<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>Adobe Product Security Incident Response Team (PSIRT)</title>
    <link rel="alternate" type="text/html" href="http://blogs.adobe.com/psirt/" />
    <link rel="self" type="application/atom+xml" href="http://blogs.adobe.com/psirt/atom.xml" />
    <id>tag:blogs.adobe.com,2009-08-05:/psirt/176</id>
    <updated>2010-01-29T16:12:10Z</updated>
    <subtitle>Working to help protect customers from vulnerabilities in Adobe software. Contact us at PSIRT@adobe.com.</subtitle>
    <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.261</generator>

<entry>
    <title>Security Bulletin - ColdFusion</title>
    <link rel="alternate" type="text/html" href="http://blogs.adobe.com/psirt/2010/01/security_bulletin_-_coldfusion_1.html" />
    <id>tag:blogs.adobe.com,2010:/psirt//176.45203</id>

    <published>2010-01-29T16:10:00Z</published>
    <updated>2010-01-29T16:12:10Z</updated>

    <summary>A Security Bulletin was posted today providing a solution to an important security issue in ColdFusion. This posting is provided &quot;AS IS&quot; with no warranties and confers no rights....</summary>
    <author>
        <name>Wendy Poland</name>
        
    </author>
    
        <category term="Security Bulletins and Advisories" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://blogs.adobe.com/psirt/">
        <![CDATA[<p>A <a href="http://www.adobe.com/support/security/bulletins/apsb10-04.html">Security Bulletin</a> was posted today providing a solution to an <a href="http://www.adobe.com/devnet/security/security_zone/severity_ratings.html">important</a> security issue in ColdFusion.</p>

<p><strong>This posting is provided "AS IS" with no warranties and confers no rights.</strong></p>]]>
        
    </content>
</entry>

<entry>
    <title>Security Bulletin - Adobe Shockwave Player</title>
    <link rel="alternate" type="text/html" href="http://blogs.adobe.com/psirt/2010/01/security_bulletin_-_adobe_shoc_1.html" />
    <id>tag:blogs.adobe.com,2010:/psirt//176.45044</id>

    <published>2010-01-19T21:53:00Z</published>
    <updated>2010-01-19T21:53:12Z</updated>

    <summary>A Security Bulletin was posted today addressing critical security issues in Adobe Shockwave Player. This posting is provided &quot;AS IS&quot; with no warranties and confers no rights....</summary>
    <author>
        <name>Wendy Poland</name>
        
    </author>
    
        <category term="Security Bulletins and Advisories" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://blogs.adobe.com/psirt/">
        <![CDATA[<p>A <a href="http://www.adobe.com/go/apsb10-03">Security Bulletin</a> was posted today addressing <a href="http://www.adobe.com/devnet/security/security_zone/severity_ratings.html">critical</a> security issues in Adobe Shockwave Player.</p>

<p><strong>This posting is provided "AS IS" with no warranties and confers no rights.</strong></p>]]>
        
    </content>
</entry>

<entry>
    <title>Security update released for Adobe Reader and Acrobat</title>
    <link rel="alternate" type="text/html" href="http://blogs.adobe.com/psirt/2010/01/security_update_released_for_a.html" />
    <id>tag:blogs.adobe.com,2010:/psirt//176.44947</id>

    <published>2010-01-12T23:27:12Z</published>
    <updated>2010-01-12T23:28:04Z</updated>

    <summary>Today a Security Bulletin has been posted in regards to the January 12, 2010 quarterly security update for Adobe Reader and Acrobat. The update addresses critical security issues in the products, including a patch to resolve CVE-2009-4324 previously discussed in...</summary>
    <author>
        <name>David Lenoe</name>
        
