--
If you haven't gotten the hang of it yet, despite Adobe's scheduled quarterly updates to their software, they've been pushing out security updates at the rate of about once a month. March was no exception. April was no exception. May was no exception. I didn't bother to announce them all here because it has become all so predictable that I figure everyone knows to watch for them coming.
And now it's June. Here comes the quarterly update, like we care that it's quarterly. Why Adobe bother with his BS is beyond my comprehension. I personally think they're nuts over there.
So here we go, the quarterly update announcement is HERE. The quarterly update comes out Tuesday, June 14th. As per usual, it is a CRITICAL security update. It will be for both Adobe Reader and Adobe Acrobat.
If you'd like to keep track of when future 'out of band' (non-quarterly, once a month) security updates from Adobe are released, the two best web locations are:
Adobe Security Bulletins and Advisories
Adobe Product Security Incident Response Team (PSIRT) Blog
Predictable as these 'out-of-band' critical security updates have become over the last full year, keep in mind that if you use Adobe's stuff, it is important to keep up-to-date with their security patches if you want to keep your Mac as safe as possible.
Over and out.
--
Showing posts with label Adobe Reader. Show all posts
Showing posts with label Adobe Reader. Show all posts
Friday, June 10, 2011
Thursday, April 21, 2011
Adobe Critical Updates Again:
Acrobat Reader 10.0.3 &
Adobe Acrobat X 10.0.3
(Out-Of-Band but ahead of schedule!)
--
You can read about it HERE and HERE.
You can directly download the Adobe Reader 10.0.3 update HERE.
You can directly download the Adobe Acrobat X 10.0.3 update HERE.
The security flaws involved are those Adobe posted on April 11th in the second article linked above. These are the promised updates of Reader and Acrobat, ahead of schedule by four days. Thank you Adobe!
Computer PWNing through the use of PDFs and Flash media is thick and fast these days, particularly on Windows, including Windows 7 (7ista). I have read speculation that hackers have a pile of 'zero-day' Adobe security hole hacks that are being used one after the other as Adobe provide patch after patch, trying to keep up. Note that it is possible to at least compromise a Mac using similar cracking methods and Trojan horses.
THEREFORE, user beware. I wrote in detail about precautions and protections available if you must use PDFs and/or Flash. Simply scroll back through my previous blog posts.
:-Derek
--
You can read about it HERE and HERE.
You can directly download the Adobe Reader 10.0.3 update HERE.
You can directly download the Adobe Acrobat X 10.0.3 update HERE.
The security flaws involved are those Adobe posted on April 11th in the second article linked above. These are the promised updates of Reader and Acrobat, ahead of schedule by four days. Thank you Adobe!
Computer PWNing through the use of PDFs and Flash media is thick and fast these days, particularly on Windows, including Windows 7 (7ista). I have read speculation that hackers have a pile of 'zero-day' Adobe security hole hacks that are being used one after the other as Adobe provide patch after patch, trying to keep up. Note that it is possible to at least compromise a Mac using similar cracking methods and Trojan horses.
THEREFORE, user beware. I wrote in detail about precautions and protections available if you must use PDFs and/or Flash. Simply scroll back through my previous blog posts.
:-Derek
--
Sunday, April 17, 2011
CRITICAL Patches for:
Adobe Flash Player
& Acrobat Pro
& Adobe Reader
& Adobe AIR
(Out-Of-Band!)
--
Sorting through this flock of updates is confusing. Therefore, for the sake of simplicity, I've thrashed through the Adobe mess for you. Below you will find links to relevant Adobe announcements as well as direct links to the update installers, lead with a *:
I) Adobe Reader & Adobe Acrobat 10.0.2 Updates:
Security updates available for Adobe Reader and Acrobat
*Adobe Acrobat 10.0.2 Pro update for Macintosh
II) Adobe Flash Player 10.2.159.1 & Adobe AIR 2.6.19140 Updates:
Security update available for Adobe Flash Player [& Adobe AIR]
*Adobe Flash Player 10.2.159.1 for Macintosh
NOTE: I tacked "[& Adobe AIR]" onto the link to the Flash announcement because it is the only place you'll find it stated that an update of Adobe AIR is available and required. (0_o)
I swear there's lead in the water at Adobe. I wish they'd get their act back together.
