<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; adobe vulnerability</title> <atom:link href="http://www.ghacks.net/tag/adobe-vulnerability/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 09:52:46 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Adobe Updates Security Advisory, Promises Patches Soon</title><link>http://www.ghacks.net/2010/06/08/adobe-updates-security-advisory-promises-patches-soon/</link> <comments>http://www.ghacks.net/2010/06/08/adobe-updates-security-advisory-promises-patches-soon/#comments</comments> <pubDate>Tue, 08 Jun 2010 08:04:07 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe vulnerability]]></category> <category><![CDATA[flash player]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=26314</guid> <description><![CDATA[Critical vulnerabilities that affected Adobe&#8217;s flagship products Adobe Reader, Acrobat and Flash Player were revealed in a security advisory by the Adobe Product Incident Response Team. The vulnerability affects Flash Player 10 and 9 as well as Adobe Reader 9 and Acrobat 9 which covers the majority of the install base. The vulnerabilities received a [...]]]></description> <content:encoded><![CDATA[<p><a
href="http://www.ghacks.net/2010/06/05/critical-adobe-reader-and-flash-vulnerabilities-emerge/">Critical vulnerabilities</a> that affected Adobe&#8217;s flagship products Adobe Reader, Acrobat and Flash Player were revealed in a security advisory by the Adobe Product Incident Response Team. The vulnerability affects Flash Player 10 and 9 as well as Adobe Reader 9 and Acrobat 9 which covers the majority of the install base.</p><p>The vulnerabilities received a severity rating of highly critical, the highest possible rating, by Secunia since they were both actively exploited and would allow remote code execution on affected computer systems.</p><p><span
id="more-26314"></span>Adobe&#8217;s Response Team has <a
href="http://www.adobe.com/support/security/advisories/apsa10-01.html">updated</a> the security vulnerability with the planned schedule for a patch to resolve the issue.</p><p>According to those information a patch for Flash Player 10 will be released on June 10 while Adobe Reader and Acrobat 9 users have to wait until June 29 for the patch.</p><p>The patches will be made available for all supported operating systems with the exception of Flash Player for Solaris.</p><p>The delay until the page becomes available is bad news for Adobe Reader and Acrobat users who have to find ways to protect their systems from the security vulnerability in the meantime.</p><p>Adobe is offering mitigation instructions on their website for Windows, Unix and Macintosh.</p><p>Adobe Reader and Acrobat &#8211; Windows</p><blockquote><p>Deleting, renaming, or removing access to the authplay.dll file that ships with Adobe Reader 9.x and Acrobat 9.x mitigates the threat for those products, but users will experience a non-exploitable crash or error message when opening a PDF file that contains SWF content.</p><p>The authplay.dll that ships with Adobe Reader 9.x and Acrobat 9.x for Windows is typically located at C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll for Adobe Reader or C:\Program Files\Adobe\Acrobat 9.0\Acrobat\authplay.dll for Acrobat.</p></blockquote><p>Adobe Reader 9.x &#8211; Macintosh</p><blockquote><p>1) Go to the Applications->Adobe Reader 9 folder.<br
/> 2) Right Click on Adobe Reader<br
/> 3) Select Show Package Contents<br
/> 4) Go to the Contents->Frameworks folder<br
/> 5) Delete or move the AuthPlayLib.bundle file</p></blockquote><p>Acrobat Pro 9.x &#8211; Macintosh</p><blockquote><p>1) Go to the Applications->Adobe Acrobat 9 Pro folder.<br
/> 2) Right Click on Adobe Acrobat Pro<br
/> 3) Select Show Package Contents<br
/> 4) Go to the Contents->Frameworks folder<br
/> 5) Delete or move the AuthPlayLib.bundle file</p></blockquote><p>Adobe Reader 9.x- UNIX</p><blockquote><p>1) Go to installation location of Reader (typically a folder named Adobe)<br
/> 2) Within it browse to Reader9/Reader/intellinux/lib/ (for Linux) or Reader9/Reader/intelsolaris/lib/ (for Solaris)<br
