New 0-day vulnerability in Adobe´s Flash Player, Reader & Acrobat

hackerman1

Expelled
New 0-day vulnerability in Adobe´s Flash Player, Reader & Acrobat

hi !

i got a flash-message from SITIC, (the Swedish IT-Incident Center), there is a new 0-day vulnerability in Adobe´s Flash Player, Reader & Acrobat !

info from Adobe:
"Security Advisory for Flash Player, Adobe Reader and Acrobat

Release date: June 4, 2010
Vulnerability identifier: APSA10-01
CVE number: CVE-2010-1297
Platform: All
Summary

A critical vulnerability exists in Adobe Flash Player 10.0.45.2 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems, and the authplay.dll component that ships with Adobe Reader and Acrobat 9.x for Windows, Macintosh and UNIX operating systems. This vulnerability (CVE-2010-1297) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against both Adobe Flash Player, and Adobe Reader and Acrobat. This advisory will be updated once a schedule has been determined for releasing a fix."


Adobe - Security Advisories: Security Advisory for Flash Player, Adobe Reader and Acrobat
Adobe Flash Player, Acrobat Reader, and Acrobat 'authplay.dll' Remote Code Execution Vulnerability
Security Advisory for Flash Player, Adobe Reader and Acrobat - Adobe Product Security Incident Response Team (PSIRT)

yet another reason not to use Adobe PDF-reader...

there are several other FREE PDF-readers available:
PDFreaders.org - Get a Free Software PDF reader!

fx. Sumatra is working very well, i´ve used it for several weeks now.

 

My Computer

Computer Manufacturer/Model Number
Dell
OS
W7-Enterprise + WS-2008 (Converted to Workstation)
CPU
P4 2,4GHz (at 1,8GHz, "slow" RDRAM, only 400MHz FSB...)
Motherboard
Intel 850E
Memory
2GB
Graphics Card(s)
NVIDIA QUADRO2 PRO 64MB
Sound Card
Yes
Monitor(s) Displays
Dell 1702FP
Screen Resolution
1280x1024
Hard Drives
Yes
PSU
Yes
Case
Yes
Cooling
Yes
Keyboard
Yes
Mouse
Yes, and i also have Cats...
Internet Speed
University: 100 MBit/s, Home: UMTS 7,2 MBit/s
Other Info
W7 on a DINOSAUR: P2 with 266MHz CPU & 160MB RAM
In this case, the problem is Adobe Flash more than Adobe/Acrobat Reader. Although the vulnerability can also be vectored through malicious PDF files to invoke FLASH, merely replacing Adobe Reader with another PDF reader is not the solution because malicious Flash files are not limited to PDF format. My recommendations: Adobe Flash/Reader Vulnerability Mitigation Options.
 

My Computer

OS
Windows 7 & Windows Vista Ultimate
Back
Top