    </author>
    
        <category term="Security Bulletins and Advisories" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://blogs.adobe.com/psirt/">
        <![CDATA[<p>Today a <a href="http://www.adobe.com/go/apsb10-02/">Security Bulletin</a> has been posted in regards to the January 12, 2010 quarterly security update for Adobe Reader and Acrobat.  The update addresses <a href="http://www.adobe.com/devnet/security/security_zone/severity_ratings.html">critical </a>security issues in the products, including a patch to resolve CVE-2009-4324 previously discussed in the Adobe PSIRT blog on December 15, 2009 ("<a href="http://blogs.adobe.com/psirt/2009/12/security_advisory_apsa09-07_up.html">Security Advisory APSA09-07 update</a>").  Adobe recommends that users apply the updates for their product installations.  Please note that support has <a href="http://blogs.adobe.com/adobereader/2009/12/adobe_reader_and_acrobat_versi.html">ended for Adobe Reader 7.x and Acrobat 7.x for Windows, Macintosh and UNIX, and Adobe Reader 8.x for UNIX</a>.</p>

<p>For more information on other security enhancements included in this update, please refer to the <a href="http://blogs.adobe.com/adobereader/">Adobe Reader blog</a>.<br />
<strong><br />
This posting is provided "AS IS" with no warranties and confers no rights.</strong><br />
</p>]]>
        
    </content>
</entry>

<entry>
    <title>Microsoft Security Advisory (979267)</title>
    <link rel="alternate" type="text/html" href="http://blogs.adobe.com/psirt/2010/01/microsoft_security_advisory_97.html" />
    <id>tag:blogs.adobe.com,2010:/psirt//176.44941</id>

    <published>2010-01-12T20:27:03Z</published>
    <updated>2010-01-12T20:26:26Z</updated>

    <summary>Microsoft Windows XP redistributes an earlier version of Adobe Flash Player (version 6) that is no longer supported. Adobe discontinued support for Adobe Flash Player 6 in 2006. As always, Adobe recommends that users follow security best practices by updating...</summary>
    <author>
        <name>David Lenoe</name>
        
    </author>
    
    
    <content type="html" xml:lang="en" xml:base="http://blogs.adobe.com/psirt/">
        <![CDATA[<p>Microsoft Windows XP redistributes an earlier version of Adobe Flash Player (version 6) that is no longer supported. Adobe discontinued support for Adobe Flash Player 6 in 2006. As always, Adobe recommends that users follow security best practices by updating to the latest, most secure version of Adobe Flash Player (currently version 10.0.42.34), which is available for download from the <a href="http://get.adobe.com/flashplayer/">Adobe Flash Player Download Center</a>. (See also <a href="http://www.microsoft.com/technet/security/advisory/979267.mspx">Microsoft Security Advisory 979267</a> on this topic.)</p>

<p><strong>This posting is provided "AS IS" with no warranties and confers no rights.</strong><br />
</p>]]>
        
    </content>
</entry>

<entry>
    <title>Security Bulletin - Adobe Illustrator CS4 and Adobe Illustrator CS3</title>
    <link rel="alternate" type="text/html" href="http://blogs.adobe.com/psirt/2010/01/security_bulletin_-_adobe_illu.html" />
    <id>tag:blogs.adobe.com,2010:/psirt//176.44867</id>

    <published>2010-01-07T19:15:52Z</published>
    <updated>2010-01-07T19:14:48Z</updated>

    <summary>A Security Bulletin has been posted in regards to the Adobe Illustrator issue last discussed in the Adobe PSIRT blog on December 7, 2009 (&quot;Security Advisory for Adobe Illustrator CS4 and Adobe Illustrator CS3&quot;, CVE-2009-4195). Adobe recommends Adobe Illustrator CS4...</summary>
    <author>
        <name>David Lenoe</name>
        
    </author>
    
        <category term="Security Bulletins and Advisories" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://blogs.adobe.com/psirt/">
        <![CDATA[<p>A <a href="http://www.adobe.com/go/apsb10-01">Security Bulletin</a> has been posted in regards to the Adobe Illustrator issue last discussed in the Adobe PSIRT blog on December 7, 2009 ("<a href="http://blogs.adobe.com/psirt/2009/12/security_advisory_for_adobe_il.html">Security Advisory for Adobe Illustrator CS4 and Adobe Illustrator CS3</a>", CVE-2009-4195).  Adobe recommends Adobe Illustrator CS4 and Adobe Illustrator CS3 customers update their installations in line with security best practices.  </p>

