Archive for June, 2010

Security updates released for Adobe Reader and Acrobat

Today, a Security Bulletin has been posted in regards to this quarter’s security updates for Adobe Reader and Acrobat. The updates address critical security issues in the products, including CVE-2010-1297 referenced in Security Advisory APSA10-01. Adobe recommends that users apply the updates for their product installations.
Note that today’s updates represent an accelerated release of this quarter’s security update originally scheduled for July 13, 2010. With this accelerated release, Adobe will not release additional updates for Adobe Reader and Acrobat on July 13, 2010. For more information on this update, please see the Adobe Reader blog.
This posting is provided “AS IS” with no warranties and confers no rights.

Pre-Notification – Quarterly Security Updates for Adobe Reader and Acrobat

A Security Advisory has been posted in regards to the upcoming Adobe Reader and Acrobat updates scheduled for June 29, 2010. The updates will address critical security issues in the products, including CVE-2010-1297 referenced in Security Advisory APSA10-01. These security updates will be made available for Windows, Macintosh and UNIX.
Note that the June 29, 2010 updates represent an accelerated release of the next quarterly security update originally scheduled for July 13, 2010. With this accelerated schedule, Adobe will not release additional updates for Adobe Reader and Acrobat on July 13, 2010.
We will continue to provide updates on the upcoming release via the Security Advisory section of the Adobe web site as well as the Adobe PSIRT blog.
This posting is provided “AS IS” with no warranties and confers no rights.

Apple Security Update 2010-004 / Mac OS X v10.6.4 Shipping with Outdated Version of Adobe Flash Player

Earlier today, Apple released security update 2010-004 / Mac OS X v10.6.4. This update includes an earlier version of Adobe Flash Player (version 10.0.45.2) than available from Adobe.com. While the Mac OS X v10.6.4 update does not appear to downgrade users who have already upgraded to Adobe Flash Player 10.1, Adobe recommends users verify they are using the latest, most secure version of Flash Player (10.1.53.64) available for download from http://www.adobe.com/go/getflashplayer.
To verify the Adobe Flash Player version number installed on your system (after applying the Mac OS X security update), access the About Flash Player page, or right-click on content running in Flash Player and select “About Adobe Flash Player” from the menu. If you use multiple browsers, checking on any one browser will verify the update for all browsers on Macintosh systems (on Windows, perform the check for each browser you have installed on your system).
This posting is provided “AS IS” with no warranties and confers no rights.

Security Bulletin – Adobe Flash Player

Today, a Security Bulletin has been posted to address critical security issues in Adobe Flash Player, including CVE-2010-1297, referenced in Security Advisory APSA10-01. This Security Bulletin affects Flash Player versions 10.0.45.2 and earlier, as well as AIR versions 1.5.3.9130 and earlier. Adobe recommends users apply the updates for their product installations.
This posting is provided “AS IS” with no warranties and confers no rights.

Update to Security Advisory for Adobe Reader, Acrobat and Flash Player

We’ve just updated the Security Advisory posted on Friday to include the planned schedule for a patch to resolve CVE-2010-1297. Adobe plans to make available an update for Flash Player 10.x for Windows, Macintosh, and Linux by June 10, 2010. The date for Flash Player 10 for Solaris is still to be determined. We expect to provide an update for Adobe Reader and Acrobat 9.3.2 for Windows, Macintosh and UNIX by June 29, 2010. Please note that the Acrobat and Reader update represents an accelerated release of the next quarterly security update originally scheduled for July 13, 2010. With this accelerated scheduled we do not plan to release any new updates for Adobe Reader and Acrobat on July 13, 2010.
We will continue to provide updates on this issue via the Security Advisory section of the Adobe website, as well as the Adobe PSIRT blog.
This posting is provided “AS IS” with no warranties and confers no rights.

Security Advisory for Flash Player, Adobe Reader and Acrobat

A Security Advisory has been posted in regards to a new Adobe Reader, Acrobat and Flash Player issue (CVE-2010-1297). A critical vulnerability exists in Flash Player 10.0.45.2 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems, and the authplay.dll component that ships with Adobe Reader and Acrobat 9.x for Windows, Macintosh and UNIX operating systems. This vulnerability could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against both Adobe Flash Player, and Adobe Reader and Acrobat.
The Flash Player 10.1 Release Candidate available on http://labs.adobe.com/technologies/flashplayer10/ does not appear to be vulnerable.
Adobe Reader and Acrobat 8.x are confirmed not vulnerable. Mitigations for Adobe Reader and Acrobat 9.x are included in the Security Advisory.
We will continue to provide updates on this issue via the Security Advisory section of the Adobe website, as well as the Adobe PSIRT blog.
This posting is provided “AS IS” with no warranties and confers no rights.