/> 3) Remove the library named &#8220;libauthplay.so.0.0.0&#8243;</p></blockquote><p>It is recommended to either perform the operations on affected computer systems or switch to another pdf reader at least for the time until the vulnerability gets fixed.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/06/08/adobe-updates-security-advisory-promises-patches-soon/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Another Adobe Reader Zero Day Vulnerability In The Wild</title><link>http://www.ghacks.net/2009/12/15/another-adobe-reader-zero-day-vulnerability-in-the-wild/</link> <comments>http://www.ghacks.net/2009/12/15/another-adobe-reader-zero-day-vulnerability-in-the-wild/#comments</comments> <pubDate>Tue, 15 Dec 2009 17:02:23 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[adobe vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=21459</guid> <description><![CDATA[Adobe Reader and Adobe Acrobat have been hit with yet another zero day vulnerability that is affecting all versions of both programs up to Adobe Reader and Adobe Acrobat 9.2. The vulnerability has been disclosed to the public by Adobe&#8217;s Security Response team who wrote in their blog that they &#8220;are currently investigating this issue [...]]]></description> <content:encoded><![CDATA[<p>Adobe Reader and Adobe Acrobat have been hit with yet another zero day vulnerability that is affecting all versions of both programs up to Adobe Reader and Adobe Acrobat 9.2. The vulnerability has been disclosed to the public by Adobe&#8217;s Security Response team <a
href="http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html">who</a> wrote in their blog that they &#8220;are currently investigating this issue and assessing the risk to [their] customers&#8221;.</p><p>Adobe itself did not reveal details about the exploit in the blog post but a post at the Shadowserver website which is run by security volunteers from around the world. According to information posted on <a
href="http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214">their</a> website the exploit has been in the wild since at least December 11. The number of attacks have been limited and targeted so far according to their information. They do expect the &#8220;exploit to become more wide spread in the next few weeks&#8221; with the potential to become fully public in the same timeframe.</p><p><span
id="more-21459"></span>The security researchers did not want to reveal all the information about the vulnerability but mentioned that it was found in the JavaScript function in Adobe Acrobat and Adobe Reader.</p><blockquote><p>With that said we can tell you that this vulnerability is actually in a JavaScript function within Adobe Acrobat [Reader] itself. Furthermore the vulnerable JavaScript is obfuscated inside a zlib stream making universal detection and intrusion detection signatures much more difficult. On the bright side though, there are some solutions to this problem.</p></blockquote><p>A temporary fix was also published on the same website.</p><blockquote><p>We have said it before and we will say it again: Disable JavaScript.</p><p>Disabling JavaScript is easy. This is how it can be done in Acrobat Reader:<br
/> Click: Edit -> Preferences -> JavaScript and uncheck Enable Acrobat JavaScript</p><p>We have not had time to fully test but enabling hardware DEP for systems that support it may also mitigate this issue.</p></blockquote><p>Adobe users are encouraged to disable JavaScript as soon as possible to block their version of the program from being vulnerable.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/12/15/another-adobe-reader-zero-day-vulnerability-in-the-wild/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Adobe Reader, Acrobat and Flash Player Zero Day Vulnerability</title><link>http://www.ghacks.net/2009/07/24/adobe-reader-acrobat-and-flash-player-zero-day-vulnerability/</link> <comments>http://www.ghacks.net/2009/07/24/adobe-reader-acrobat-and-flash-player-zero-day-vulnerability/#comments</comments> <pubDate>Fri, 24 Jul 2009 14:08:36 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[acrobat]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <category><![CDATA[adobe vulnerability]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[flash player vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=14724</guid> <description><![CDATA[Adobe has issued a security advisory that describes a critical vulnerability in the current versions of Adobe Reader, Acrobat and Flash Player. The vulnerability &#8220;could cause a crash and potentially allow an attacker to take control of the affected system&#8221;. Adobe&#8217;s Flash Player seems to be affected completely while the file authplay.dll is the reason [...]]]></description> <content:encoded><![CDATA[<p><img