<p><strong>This posting is provided "AS IS" with no warranties and confers no rights.</strong><br />
</p>]]>
        
    </content>
</entry>

<entry>
    <title>Pre-Notification - Quarterly Security Update for Adobe Reader and Acrobat</title>
    <link rel="alternate" type="text/html" href="http://blogs.adobe.com/psirt/2010/01/pre-notification_-_quarterly_s_1.html" />
    <id>tag:blogs.adobe.com,2010:/psirt//176.44868</id>

    <published>2010-01-07T19:14:00Z</published>
    <updated>2010-01-07T19:14:20Z</updated>

    <summary>A Security Advisory has been posted in regards to the upcoming Adobe Reader and Acrobat updates scheduled for January 12, 2010. The updates will address critical security issues in the products, including a critical vulnerability in Adobe Reader and Acrobat...</summary>
    <author>
        <name>Wendy Poland</name>
        
    </author>
    
        <category term="Security Bulletins and Advisories" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://blogs.adobe.com/psirt/">
        <![CDATA[<p>A <a href="http://www.adobe.com/go/apsb10-02">Security Advisory</a> has been posted in regards to the upcoming Adobe Reader and Acrobat updates scheduled for January 12, 2010.  The updates will address <a href="http://www.adobe.com/devnet/security/security_zone/severity_ratings.html">critical</a> security issues in the products, including a critical vulnerability in Adobe Reader and Acrobat 9.2 and earlier (CVE-2009-4324), as described in a <a href="http://blogs.adobe.com/psirt/2009/12/security_advisory_apsa09-07_up.html">separate PSIRT blog last posted on December 15, 2009</a>. This quarterly security update will be made available for Windows, Macintosh and UNIX.</p>

<p>We will continue to provide updates on the upcoming release via the <a href="http://blogs.adobe.com/psirt/2009/12/security_advisory_apsa09-07_up.html">Security Advisory section of the Adobe web site</a>, as well as the <a href="http://blogs.adobe.com/psirt/">Adobe PSIRT blog</a>.</p>

<p><strong>This posting is provided "AS IS" with no warranties and confers no rights.</strong></p>]]>
        
    </content>
</entry>

<entry>
    <title>Security Bulletin - Adobe Flash Media Server (FMS)</title>
    <link rel="alternate" type="text/html" href="http://blogs.adobe.com/psirt/2009/12/security_bulletin_-_adobe_flas_1.html" />
    <id>tag:blogs.adobe.com,2009:/psirt//176.44629</id>

    <published>2009-12-18T19:37:04Z</published>
    <updated>2009-12-18T19:38:25Z</updated>

    <summary>Today we posted a Security Bulletin to address critical security issues in Adobe Flash Media Server. Adobe recommends Flash Media Server customers update to the latest version of Flash Media Server (version 3.5.3) in line with security best practices. This...</summary>
    <author>
        <name>Wendy Poland</name>
        
    </author>
    
        <category term="Security Bulletins and Advisories" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://blogs.adobe.com/psirt/">
        <![CDATA[<p>Today we posted a <a href="http://www.adobe.com/go/apsb09-18">Security Bulletin</a> to address <a href="http://www.adobe.com/devnet/security/security_zone/severity_ratings.html">critical</a> security issues in Adobe Flash Media Server.  Adobe recommends Flash Media Server customers update to the latest version of Flash Media Server (version 3.5.3) in line with security best practices.</p>

<p><strong>This posting is provided "AS IS" with no warranties and confers no rights.</strong></p>]]>
        
    </content>
</entry>

<entry>
    <title>Security Advisory APSA09-07 update</title>
    <link rel="alternate" type="text/html" href="http://blogs.adobe.com/psirt/2009/12/security_advisory_apsa09-07_up.html" />
    <id>tag:blogs.adobe.com,2009:/psirt//176.44595</id>

