<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; flash player vulnerability</title> <atom:link href="http://www.ghacks.net/tag/flash-player-vulnerability/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 21:54:04 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Critical Adobe Reader And Flash Vulnerabilities Emerge</title><link>http://www.ghacks.net/2010/06/05/critical-adobe-reader-and-flash-vulnerabilities-emerge/</link> <comments>http://www.ghacks.net/2010/06/05/critical-adobe-reader-and-flash-vulnerabilities-emerge/#comments</comments> <pubDate>Sat, 05 Jun 2010 20:39:03 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[flash player vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=26221</guid> <description><![CDATA[Two new vulnerabilities affecting the Adobe products Adobe Reader and Adobe Flash were reported by Secunia earlier this day. They have in common that they have been both rated as extremely critical, the highest available severity rating for vulnerabilities posted at Secunia. Highly critical is a rating for &#8220;remotely exploitable vulnerabilities that can lead to [...]]]></description> <content:encoded><![CDATA[<p>Two new vulnerabilities affecting the Adobe products Adobe Reader and Adobe Flash were reported by <a
href="http://secunia.com/">Secunia</a> earlier this day. They have in common that they have been both rated as extremely critical, the highest available severity rating for vulnerabilities posted at Secunia.</p><p>Highly critical is a rating for &#8220;remotely exploitable vulnerabilities that can lead to system compromise&#8221; that usually do not &#8220;require any interaction&#8221; and where exploits are already in the wild.</p><p>The Adobe Flash vulnerability that has been reported is affecting Adobe Flash Player 10.x and Adobe Flash Player 9.x.</p><p><span
id="more-26221"></span><br
/><blockquote>A vulnerability has been reported in Adobe Flash Player, which can be exploited by malicious people to compromise a user&#8217;s system.</p><p>The vulnerability is caused due to an unspecified error. No more information is currently available.</p><p>Successful exploitation allows execution of arbitrary code.</p><p>The vulnerability is reported in version 10.0.45.2 and prior 10.0.x and 9.0.x versions for Windows, Macintosh, Linux, and Solaris.</p><p>NOTE: The vulnerability is reportedly being actively exploited.</p></blockquote><p>The release candidate of the upcoming Adobe Flash Player 10.1 does not seem to be affected by the vulnerability according to the information <a
href="http://secunia.com/advisories/40026">at</a> the Secunia website.</p><p>Users who want to protect their computer system from being exploited by the vulnerability can either disable Adobe Flash for the time being or <a
href="http://labs.adobe.com/downloads/flashplayer10.html">update to</a> the Adobe Flash Player 10.1 Release Candidate. Additional information about the vulnerability are posted in a Security Bulletin <a
href="http://www.adobe.com/support/security/advisories/apsa10-01.html">at the</a> Adobe website.</p><p>The Adobe Reader and Adobe Acrobat vulnerability might be related to the Adobe Flash vulnerability. The <a
href="http://secunia.com/advisories/40034">Secunia Advisory</a> lists Adobe Reader 9 versions for Windows, Macintosh and Linux as affected by the vulnerability.</p><blockquote><p>The vulnerability is caused due to a vulnerable bundled version of Flash Player (authplay.dll).Successful exploitation allows execution of arbitrary code.</p><p>The vulnerability is reported in version 9.3.2 and earlier 9.x versions for Windows, Macintosh, and UNIX.</p><p>NOTE: The vulnerability is currently being actively exploited.</p></blockquote><p>The temporary solution to protect the computer system from the exploits is to delete, rename or remove access to autoplay.dll to prevent Flash content from being executed in Adobe Reader and Acrobat.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/06/05/critical-adobe-reader-and-flash-vulnerabilities-emerge/feed/</wfw:commentRss> <slash:comments>7</slash:comments> </item> <item><title>Adobe Reader, Acrobat and Flash Player Zero Day Vulnerability</title><link>http://www.ghacks.net/2009/07/24/adobe-reader-acrobat-and-flash-player-zero-day-vulnerability/</link> <comments>http://www.ghacks.net/2009/07/24/adobe-reader-acrobat-and-flash-player-zero-day-vulnerability/#comments</comments> <pubDate>Fri, 24 Jul 2009 14:08:36 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[acrobat]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe reader vulnerability]]></category> <category><![CDATA[adobe vulnerability]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[flash player vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=14724</guid> <description><![CDATA[Adobe has issued a security advisory that describes a critical vulnerability in the current versions of Adobe Reader, Acrobat and Flash Player. The vulnerability &#8220;could cause a crash and potentially allow an attacker to take control of the affected system&#8221;. Adobe&#8217;s Flash Player seems to be affected completely while the file authplay.dll is the reason [...]]]></description> <content:encoded><![CDATA[<p><img
src="http://www.ghacks.net/wp-content/uploads/2009/05/adobe.jpg" alt="adobe" title="adobe" width="100" height="100" class="alignleft size-full wp-image-13093" />Adobe has issued a security advisory <a
href="http://www.adobe.com/support/security/advisories/apsa09-03.html">that</a> describes a critical vulnerability in the current versions of Adobe Reader, Acrobat and Flash Player. The vulnerability &#8220;could cause a crash and potentially allow an attacker to take control of the affected system&#8221;. Adobe&#8217;s Flash Player seems to be affected completely while the file authplay.dll is the reason for the vulnerability affecting Adobe Reader and Acrobat as well. Adobe mentioned that the vulnerability is already exploited in the wild via targeted attacks against users running a Windows operating system and Adobe Reader 9.</p><p>Apple Mac and Unix systems are affected by the vulnerability as well but the exploit that is currently in the wild is only affecting Windows. Adobe suggests to enable UAC in Windows Vista (and Windows 7). Windows XP users should consider moving or deleting authplay.dll to protect their computer system from the threat against Adobe Reader and Acrobat &#8220;but users will experience a non-exploitable crash or error message when opening a PDF that contains SWF content&#8221;.</p><p><span
id="more-14724"></span>An alternative would be to uninstall Adobe Reader or Acrobat and install one of the available third party pdf readers like <a
href="http://www.ghacks.net/2008/04/26/foxit-reader-23/">Foxit Reader</a> or <a
href="http://www.ghacks.net/2008/03/01/goodbye-adobe-reader-hello-sumatra/">Sumatra</a>.</p><p>Adobe does not offer any advise on the Flash Player vulnerability. The only viable option seems to be to disable or even uninstall Flash and wait for the patch which is expected to be released on July 30 and July 31.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/07/24/adobe-reader-acrobat-and-flash-player-zero-day-vulnerability/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> </channel> </rss>