--
Sorting through this flock of updates is confusing. Therefore, for the sake of simplicity, I've thrashed through the Adobe mess for you. Below you will find links to relevant Adobe announcements as well as direct links to the update installers, lead with a *:
I) Adobe Reader & Adobe Acrobat 10.0.2 Updates:
Security updates available for Adobe Reader and Acrobat
*Adobe Acrobat 10.0.2 Pro update for Macintosh
II) Adobe Flash Player 10.2.159.1 & Adobe AIR 2.6.19140 Updates:
Security update available for Adobe Flash Player [& Adobe AIR]
*Adobe Flash Player 10.2.159.1 for Macintosh
NOTE: I tacked "[& Adobe AIR]" onto the link to the Flash announcement because it is the only place you'll find it stated that an update of Adobe AIR is available and required. (0_o)I swear there's lead in the water at Adobe. I wish they'd get their act back together.
--
Tuesday, March 15, 2011
CRITICAL Zero-Day Security Exploit
In-The-Wild:
Adobe Flash
& Adobe Acrobat
& Adobe Reader
--Q: So Adobe! How's that quarterly 'in-band' update schedule working for you?
A: Um...
After a nice break from The Summer Of Security Holes, we are back on track with CRITICAL Adobe zero-day exploits. This one hits ALL versions of Adobe Flash (v10.2.152.33 on down) on ALL OS platforms, except of course Apple's iOS which does not allow Flash content. Now perhaps skeptics can understand why. It also hits versions 10.0.1 on down through v9.x of Adobe Reader and Adobe Acrobat on Mac and Windows.
Here is the security advisory from Adobe.
This vulnerability (CVE-2011-0609) could cause a crash and potentially allow an attacker to take control of the affected system.Here is an article by Electronista.
Given the popularity of the Flash platform, it would seem that this could be a somewhat difficult situation to manage.Here is the advisory from Adobe's PSIRT (Adobe Product Security Incident Response Team) blog.
We are in the process of finalizing a fix for the issue and expect to make available an update . . . during the week of March 21, 2011.And here are even more details from yet-another Adobe security blog, this time called ASSET (Adobe Secure Software Engineering Team).
We currently plan to address CVE-2011-0609 in Adobe Reader X with the next quarterly security update for Adobe Reader, currently scheduled for June 14, 2011.... We determined that the above patch schedule would allow us to provide the best balance of risk mitigation and admin/update costs for our customers.Translation: Watch for patches of Adobe Flash Player, Adobe Acrobat and Adobe Reader v9.x (not 10.x) the week of March 21, 2011. There will be NO patch for Acrobat Reader v10.x until the scheduled quarterly "in-band" date of June 14, 2011. There is an explanation of this inexplicable schedule in the ASSET article.
The currently known exploit is a Microsoft Excel (XLS) file sent via email to victims. Embedded within this file is a Trojan horse Flash file (SWF). Adobe does not explicitly state that this specific file is directed only at Windows users. However, the details they provide refer only to using 'Protected Mode' in Adobe Reader, which is a Windows-only feature. Therefore, I can infer that this is a Windows-only exploit file.
Other exploits are possible. Therefore, until Adobe patch this hole, beware of Flash in general, either as straight Flash files OR embedded in another file type.
My solutions:
A) Use one of the many Flash blocking extensions in your web browsers AT ALL TIMES.
B) As a corollary of The Second Rule Of Computing:
- Only open files emailed to you AFTER you have verified that their source is legitimate.
- Only click on embedded Flash on web sites that have been verified to be legitimate.
D) If you just 'have to' use Adobe Reader: Be sure you are using 'Enhanced Security' inside the Preferences. You'll find it listed under 'Security (Enhanced)'. Note that this is enabled by default when you first install Adobe Reader.
