you download and install "the latest version" of Reader, go under the Help menu to "Check for Updates...". Otherwise you may have only installed an earlier version of Reader without the new security patches.

Those patch download links again:

1) Adobe Flash Player v10.0.32.18. There is a special patch for version 9 users to v9.0.246.0.

2) Adobe Air v1.5.2.

3) Adobe Reader v9.1.3.

4) Acrobat v9.1.3.

Glad to be of service!
--

Search