Flash Player

Patchday ahead

Published: November 6, 2010 Reading time: 2 min

The Redmond company today published its announcement for the upcoming November Patch Tuesday. Microsoft wants to release 3 security bulletins which deal with 11 security vulnerabilities within Office and PowerPoint (up to the brand new Office 2011 for Mac) and Forefront Unified Access Gateway. A patch for the just recently detected 0-day vulnerability in Internet Explorer is not in the list. Adobe meanwhile ships an update for the Flash Player to version 10.1.102.64 today and plans one for the Reader and Acrobat next week. The Flash update is available via the Download Center and fixes the“authplay” vulnerability which got public last week. But the company has to deal with a new security vulnerability as well. It’s not yet exploited and it remains currently unknown whether it is exploitable to infect PCs with malware, but Adobe investigates the flaw. On a public security list a so-called Proof-of-Concept (PoC) has been published which just shows a Denial-of-Service attack. ...

Continue Reading

New Vulnerability in Adobe Flash and Reader

Published: November 1, 2010 Reading time: 1 min

Avira TechBlog: Adobe warns of a new vulnerability in Flash Player and in Reader. The problem is within authplay.dll and the corresponding .lib in the Unix versions. It allows attackers to inject malicious code like Trojans with specially prepared documents or Flash objects. The company works on a patch which it plans to release on the 9th of November. Until then, deleting the authplay library helps to prevent a successful attack. Flash or Reader will crash then when a file requests the services from authplay, but this is clearly better than having an infected system.

Continue Reading

Adobe confirms Flash 10.1 coming to everything but iPhone

Published: October 28, 2010 Reading time: 1 min

At its MAX conference, Adobe not only announced Air 2.5 for phones, tablets, and TVs but it also confirmed that it would be bringing Flash Player 10.1 to Microsoft’s Windows Phone 7, RIM’s BlackBerry OS, HP’s WebOS 2.0, Symbian, MeeGo, and the LiMo platform. Unfortunately, there’s still no timeline for a release on each platform; Adobe is only saying that Flash 10.1 is “expected” to hit each mobile OS. These six platforms will join Android 2.2, which has had Flash since June 2010. The current list of Adobe Flash Player 10.1 certified devices is thus not very long, but if Adobe manages to deliver on what it’s promising, it should grow very rapidly. The news today also means that the iOS is the only major mobile platform that will not support the plug-in: Apple won’t let it touch the iPhone, the iPod touch, or the iPad.

Continue Reading

Flash Player Updates fix 0-day-vulnerability

Published: September 21, 2010 Reading time: 1 min

Adobe fixed the vulnerability in Flash Player in a record time again. Just one week after the 0-day became public and started to get exploited, an update is available to close the security hole. Even though Adobe Reader and Acrobat are affected (which are supposed to get an update in 2 weeks), until now we’ve only seen exploits against the Windows Flash Player. Users and administrators should update their Flash Player as soon as possible! The version 10.1.85.3 fixes the issue for Windows, Unix, Solaris and is available through Adobe’s download center. Android users can get the update to 10.1.95.1 on the Android Market Place.

Continue Reading