E) Or to be totally safe: Remove Adobe Flash, Adobe Acrobat and Adobe Reader from your computer.
Q: Does this make the Internet more dangerous than ever?A: You bet!
Q: Why does the Internet have to be such an annoying pain?
A: Bad coding practices by developers as well as poor code documentation, critical to cleaning up bad code.
Theoretically, newer coding students are being taught how to avoid computer memory security holes. However, even if they are diligent at writing 'perfect' code, other problems persist in the code languages themselves. For example, the Java code language was created specifically to never be able to exploit the user's computer. And yet it does. As I ever rant: We are still in The Stone Age Of Computing.
Q: Are Mac users really vulnerable to this security exploit?A: Absolutely!
Keep in mind that this is not an Apple or Mac OS X problem. This is an Adobe problem. It is their software that is being exploited and ends up damaging the computer. There is nothing Apple can do to prevent Flash exploits apart from ban Flash, which is thankfully the case with all Apple iOS devices.
Meanwhile, whether this exploit will be targeted specifically at Macs is entirely up to the evil scumbag hackers writing the exploit code. If I hear of a Mac specific exploit file, I will post here.
--
Wednesday, November 17, 2010
Adobe CRITICAL Security Update
Of The Month Club
--
And now for something useful:

Adobe have posted their promised CRITICAL "out-of-band" security updates for Adobe Acrobat and Adobe Reader. The new versions are 9.4.1. If you use either of these applications, get the security updates now. Proof-of-concept exploits for the previous versions have been available for weeks.
You can read about the CRITICAL security updates here:
Security updates available for Adobe Reader and Acrobat
The direct download URLs, to save you from suffering Adobe's lunatic website:
Adobe Acrobat 9.4.1 Pro update
Adobe Reader 9.4.1 update - PPC
Adobe Reader 9.4.1 update - Intel
See you back here next month for the latest in "out-of-band" CRITICAL Adobe security updates!
Stay safe, stay secure, laugh at the FUD.
--
And now for something useful:

Adobe have posted their promised CRITICAL "out-of-band" security updates for Adobe Acrobat and Adobe Reader. The new versions are 9.4.1. If you use either of these applications, get the security updates now. Proof-of-concept exploits for the previous versions have been available for weeks.
You can read about the CRITICAL security updates here:
Security updates available for Adobe Reader and Acrobat
The direct download URLs, to save you from suffering Adobe's lunatic website:
Adobe Acrobat 9.4.1 Pro update
Adobe Reader 9.4.1 update - PPC
Adobe Reader 9.4.1 update - Intel
See you back here next month for the latest in "out-of-band" CRITICAL Adobe security updates!
Stay safe, stay secure, laugh at the FUD.
--
Thursday, November 4, 2010
Adobe Flash Player 10.1.102.64 CRITICAL Update
--
THIS MONTH'S critical Adobe Flash Player update for Mac OS X is available a few days ahead of schedule. Thank you Adobe! It patches 18 security holes.
Security update available for Adobe Flash Player
NOTE: We're still waiting for CRITICAL security updates for Adobe Reader 9.4 and Adobe Acrobat 9.4. You can read details about the ongoing security problems HERE.
--
THIS MONTH'S critical Adobe Flash Player update for Mac OS X is available a few days ahead of schedule. Thank you Adobe! It patches 18 security holes.
Security update available for Adobe Flash Player
Critical vulnerabilities have been identified in Adobe Flash Player 10.1.85.3 and earlier versions for Windows, Macintosh, Linux, and Solaris, and Adobe Flash Player 10.1.95.1 for Android. These vulnerabilities, including CVE-2010-3654 referenced in Security Advisory APSA10-05, could cause the application to crash and could potentially allow an attacker to take control of the affected system.The download link is HERE.
Adobe recommends users of Adobe Flash Player 10.1.85.3 and earlier versions for Windows, Macintosh, Linux, and Solaris update to Adobe Flash Player 10.1.102.64. We expect to make available an update for Flash Player 10.x for Android by November 9, 2010. . .
