Posts tagged "Flash Player"

Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat (APSA11-01)

A Security Advisory (APSA11-01) has been posted in regards to an issue in Adobe Flash Player (CVE-2011-0609). A critical vulnerability exists in Adobe Flash Player 10.2.152.33 and earlier versions (Adobe Flash Player 10.2.154.18 and earlier for Chrome users) for Windows, Macintosh, Linux and Solaris operating systems, Adobe Flash Player 101.106.16 and earlier versions for Android, and the authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.1) and earlier 10.x and 9.x versions for Windows and Macintosh operating systems. There are reports that this vulnerability is being exploited in the wild in targeted attacks via a Flash (.swf) file embedded in a Microsoft Excel (.xls) file delivered as an email attachment. At this time, Adobe is not aware of attacks targeting Adobe Reader and Acrobat.

We are in the process of finalizing a fix for the issue and expect to make available an update for Flash Player 10.x and earlier versions for Windows, Macintosh, Linux, Solaris and Android, and an update for Adobe Acrobat X (10.0.1) and earlier 10.x and 9.x versions for Windows and Macintosh, Adobe Reader X (10.0.1) for Macintosh, and Adobe Reader 9.4.2 and earlier 9.x versions during the week of March 21, 2011. Because Adobe Reader X Protected Mode would prevent an exploit of this kind from executing, we are currently planning to address this issue in Adobe Reader X for Windows with the next quarterly security update for Adobe Reader, currently scheduled for June 14, 2011.

We will continue to provide updates on this issue via the Security Advisory section of the Adobe website as well as the Adobe PSIRT blog.

This posting is provided “AS IS” with no warranties and confers no rights.

Security update available for Adobe Flash Player (APSB11-02)

Today, a Security Bulletin (APSB11-02) has been posted to address critical security issues in Adobe Flash Player. This Security Bulletin affects Flash Player version 10.1.102.64 and earlier versions for Windows, Macintosh, Linux, and Solaris. Adobe recommends users apply the updates for their product installations.

This posting is provided “AS IS” with no warranties and confers no rights.

Security update available for Adobe Flash Player (APSB10-26)

Today, a Security Bulletin (APSB10-26) has been posted to address critical security issues in Adobe Flash Player, including CVE-2010-3654 referenced in Security Advisory APSA10-05. This Security Bulletin affects Flash Player versions 10.1.85.3 and earlier versions for Windows, Macintosh, Linux, and Solaris. Adobe recommends users apply the updates for their product installations.  We expect to make available an update for Flash Player 10.x for Android by November 9, 2010.

This posting is provided “AS IS” with no warranties and confers no rights.

Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat (APSA10-05)

A Security Advisory (APSA10-05) has been posted in regards to a new Flash Player, Adobe Reader and Acrobat issue (CVE-2010-3654). A critical vulnerability exists in Adobe Flash Player 10.1.85.3 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems; Adobe Flash Player 10.1.95.2 and earlier versions for Android; and the authplay.dll component that ships with Adobe Reader 9.4 and earlier 9.x versions for Windows, Macintosh and UNIX operating systems, and Adobe Acrobat 9.4 and earlier 9.x versions for Windows and Macintosh operating systems. This vulnerability (CVE-2010-3654) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against Adobe Reader and Acrobat 9.x. Adobe is not currently aware of attacks targeting Adobe Flash Player.

Adobe Reader and Acrobat 8.x, and Adobe Reader for Android are confirmed not vulnerable. Mitigations for Adobe Reader and Acrobat 9.x are included in the Security Advisory.

We are in the process of finalizing a fix for the issue and expect to provide an update for Adobe Flash Player 10.x for Windows, Macintosh, Linux and Android by November 9, 2010. We expect to make available an update for Adobe Reader and Acrobat 9.4 and earlier 9.x versions during the week of November 15, 2010.

We will continue to provide updates on this issue via the Security Advisory section of the Adobe website as well as the Adobe PSIRT blog.

This posting is provided “AS IS” with no warranties and confers no rights.

Security update available for Adobe Flash Player

Today, a Security Bulletin has been posted to address a critical security issue (CVE-2010-2884) in Adobe Flash Player. This Security Bulletin affects Adobe Flash Player 10.1.82.76 and earlier versions for Windows, Macintosh, Linux, and Solaris, and Adobe Flash Player 10.1.92.10 for Android.  Adobe recommends users apply the update for their product installation. This addresses the issue first mentioned in Security Advisory APSA10-03.

This posting is provided “AS IS” with no warranties and confers no rights.

Schedule Update to Security Advisory for Adobe Flash Player (APSA 10-03)

We just updated the Security Advisory (APSA10-03) posted on Monday, Sept. 13, 2010 to include an updated schedule for a patch to resolve CVE-2010-2884. Adobe now plans to make available updates for Adobe Flash Player for Windows, Macintosh, UNIX, Solaris and Android on Monday, Sept. 20, 2010.

We will continue to provide updates on this issue via the Security Advisory section of the Adobe website as well as the Adobe PSIRT blog.

This posting is provided “AS IS” with no warranties and confers no rights.

Security Advisory for Adobe Flash Player (APSA10-03)

A Security Advisory (APSA10-03) has been posted in regards to a new Adobe Flash Player issue (CVE-2010-2884). A critical vulnerability exists in Adobe Flash Player 10.1.82.76 and earlier versions for Windows, Macintosh, Linux, Solaris and Android. This vulnerability also affects Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against Flash Player on Windows.

We will continue to provide updates on this issue via the Security Advisory section of the Adobe website as well as the Adobe PSIRT blog.

This posting is provided “AS IS” with no warranties and confers no rights.

Security updates available for Adobe Flash Player, ColdFusion and Flash Media Server

Today, we released the following Security Bulletins:

Customers of the affected products should consult the relevant Security Bulletin(s) and apply updates as recommended.

This posting is provided “AS IS” with no warranties and confers no rights.

Apple Security Update 2010-004 / Mac OS X v10.6.4 Shipping with Outdated Version of Adobe Flash Player

Earlier today, Apple released security update 2010-004 / Mac OS X v10.6.4. This update includes an earlier version of Adobe Flash Player (version 10.0.45.2) than available from Adobe.com. While the Mac OS X v10.6.4 update does not appear to downgrade users who have already upgraded to Adobe Flash Player 10.1, Adobe recommends users verify they are using the latest, most secure version of Flash Player (10.1.53.64) available for download from http://www.adobe.com/go/getflashplayer.
To verify the Adobe Flash Player version number installed on your system (after applying the Mac OS X security update), access the About Flash Player page, or right-click on content running in Flash Player and select “About Adobe Flash Player” from the menu. If you use multiple browsers, checking on any one browser will verify the update for all browsers on Macintosh systems (on Windows, perform the check for each browser you have installed on your system).
This posting is provided “AS IS” with no warranties and confers no rights.

Security Bulletin – Adobe Flash Player

Today, a Security Bulletin has been posted to address critical security issues in Adobe Flash Player, including CVE-2010-1297, referenced in Security Advisory APSA10-01. This Security Bulletin affects Flash Player versions 10.0.45.2 and earlier, as well as AIR versions 1.5.3.9130 and earlier. Adobe recommends users apply the updates for their product installations.
This posting is provided “AS IS” with no warranties and confers no rights.