    <published>2009-12-16T06:55:15Z</published>
    <updated>2009-12-16T06:55:23Z</updated>

    <summary>We&apos;ve just updated the Security Advisory posted earlier today to include the planned schedule for a patch to resolve CVE-2009-4324. Adobe plans to make available an update to Adobe Reader and Acrobat by January 12, 2010 to resolve the issue....</summary>
    <author>
        <name>David Lenoe</name>
        
    </author>
    
        <category term="Security Bulletins and Advisories" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://blogs.adobe.com/psirt/">
        <![CDATA[<p>We've just <a href="http://www.adobe.com/support/security/advisories/apsa09-07.html">updated the Security Advisory</a> posted earlier today to include the planned schedule for a patch to resolve CVE-2009-4324. Adobe plans to make available an update to Adobe Reader and Acrobat by January 12, 2010 to resolve the issue.</p>

<p><strong>This posting is provided "AS IS" with no warranties and confers no rights.</strong></p>]]>
        
    </content>
</entry>

<entry>
    <title>Security Advisory- Adobe Reader and Acrobat</title>
    <link rel="alternate" type="text/html" href="http://blogs.adobe.com/psirt/2009/12/security_advisory-_adobe_reade.html" />
    <id>tag:blogs.adobe.com,2009:/psirt//176.44593</id>

    <published>2009-12-16T00:17:32Z</published>
    <updated>2009-12-16T00:17:58Z</updated>

    <summary>A Security Advisory has been posted in regards to the Adobe Reader and Acrobat issue discussed in the Adobe PSIRT blog on December 14 (&quot;New Adobe Reader and Acrobat Vulnerability&quot;, CVE-2009-4324). A critical vulnerability exists in Adobe Reader and Acrobat...</summary>
    <author>
        <name>David Lenoe</name>
        
    </author>
    
        <category term="Security Bulletins and Advisories" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://blogs.adobe.com/psirt/">
        <![CDATA[<p>A <a href="http://www.adobe.com/support/security/advisories/apsa09-07.html">Security Advisory</a> has been posted in regards to the Adobe Reader and Acrobat issue discussed in the Adobe PSIRT blog on December 14 ("<a href="http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html">New Adobe Reader and Acrobat Vulnerability</a>", CVE-2009-4324).  A critical vulnerability exists in Adobe Reader and Acrobat 9.2 and earlier for Windows, Macintosh and UNIX operating systems.  This vulnerability (CVE-2009-4324) could cause a crash and potentially allow an attacker to take control of the affected system.  There are reports that this vulnerability is being actively exploited in the wild.  Customers should <a href="http://www.adobe.com/support/security/advisories/apsa09-07.html">refer to the Security Advisory</a> for information on mitigating this vulnerability. The advisory will be updated once a schedule has been determined for releasing a fix.</p>

<p>Adobe actively shares information about this and other vulnerabilities with partners in the security community to enable them to quickly develop detection and quarantine methods to protect users until a patch is available.  Adobe recommends that you keep your anti-malware software and definitions up-to-date and monitor releases from your vendor about this issue.</p>

<p>We will continue to provide updates on this issue via the <a href="http://www.adobe.com/support/security/">Security Advisory section</a> of the Adobe web site, as well as the <a href="http://blogs.adobe.com/psirt/">Adobe PSIRT blog</a>.</p>

<p><strong>This posting is provided "AS IS" with no warranties and confers no rights.</strong><br />
</p>]]>
        
    </content>
</entry>

<entry>
    <title>New Adobe Reader and Acrobat Vulnerability</title>
    <link rel="alternate" type="text/html" href="http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html" />
    <id>tag:blogs.adobe.com,2009:/psirt//176.44579</id>

    <published>2009-12-15T00:13:42Z</published>
    <updated>2009-12-15T02:10:11Z</updated>

    <summary>This afternoon, Adobe received reports of a vulnerability in Adobe Reader and Acrobat 9.2 and earlier versions being exploited in the wild (CVE-2009-4324). We are currently investigating this issue and assessing the risk to our customers. We will provide an...</summary>
    <author>
        <name>David Lenoe</name>
        