NOTE: We're still waiting for CRITICAL security updates for Adobe Reader 9.4 and Adobe Acrobat 9.4. You can read details about the ongoing security problems HERE.
--
Friday, October 29, 2010
Adobe Flash, Reader and Acrobat
CRITICAL Security Hole
Of The Month Club
--
Another month, and other Adobe software security hole exploit. If you still use Flash, pay attention! This security hole is currently being exploited In-The-Wild.
Affected:
-> Adobe Flash Player 10.1.85.3 and earlier
-> Adobe Reader 9.4 and earlier 9.x versions
-> Adobe Acrobat 9.4 and earlier 9.x versions
Hackers exploit newest Flash zero-day bug
This issue is described in CVE-2010-3654.
Adobe provide a workaround in their 'Security Advisory' article linked above. They have promised to fix the security hole by November 9th.
Darn, Adobe blew their quarterly update schedule yet again. Can you comprehend why Adobe still believe in 'scheduled' security updates?
(o_0)
Another month, and other Adobe software security hole exploit. If you still use Flash, pay attention! This security hole is currently being exploited In-The-Wild.
Affected:
-> Adobe Flash Player 10.1.85.3 and earlier
-> Adobe Reader 9.4 and earlier 9.x versions
-> Adobe Acrobat 9.4 and earlier 9.x versions
Hackers exploit newest Flash zero-day bug
Those reports came from Mila Parkour, an independent security researcher who notified Adobe early today after spotting and then analyzing a malicious PDF file. According to Parkour, the rigged PDF document exploits the Flash bug in Reader, then drops a Trojan horse and other malware on the victimized machine.Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat
This issue is described in CVE-2010-3654.
Adobe provide a workaround in their 'Security Advisory' article linked above. They have promised to fix the security hole by November 9th.
Darn, Adobe blew their quarterly update schedule yet again. Can you comprehend why Adobe still believe in 'scheduled' security updates?
(o_0)
Wednesday, October 6, 2010
October Adobe Security Updates:
Acrobat, Reader and AIR
--
Rather quietly, in keeping with Adobe's bad PR attitude, their latest 'CRITICAL' security updates have hit the net. Below are some direct links to help you past the clickity-click-click garbage you have to endure when going through Adobe's home page.
I) Adobe Acrobat Pro v9.4.0 update
IIa) Adobe Reader v9.4.0 update - multiple languages INTEL version
IIb) Adobe Reader v9.4.0 update - multiple languages PPC version
III) Adobe AIR v2.0.4.13090 update
And of course you've already installed Adobe Flash Player v10.1.0 update from two weeks ago, right?
What's been fixed?
Adobe Acrobat and Reader:
.
Can anyone spare Adobe an anvil? Mine's in for repair. ;-)
And now it's time for a laugh! Every month this summer Adobe have had 'CRITICAL' security flaws discovered and patched in Acrobat, Reader and Flash Player. There have also been two updates to Adobe Air. Despite this situation, Adobe still hold to the bizarro naive notion of 'quarterly updates'. Here is their message to the world regarding this situation, as of today:
We know better. See you back here next month!
;-P
--
Rather quietly, in keeping with Adobe's bad PR attitude, their latest 'CRITICAL' security updates have hit the net. Below are some direct links to help you past the clickity-click-click garbage you have to endure when going through Adobe's home page.
I) Adobe Acrobat Pro v9.4.0 update
IIa) Adobe Reader v9.4.0 update - multiple languages INTEL version
IIb) Adobe Reader v9.4.0 update - multiple languages PPC version
III) Adobe AIR v2.0.4.13090 update
And of course you've already installed Adobe Flash Player v10.1.0 update from two weeks ago, right?
What's been fixed?