src="http://www.ghacks.net/wp-content/uploads/2009/05/adobe.jpg" alt="adobe" title="adobe" width="100" height="100" class="alignleft size-full wp-image-13093" />Adobe has issued a security advisory <a
href="http://www.adobe.com/support/security/advisories/apsa09-03.html">that</a> describes a critical vulnerability in the current versions of Adobe Reader, Acrobat and Flash Player. The vulnerability &#8220;could cause a crash and potentially allow an attacker to take control of the affected system&#8221;. Adobe&#8217;s Flash Player seems to be affected completely while the file authplay.dll is the reason for the vulnerability affecting Adobe Reader and Acrobat as well. Adobe mentioned that the vulnerability is already exploited in the wild via targeted attacks against users running a Windows operating system and Adobe Reader 9.</p><p>Apple Mac and Unix systems are affected by the vulnerability as well but the exploit that is currently in the wild is only affecting Windows. Adobe suggests to enable UAC in Windows Vista (and Windows 7). Windows XP users should consider moving or deleting authplay.dll to protect their computer system from the threat against Adobe Reader and Acrobat &#8220;but users will experience a non-exploitable crash or error message when opening a PDF that contains SWF content&#8221;.</p><p><span
id="more-14724"></span>An alternative would be to uninstall Adobe Reader or Acrobat and install one of the available third party pdf readers like <a
href="http://www.ghacks.net/2008/04/26/foxit-reader-23/">Foxit Reader</a> or <a
href="http://www.ghacks.net/2008/03/01/goodbye-adobe-reader-hello-sumatra/">Sumatra</a>.</p><p>Adobe does not offer any advise on the Flash Player vulnerability. The only viable option seems to be to disable or even uninstall Flash and wait for the patch which is expected to be released on July 30 and July 31.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/07/24/adobe-reader-acrobat-and-flash-player-zero-day-vulnerability/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Adobe Reader and Acrobat Critical Security Update</title><link>http://www.ghacks.net/2008/06/25/adobe-reader-and-acrobat-critical-security-update/</link> <comments>http://www.ghacks.net/2008/06/25/adobe-reader-and-acrobat-critical-security-update/#comments</comments> <pubDate>Wed, 25 Jun 2008 13:48:51 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[adobe vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=5107</guid> <description><![CDATA[Adobe has released a security update for its products Adobe Reader and Adobe Acrobat for both Microsoft Windows and Apple Macintosh that closes one critical security vulnerability. Affected versions are Adobe Reader 8.0 through 8.1.2, Adobe Reader 7.0.9 and earlier, Adobe Acrobat Professional, 3D and Standard 8.0 through 8.1.2 and Adobe Acrobat Professional, 3D and [...]]]></description> <content:encoded><![CDATA[<p>Adobe has released a security update for its products Adobe Reader and Adobe Acrobat for both Microsoft Windows and Apple Macintosh that closes one critical security vulnerability. Affected versions are Adobe Reader 8.0 through 8.1.2, Adobe Reader 7.0.9 and earlier, Adobe Acrobat Professional, 3D and Standard 8.0 through 8.1.2 and Adobe Acrobat Professional, 3D and Standard 7.0.9 and earlier.</p><p>Adobe Reader 9 and Acrobat 9 as well as Adobe Reader 7.1.0 and Acrobat 7.1.0 are not affected by the security vulnerability. The vulnerability causes the applications to crash which can allow an attacker to take control of the host system.</p><p>Downloads are available that fix the security vulnerability in Adobe Reader 8 for <a
href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3967">Windows</a> and <a
href="http://www.adobe.com/support/downloads/detail.jsp?ftpID=3966">Macintosh</a> computers. Take a look at the security bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb08-15.html">issued</a> by Adobe if you are using Adobe Acrobat or a previous version of one of the products to find the links pointing to updates for your product.</p><p><span
id="more-5107"></span></p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/06/25/adobe-reader-and-acrobat-critical-security-update/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> </channel> </rss>
