news4geeks.net
17Feb/120

Adobe confirms new zero-day Flash bug

Adobe on Wednesday patched seven critical vulnerabilities in Flash Player, including one reported by Google researchers that hackers are using in "active targeted attacks." The bug attackers have been exploiting is a cross-site scripting (XSS) flaw in the Flash Player plug-in used by Microsoft's Internet Explorer (IE).

"This update resolves a universal cross-site scripting vulnerability that could be used to take actions on a user's behalf on any website or Web mail provider, if the user visits a malicious website," read the Adobe security advisory that accompanied yesterday's Flash update. "There are reports that this vulnerability is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an email message."


The attack only works against IE.

Adobe said the other six vulnerabilities, all rated critical like the XSS bug, were memory corruption flaws or security bypass bugs that "could cause a crash and potentially allow an attacker to take control of the affected system."

Google was credited with notifying Adobe of the XSS vulnerability, but Adobe did not note when Google filed the bug report or how long attackers have been exploiting the bug.

To patch the vulnerabilities, Adobe updated Flash Player 11 and Flash Player 10 on Windows, Mac OS X, Linux and Solaris, and Flash Player on Android.

Also on Wednesday, Google updated Chrome to offer the newly-patched Flash to its users. Google has packaged Flash Player with Chrome since April 2010, and remains the only browser that contains its own copy of Flash Player.

Last week, Adobe confirmed that its next target for a "sandboxed" Flash Player would be he plug-in for Internet Explorer, a defense that, if already implemented, should have stopped the current exploits in their tracks.

Adobe finished a sandboxed Flash for Chrome in 2010, and has just launched a beta of sandboxed Flash for Mozilla's Firefox on Windows Vista and Windows 7.

Wednesday's Flash update was the first this year for the media player, but the software has required aggressive patching: In 2011, Adobe fixed Flash flaws nine different times.

The patched versions of Flash Player for Windows, Mac, Linux and Solaris can be downloaded from Adobe's website. Alternately, users can run Flash's update tool or wait for the software to prompt them that a new version is available.

Android users can retrieve the new version from the Android Market.

(Source: computerworld.com)

 

Adobe has released a beta version of Flash Player for Firefox, which has better protection against vulnerability exploits because of a new sandboxed architecture. "The design of this sandbox ...
READ MORE
Adobe yesterday updated Flash Player to solve a weeks-long problem for users of Mozilla's Firefox browser. The update, Flash Player 11.3.300.262, was released Thursday and applies only to Firefox on Windows. Since ...
READ MORE
Adobe preps silent Flash updates for Macs
Adobe last week released a new beta of Flash Player that includes silent updates for Macs. Adobe first included silent updates for OS X in the Flash Player beta a ...
READ MORE
Adobe to Linux users: Get Chrome or forget Flash
Adobe today said that it would stop offering direct downloads of Flash Player for Linux, telling users to move to Google's Chrome browser, which bundles Flash with its ...
READ MORE
Espionage network exploiting Adobe Reader flaw
Adobe warned users of its Reader software earlier this week that hackers were using a critical vulnerability in the program to enable "limited, targeted attacks." Today security firm ...
READ MORE
Adobe launches sandboxed Flash Player for Firefox, hopes
Adobe fixes Flash Player for Firefox to stop
Adobe preps silent Flash updates for Macs
Adobe to Linux users: Get Chrome or forget
Espionage network exploiting Adobe Reader flaw

Comments (0) Trackbacks (0)

No comments yet.


Leave a comment

Trackbacks are disabled.