Adobe Acrobat and Reader:
This vulnerability (CVE-2010-2883) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild.--Quoting from CVE-2010-2883:
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.3.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information.Adobe AIR: Beats me! As of today, Adobe have provided NO release notes for AIR v2.0.4. Imagine my cynicism. When Adobe bother to provide release notes, they will appear HERE
.Can anyone spare Adobe an anvil? Mine's in for repair. ;-)
And now it's time for a laugh! Every month this summer Adobe have had 'CRITICAL' security flaws discovered and patched in Acrobat, Reader and Flash Player. There have also been two updates to Adobe Air. Despite this situation, Adobe still hold to the bizarro naive notion of 'quarterly updates'. Here is their message to the world regarding this situation, as of today:
Note that today’s updates represent an accelerated release of the quarterly security update originally scheduled for October 12, 2010. With this accelerated schedule, Adobe will not release additional updates for Adobe Reader and Acrobat on October 12, 2010. The next quarterly security updates for Adobe Reader and Acrobat are scheduled for February 8, 2011.Right. So we'll all meet back here on February 8th. Sure. Everything will be safe and sound until then! Uh huh.
We know better. See you back here next month!
;-P
--
Saturday, September 18, 2010
Adobe Flash Player Security Update:
Moved Up To Monday, September 20th
--
Adobe have announced that they've moved up the critical security update for Flash Player to Monday, September 20, 2010.
Be sure to grab the update ASAP as the security hole it patches (CVE-2010-2884) is being exploited in-the-wild on at least Windows boxes. So far no known exploit is being used on Mac OS X.
You can read Adobe's announcement here:
Schedule Update to Security Advisory for Adobe Flash Player (APSA 10-03)
Meanwhile, the critical security updates for Adobe Reader and Acrobat remain scheduled for the week of October 4, 2010.
--
Adobe have announced that they've moved up the critical security update for Flash Player to Monday, September 20, 2010.
Be sure to grab the update ASAP as the security hole it patches (CVE-2010-2884) is being exploited in-the-wild on at least Windows boxes. So far no known exploit is being used on Mac OS X.
You can read Adobe's announcement here:
Schedule Update to Security Advisory for Adobe Flash Player (APSA 10-03)
Meanwhile, the critical security updates for Adobe Reader and Acrobat remain scheduled for the week of October 4, 2010.
--
Tuesday, September 14, 2010
NEWEST-New CRITICAL Adobe Security Holes
déjà vu déjà vu déjà vu...

--
Question: What is the point of 'in band' quarterly Adobe security updates when this stuff keeps repeating month after month after month?
SHORT VERSION:
Don't use Adobe Reader, Adobe Acrobat, or Adobe Flash until yet-another-nother set of 'out-of-band' security updates are available. Each of these applications have NEW security holes that are being exploited IN THE WILD.
[...Hysterical laughter is heard from some distant room...]
Temporary fix options:
A) PDF Viewing
Use Preview, provided with Mac OS X, for all PDF file reading.
Delete the Adobe PDF Viewer Internet plug-in. You will find it here:
/Library/Internet Plug-ins/AdobePDFViewer.pluginDelete Adobe Reader 9. You will find it here:
/Library/Applications/Adobe Reader 9B) Flash Playing
Control Flash in your web browser and/or delete Flash Player:
There are several options for taking control of Flash in your web browser. I personally use ClickToFlash for Safari and other WebKit browsers, as well as Flashblock for FireFox.
OR
Just delete Adobe Flash Player from your computer.
How to remove Adobe Flash Player:
Check to see if you have the 'uninstall_flash_player_osx.dmg' file and run it. It should be located here:
/Applications/Adobe Flash Player/uninstall_flash_player_osx.dmgOR
You can find and remove the Flash web plug-in files here:
/Library/Internet Plug-Ins/Flash Player.pluginAfter deleting Adobe Flash Player files, be sure to Quit then restart your web browsers in order to clean Flash Player out of memory.
