Critical vulnerability found in Adobe Flash Player

    Critical vulnerability found in Adobe Flash Player


    Posted: 27 Jul 2009
    Adobe has posted a security advisory for Adobe Reader, Acrobat and Flash Player. The company states that a critical vulnerability is present in the current versions of Flash Player (v9.0.159.0 and v10.0.22.87) for Windows, Macs and UNIX operating systems and the authplay.dll component that ships with Adobe Reader and Acrobat v9.x on the same operating systems.
    more..
    Airbot's Avatar Posted By: Airbot
    27 Jul 2009



  1. Posts : 13
    w 7
       #1

    many thanks mate for the great info
      My Computer


  2. Posts : 344
    Windows 7™ Home Premium x64/Sony PS3 XrossMediaBar™ FW 3.30/Sony PSP XrossMediaBar™ FW 6.20
       #2

    Adobe really needs to rewrite Flash and Shockwave from the ground-up now...

    Especially Flash since you need a dual-core PC to actually view Flash videos without the annoying buffering in YouTube, especially on Windows XP.

    On the otherhand, I can view Silverlight content perfectly smooth and clear on the same XP PC...
      My Computer


  3. Posts : 4,925
    Windows 7 Professional 64-bit
       #3

    Sites really need to start adopting silverlight.
      My Computer


  4. Posts : 301
    Windows 7 Home Premium
       #4

    how do you make silverlight your default player thing? can you make it your default it firefox?
      My Computer


  5. Posts : 2,899
    Windows 7 Ult x64(x2), HomePrem x32(x4), Server 08 (+VM), 08 R2 (VM) , SuSe 11.2 (VM), XP 32 (VM)
       #5

    from what i know they are different formats and so they are not compatible...
    as for me yes i hate the fact that the its forced me to run with High performance just to play youtube (with being able to play 720p and 1080p content through DXVA at power saver or balanced...) which i really hate...

    and thanks for the update
    thats why i love flashblock....
      My Computer


  6. Posts : 17
    Windows 7
       #6

    Adobe Product Security Incident Response Team (PSIRT)

    We evaluated the impact of the vulnerable versions of the Microsoft Active Template Library (ATL) / CVE-2009-0901, CVE-2009-2395, CVE-2009-2493 / Microsoft Security Advisory (973882) on the Adobe product portfolio. We determined that Flash Player and Shockwave Player are the two products that leverage vulnerable versions of ATL. A Security Advisory for Flash Player and a Security Bulletin for Shockwave Player have been posted to our security bulletins and advisories page.
    PSIRT has determined that the Adobe Reader browser plug-in for Internet Explorer, Connect Pro, Flash Lite for mobile devices, LiveCycle SAP Forms and other products are NOT vulnerable to CVE-2009-0901, CVE-2009-2395, or CVE-2009-2493.
    Note that only Internet Explorer plug-ins are vulnerable. Thus, people using Flash Player within the Firefox browser -- as well as all other Windows-based browsers (that aren't Internet Explorer) -- are not vulnerable. Additionally, Flash Player and Shockwave Player on Macintosh, Linux and Solaris operating systems are not vulnerable.
    Per the Shockwave Player Security Bulletin, this vulnerability has been patched in the latest version of Shockwave Player, which is now available for download (Adobe - Adobe Shockwave Player). Per the Security Advisory for Flash Player, this vulnerability will be patched in the scheduled July 30, 2009 update of Flash Player.
    Users should consider installing MS09-034. As a defense-in-depth measure, this Internet Explorer security update helps mitigate known attack vectors within Internet Explorer for those components and controls, such as Flash Player and Shockwave Player, that have been developed with vulnerable versions of ATL as described in Microsoft Security Advisory (973882) and Microsoft Security Bulletin MS09-035.
    We will continue to provide updates on this issue via the Security Advisory section of the Adobe web site, as well as the Adobe PSIRT blog.
    This posting is provided "AS IS" with no warranties and confers no rights.
    Bold added by me.

    This is reassuring. Lately I've taken to not installing any plug-ins into IE. I use it mainly to only check links for problems.
      My Computer


  7. Posts : 237
    Windows 7 Home Premium x64 - SP1
       #7

    darkassain said:
    and thanks for the update
    thats why i love flashblock....
    Agreed.......and "No Scripts", .....two x milli-second, stop and thinks!
      My Computer


  8. Posts : 1,289
       #8

    Babel17 said:
    This is reassuring. Lately I've taken to not installing any plug-ins into IE. I use it mainly to only check links for problems.
    That ATL bug affects millions of developed applications not just Flash, flashblock and NoScript will not save you from this one
      My Computer

  9.   My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 03:55.
Find Us