User Login    
 + Register
  • Main navigation
Login
Username:

Password:

Remember me



Lost Password?

Register now!


Donate

Wired Feed
Google

Browsing this Thread:   1 Anonymous Users





New Adobe Exploit
Webmaster
Joined:
1/8 21:05
From Dayton, Ohio
Group:
Webmasters
Registered Users
Moderator
Vets
Plus+User
Posts: 59
Offline
Quote:
June 5, 2010 11:00 AM

Adobe Security Vulnerability Under Attack


Adobe Systems is warning users about a zero-day bug affecting Adobe Reader, Flash Player and Acrobat that is actively being exploited by attackers.

According to Adobe, the vulnerability exists in Flash Player 10.0.45.2 and earlier versions for Windows, Macintosh, Linux and Solaris, as well as the authplay.dll component that ships with Adobe Reader and Acrobat 9.x for Windows, Mac and UNIX operating systems.

If exploited, the vulnerability (CVE-2010-1297) could cause systems to crash and potentially allow attacker to execute code and take control of the affected system.
Users looking for a quick fix can delete, rename or remove access to the authplay.dll file in Adobe Reader and Acrobat 9.x, but doing so means they will experience a non-exploitable crash or error message when opening a PDF file that contains SWF content. The file is typically located at C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll for Adobe Reader or C:\Program Files\Adobe\Acrobat 9.0\Acrobat\authplay.dll for Acrobat, according to Adobe.

The Flash Player 10.1 Release Candidate does not appear to be vulnerable, and Adobe Reader and Acrobat 8.x have been confirmed to be unaffected.

The company said it will update the advisory when it has determined a schedule for releasing a patch.


The above report calls for everyone to update their adobe installs ASAP.
I'll update this when they actually have a patch.

Posted on: 6/5 11:45

Edited by dante on 2010/6/5 14:33:36
_________________
The more I know, the more I know that I didn't wanna know.
Transfer the post to other applications Transfer


Re: New Adobe Exploit
Webmaster
Joined:
1/8 21:05
From Dayton, Ohio
Group:
Webmasters
Registered Users
Moderator
Vets
Plus+User
Posts: 59
Offline
For the moment, this is the fix recommended:
Reader and Acrobat users can protect themselves by deleting or renaming authplay.dll. Doing so, however, means that opening a PDF file containing Flash content will crash the software or produce an error message.

Alternately:
Flash Player 10.1 Release Candidate, which can be downloaded from Adobe's site, "does not appear to be vulnerable," Adobe said, implicitly urging users to shift to the unfinished software.

Download the RC here:
http://labs.adobe.com/technologies/flashplayer10/

Posted on: 6/6 8:24
_________________
The more I know, the more I know that I didn't wanna know.
Transfer the post to other applications Transfer


Re: New Adobe Exploit
Just popping in
Joined:
3/22 12:27
From SWNY
Group:
Registered Users
Posts: 9
Offline
Wow thanks for the heads up Dante I will search my system for that file & my girlfriends! I will also post this on my facebook page to let others know...

Posted on: 6/25 9:57
_________________
Haha This might hurt!!
Transfer the post to other applications Transfer


Re: New Adobe Exploit
Just popping in
Joined:
3/22 12:27
From SWNY
Group:
Registered Users
Posts: 9
Offline
I have also found the "authply.dll" in my Adobe flash player directory. Which I have denied access for both in my Adobe Reader and Adobe Flash for the system, administrator, and My account. Both The reader and flash still work. I am posting this to let people know to look into their Adobe Flash directory as well if they wish to also if Dante thinks it's a good approach (this is his forum I can not give out advice without his approval) in C:\Programs also maybe in the "User" account folder under the appropriate account names (C:\Documents & Settings\User\Application Data for XP) (C:\Users\your account name\AppData\Local for Vista and maybe for Win7) also the "default" user account. Also under Vista look in the "ProgramData" folder. Also in Vista open any window using the search feature type in "authply.dll to look for that file, if it is in your system it will find the file in all directories if you do not want to rummage through your C: drive. This is just advice :D

Posted on: 6/25 19:22
_________________
Haha This might hurt!!
Transfer the post to other applications Transfer






You can view topic.
You cannot start a new topic.
You cannot reply to posts.
You cannot edit your posts.
You cannot delete your posts.
You cannot add new polls.
You cannot vote in polls.
You cannot attach files to posts.
You cannot post without approval.

[Advanced Search]


Who's Online
7 user(s) are online (2 user(s) are browsing Forums)

Members: 0
Guests: 7

more...
New Members
kyngofkomedy 2010/8/29
robert2 2010/8/28
glitch 2010/8/20
MassAssassin 2010/8/19
throoper
throoper
2010/6/27
azevedan 2010/6/9
Synja 2010/5/29
poppij 2010/5/23
EMGARCIA 2010/5/13
choatpadda 2010/4/4
Google
      Stop Spam Harvesters, Join Project Honey Pot
Site Info
Webmasters
dante
dante
 
Spectre
Spectre
 
Moderator
dante
dante
 

Rolling Stone: Videos