/Library/Internet Plug-ins/flashplayer.xpt
~~~~~~~~~~~~~~
LONG VERSION:
Just when you thought your Adobe apps were safe, this dark sense of wariness creeps into your subconsciousness followed by a sense of déjà vu as you read the latest news. I'll let Adobe give you the bad news. Here are the two pages at Adobe where you can find their security announcements:
Adobe Product Security Incident Response Team (PSIRT)
Adobe Security Bulletins and Advisories
The latest Adobe bad news déjà vu déjà vu déja vu (with added emphasis mine):
I) Security Advisory for Adobe Reader and Acrobat (APSA10-02)

Release date: September 8, 2010II) Security Advisory for Adobe Flash Player (APSA 10-03)
Last updated: September 13, 2010
Vulnerability identifier: APSA10-02
CVE number: CVE-2010-2883
Platform: All
SUMMARY
A critical vulnerability exists in Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2883) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild.
We are in the process of finalizing a fix for the issue and expect to provide updates for Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 for Windows and Macintosh during the week of October 4, 2010.
Please note that these Adobe Reader and Acrobat updates represent an accelerated release of the next quarterly security update originally scheduled for October 12, 2010. With this accelerated schedule, we do not plan to release any new updates for Adobe Reader and Acrobat on October 12, 2010.
AFFECTED SOFTWARE VERSIONS
Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX
Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh
MITIGATIONS
Current exploits in the wild target the Windows platform. Customers using Adobe Reader or Acrobat 9.3.4 or earlier on Windows can utilize Microsoft's Enhanced Mitigation Evaluation Toolkit (EMET) to help prevent this vulnerability from being exploited. For more information on EMET and implementing this mitigation, please refer to the Microsoft Security Research and Defense blog. Note that due to the time-sensitive nature of this issue, testing of the functional compatibility of this mitigation has been limited. Therefore, we recommend that you also test the mitigation in your environment to minimize any impact on your workflows.
SEVERITY RATING
Adobe categorizes this as a critical issue.
DETAILS
A critical vulnerability exists in Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2883) could cause a crash and potentially allow an attacker to take control of the affected system. Adobe is aware of public exploit code for this vulnerability.
Adobe actively shares information about this and other vulnerabilities with partners in the security community to enable them to quickly develop detection and quarantine methods to protect users until a patch is available. As always, Adobe recommends that users follow security best practices by keeping their anti-malware software and definitions up to date.
We are in the process of finalizing a fix for the issue and expect to provide updates for Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 for Windows and Macintosh during the week of October 4, 2010. These updates will also address the issue referenced in Security Advisory APSA10-03 (CVE-2010-2884).
Please note that these Adobe Reader and Acrobat updates represent an accelerated release of the next quarterly security updates originally scheduled for October 12, 2010. With this accelerated schedule, we do not plan to release any new updates for Adobe Reader and Acrobat on October 12, 2010.
Users may monitor the latest information on the Adobe Product Security Incident Response Team blog at the following URL: http://blogs.adobe.com/psirt or by subscribing to the RSS feed here: http://blogs.adobe.com/psirt/atom.xml.
ACKNOWLEDGMENTS
Adobe would like to thank Mila Parkour of http://contagiodump.blogspot.com for working on this issue with Adobe to help protect our customers.
REVISIONS
September 13, 2010 - Updated information on the release schedule, and that the releases represent the next quarterly security update (originally scheduled for October 12, 2010).
September 10, 2010 - Added the Mitigations section with instructions for a mitigation option for Windows users.
September 8, 2010 - Advisory released.

Release date: September 13, 2010~~~~~~~~~~~
Vulnerability identifier: APSA10-03
CVE number: CVE-2010-2884
Platform: All
SUMMARY
A critical vulnerability exists in Adobe Flash Player 10.1.82.76 and earlier versions for Windows, Macintosh, Linux, Solaris, and Adobe Flash Player 10.1.92.10 for Android. This vulnerability also affects Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2884) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against Adobe Flash Player on Windows. Adobe is not aware of any attacks exploiting this vulnerability against Adobe Reader or Acrobat to date.
We are in the process of finalizing a fix for the issue and expect to provide an update for Adobe Flash Player for Windows, Macintosh, Linux, Solaris, and Android operating systems during the week of September 27, 2010. We expect to provide updates for Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 for Windows and Macintosh during the week of October 4, 2010.