    </author>
    
    
    <content type="html" xml:lang="en" xml:base="http://blogs.adobe.com/psirt/">
        <![CDATA[<p>This afternoon, Adobe received reports of a vulnerability in Adobe Reader and Acrobat 9.2 and earlier versions being exploited in the wild (CVE-2009-4324). We are currently investigating this issue and assessing the risk to our customers. We will provide an update as soon as we have more information. Please continue monitoring the <a href="http://blogs.adobe.com/psirt/">Adobe PSIRT blog</a> for the latest information. </p>

<p><strong>This posting is provided "AS IS" with no warranties and confers no rights.</strong><br />
</p>]]>
        
    </content>
</entry>

<entry>
    <title>Security Bulletin - Adobe Flash Player</title>
    <link rel="alternate" type="text/html" href="http://blogs.adobe.com/psirt/2009/12/security_bulletin_-_adobe_flas.html" />
    <id>tag:blogs.adobe.com,2009:/psirt//176.44485</id>

    <published>2009-12-09T00:26:00Z</published>
    <updated>2009-12-09T00:26:40Z</updated>

    <summary>A Security Bulletin was posted to address critical security issues in Adobe Flash Player. This Security Bulletin affects Flash Player versions 10.0.12.36 and earlier, as well as AIR versions 1.5.2 and earlier. This posting is provided &quot;AS IS&quot; with no...</summary>
    <author>
        <name>Wendy Poland</name>
        
    </author>
    
        <category term="Security Bulletins and Advisories" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://blogs.adobe.com/psirt/">
        <![CDATA[<p>A <a href="http://www.adobe.com/go/apsb09-19">Security Bulletin</a> was posted to address <a href="http://www.adobe.com/devnet/security/security_zone/severity_ratings.html">critical</a> security issues in Adobe Flash Player.  This Security Bulletin affects Flash Player versions 10.0.12.36 and earlier, as well as AIR versions 1.5.2 and earlier.</p>

<p><strong>This posting is provided "AS IS" with no warranties and confers no rights.</strong></p>]]>
        
    </content>
</entry>

<entry>
    <title>Security Advisory for Adobe Illustrator CS4 and Adobe Illustrator CS3</title>
    <link rel="alternate" type="text/html" href="http://blogs.adobe.com/psirt/2009/12/security_advisory_for_adobe_il.html" />
    <id>tag:blogs.adobe.com,2009:/psirt//176.44464</id>

    <published>2009-12-07T23:17:39Z</published>
    <updated>2009-12-07T23:18:32Z</updated>

    <summary>Today, we posted a Security Advisory regarding a recently reported Adobe Illustrator issue (CVE-2009-4195). Adobe plans to make available an update to Adobe Illustrator to resolve the issue by January 8, 2010. This posting is provided &quot;AS IS&quot; with no...</summary>
    <author>
        <name>David Lenoe</name>
        
    </author>
    
        <category term="Security Bulletins and Advisories" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://blogs.adobe.com/psirt/">
        <![CDATA[<p>Today, we posted a <a href="http://www.adobe.com/support/security/advisories/apsa09-06.html">Security Advisory</a> regarding a recently reported Adobe Illustrator issue (CVE-2009-4195). Adobe plans to make available an update to Adobe Illustrator to resolve the issue by January 8, 2010.<br />
<strong><br />
This posting is provided "AS IS" with no warranties and confers no rights.</strong><br />
</p>]]>
        
    </content>
</entry>

<entry>
    <title>Adobe Illustrator issue update</title>
    <link rel="alternate" type="text/html" href="http://blogs.adobe.com/psirt/2009/12/adobe_illustrator_cs4_issue_up.html" />
    <id>tag:blogs.adobe.com,2009:/psirt//176.44445</id>

    <published>2009-12-04T22:10:40Z</published>
    <updated>2009-12-04T22:18:43Z</updated>