AFFECTED SOFTWARE VERSIONS
Adobe Flash Player 10.1.82.76 and earlier versions for Windows, Macintosh, Linux, Solaris, and Adobe Flash Player 10.1.92.10 for Android
Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX
Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh
SEVERITY RATING
Adobe categorizes this as a critical issue.
DETAILS
A critical vulnerability exists in Adobe Flash Player 10.1.82.76 and earlier versions for Windows, Macintosh, Linux, Solaris, and Adobe Flash Player 10.1.92.10 for Android. This vulnerability also affects Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2884) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against Adobe Flash Player on Windows. Adobe is not aware of any attacks exploiting this vulnerability against Adobe Reader or Acrobat to date.
We are in the process of finalizing a fix for the issue and expect to provide an update for Adobe Flash Player for Windows, Macintosh, Linux, Solaris, and Android operating systems during the week of September 27, 2010. We expect to provide updates for Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 for Windows and Macintosh during the week of October 4, 2010.
Adobe actively shares information about this and other vulnerabilities with partners in the security community to enable them to quickly develop detection and quarantine methods to protect users until a patch is available. As always, Adobe recommends that users follow security best practices by keeping their anti-malware software and definitions up to date.
Users may monitor the latest information on the Adobe Product Security Incident Response Team blog at the following URL:
http://blogs.adobe.com/psirt
or by subscribing to the RSS feed here:
http://blogs.adobe.com/psirt/atom.xml
ACKNOWLEDGMENTS
Adobe would like to thank Steven Adair of the Shadowserver Foundation for working with us on this issue with Adobe to help protect our customers.
And now for another rant:
This past week we learned that the first version of Adobe Flash Player had been released for the Google Android OS for smartphones. We also learned that it is a dreadfully buggy, slow, battery consuming POS. Now we learn, if you read through the Adobe bulletins above, that Flash for Android has a 'critical' security hole.
These two Adobe Flash problems were known over a year ago. Dr. Charlie Miller warned us that Flash is the single biggest source of pwnage security holes on the Mac OS X platform. Steve Jobs made it clear that Flash for Mac is a resource hog, verifiable by anyone with a brain (which apparently is not the case with Adobe's current CEO). It is no surprise that Flash turns out to be a resource hog, running as slow as a one-legged dog on Android.
Conclusion: It's time for Flash to die.
Then what?
Contrary to popular mythology, there is no perfect replacement for Flash. The HTML5 video spec promises to replace one niche for Flash with a totally free-forever video playing alternative. (Yes kids. The patent holders for H.264 are giving it away for everyone forever). However, actual Flash applications will be more difficult to replace. These include games, slideshows, web page embedded applications, etc.
Once upon a time we dreamed that Java would take up these roles, and perhaps it may someday. But for now, Java is considered much more difficult to program than Flash, slow to run, and Java has its own security problems. Ideally a Java app building program, as easy as Flash, will appear and will use stringent security protocols, secure memory management and decent speed along with restrained CPU access. It could happen! For all I know, such a Java app builder already exists. Please post a comment if you have related information.

In the meantime, I'm supported the death sentence for Adobe Flash.
Share and Enjoy,
:-Derek
--
Thursday, August 19, 2010
Adobe 'Out Of Band' CRITICAL Updates Parade:
Acrobat and Reader v9.3.4
--
And the parade marches on. At last we have the latest in CRITICAL Adobe security hole updates. This time the updates are for Adobe Acrobat and Adobe Reader. GET THEM NOW!
Because the process of getting to actual download links at the Adobe site is a huge PITA, here are direct URLs for English Intel Mac users. Send me virtual luv:
Acrobat Reader v9.3.4 update
Adobe Acrobat 9.3.4 Pro update
The general update page for all other users and versions is HERE.
What's so CRITICAL? The update's security bulletin is HERE.
To quote Adobe:
1) The updates patch memory corruption vulnerabilities that could lead to hacked code execution on your Mac and/or program crashes. IOW its more of the same old buffer overflow problem that plagues current computer coding in general. (As found in CVE-2010-2862).