    <summary>Adobe has confirmed the vulnerability in Adobe Illustrator reported recently (CVE-2009-4195). This vulnerability affects Adobe Illustrator CS4 (14.0.0) and Adobe Illustrator CS3 (13.0.3 and earlier) on the Windows and Macintosh platforms. We expect to publish a Security Advisory on Monday,...</summary>
    <author>
        <name>David Lenoe</name>
        
    </author>
    
    
    <content type="html" xml:lang="en" xml:base="http://blogs.adobe.com/psirt/">
        <![CDATA[<p>Adobe has confirmed the vulnerability in Adobe Illustrator reported recently (CVE-2009-4195). This vulnerability affects Adobe Illustrator CS4 (14.0.0) and Adobe Illustrator CS3 (13.0.3 and earlier) on the Windows and Macintosh platforms. We expect to publish a Security Advisory on Monday, December 7 with further information, including a schedule for an update to resolve the issue. As previously reported, a successful exploit of the vulnerability would require a local user to take the action of opening a malicious .eps file in Illustrator. Adobe recommends that customers avoid opening .eps files from unknown sources in Illustrator until a patch is available.</p>

<p><strong>This posting is provided "AS IS" with no warranties and confers no rights.</strong><br />
</p>]]>
        
    </content>
</entry>

<entry>
    <title>Potential Adobe Illustrator CS4 issue</title>
    <link rel="alternate" type="text/html" href="http://blogs.adobe.com/psirt/2009/12/potential_adobe_illustrator_cs.html" />
    <id>tag:blogs.adobe.com,2009:/psirt//176.44408</id>

    <published>2009-12-03T20:04:00Z</published>
    <updated>2009-12-03T20:18:53Z</updated>

    <summary>Adobe is aware of a report of a potential vulnerability in Adobe Illustrator CS4 (CVE-2009-4195). We are currently investigating this issue and will have an update once we have more information. It appears that this issue would require a local...</summary>
    <author>
        <name>David Lenoe</name>
        
    </author>
    
    
    <content type="html" xml:lang="en" xml:base="http://blogs.adobe.com/psirt/">
        <![CDATA[<p>Adobe is aware of a report of a potential vulnerability in Adobe Illustrator CS4 (CVE-2009-4195). We are currently investigating this issue and will have an update once we have more information. It appears that this issue would require a local user to take the action of opening a malicious .eps file in Illustrator.<br />
<strong><br />
This posting is provided "AS IS" with no warranties and confers no rights.</strong></p>]]>
        
    </content>
</entry>

<entry>
    <title>Pre-Notification - Security Update for Adobe Flash Player</title>
    <link rel="alternate" type="text/html" href="http://blogs.adobe.com/psirt/2009/12/pre-notification_-_security_up.html" />
    <id>tag:blogs.adobe.com,2009:/psirt//176.44404</id>

    <published>2009-12-03T19:02:00Z</published>
    <updated>2009-12-03T19:03:27Z</updated>

    <summary>A Security Advisory has been posted in regards to the upcoming Adobe Flash Player update scheduled for December 8, 2009. The update addresses critical security issues in the product. We will continue to provide updates on the upcoming release via...</summary>
    <author>
        <name>Wendy Poland</name>
        
    </author>
    
        <category term="Security Bulletins and Advisories" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://blogs.adobe.com/psirt/">
        <![CDATA[<p>A <a href="http://www.adobe.com/go/apsb09-19">Security Advisory</a> has been posted in regards to the upcoming Adobe Flash Player update scheduled for December 8, 2009.  The update addresses <a href="http://www.adobe.com/devnet/security/security_zone/severity_ratings.html">critical</a> security issues in the product.</p>

<p>We will continue to provide updates on the upcoming release via the <a href="http://www.adobe.com/support/security/">Security Advisory section of the Adobe web site</a>, as well as the <a href="http://blogs.adobe.com/psirt/">Adobe PSIRT blog</a>.</p>

<p><strong>This posting is provided "AS IS" with no warranties and confers no rights.</strong></p>]]>
        
    </content>
</entry>

</feed>