Quoting from the CVE:
2) They solve a social engineering attack security hole via PDF files that could lead to hacked code execution on your Mac. (As found in CVE-2010-1240).
Quoting from the CVE:
BTW: Looking up CVE reports is easy, if snooze inducing. Just go to the National Vulnerability Database site (at the National Institute of Standards and Technology) and search on the CVE number. Here is the URL to get you started:
National Vulnerability Database (NVD) Search Vulnerabilities
And now for a rant:
If you're wondering why these simple and specific CVE searches take a long time (zzzzz) to resolve, it's the decrepit US government. It's Microsoft Windows. It's ancient old PCs the government is too cheap to replace, cranking away on stuff that takes any modern Mac a microsecond. (But of course, the government did manage to fund the infamous 'Bridge To Nowhere' in Alaska, hardy har har, porky pork, oinky oink, so long Ted Stevens you parasite).
I was once offered a job at the Department of Wildlife. I took one look at their computers and wondered what would be the appropriate response: Running away screaming OR sauntering out laughing?
In any case, if you've ever wondered why it's so incredibly easy for The Red Hacker Alliance in Red China and other such scum to hack into US government computers, look no further for your answer. Much as I hated the Bush League, much as I'd like to support the Obama Era, this stupid state of affairs continues. Note the fact that the Obama Administration hired ex-Microsoft executives and coders to help them solve their computer security crisis. That's right! They hired the CAUSE of the problem to SOLVE the problem.
(o_0)
Hmm. What would be the appropriate response? I'll leave it to you to decide.
CUL8R!
Stay safe.
Stay secure.
Don't touch my cookies.
;-Derek
--
And the parade marches on. At last we have the latest in CRITICAL Adobe security hole updates. This time the updates are for Adobe Acrobat and Adobe Reader. GET THEM NOW!
Because the process of getting to actual download links at the Adobe site is a huge PITA, here are direct URLs for English Intel Mac users. Send me virtual luv:
Acrobat Reader v9.3.4 update
Adobe Acrobat 9.3.4 Pro update
The general update page for all other users and versions is HERE.
What's so CRITICAL? The update's security bulletin is HERE.
To quote Adobe:
These updates address CVE-2010-2862, which was discussed at the Black Hat USA 2010 security conference on Wednesday, July 28, 2010. They also incorporate the Adobe Flash Player update as noted in Security Bulletin APSB10-16.My summary:
1) The updates patch memory corruption vulnerabilities that could lead to hacked code execution on your Mac and/or program crashes. IOW its more of the same old buffer overflow problem that plagues current computer coding in general. (As found in CVE-2010-2862).
Quoting from the CVE:
Integer overflow in CoolType.dll in Adobe Reader 8.2.3 and 9.3.3, and Acrobat 9.3.3, allows remote attackers to execute arbitrary code via a TrueType font with a large maxCompositePoints value in a Maximum Profile (maxp) table.
2) They solve a social engineering attack security hole via PDF files that could lead to hacked code execution on your Mac. (As found in CVE-2010-1240).
Quoting from the CVE:
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in the Launch File warning dialog, which makes it easier for remote attackers to trick users into executing an arbitrary local program that was specified in a PDF document, as demonstrated by a text field that claims that the Open button will enable the user to read an encrypted message.~~~~~~~~~~
BTW: Looking up CVE reports is easy, if snooze inducing. Just go to the National Vulnerability Database site (at the National Institute of Standards and Technology) and search on the CVE number. Here is the URL to get you started:
National Vulnerability Database (NVD) Search Vulnerabilities
And now for a rant:
If you're wondering why these simple and specific CVE searches take a long time (zzzzz) to resolve, it's the decrepit US government. It's Microsoft Windows. It's ancient old PCs the government is too cheap to replace, cranking away on stuff that takes any modern Mac a microsecond. (But of course, the government did manage to fund the infamous 'Bridge To Nowhere' in Alaska, hardy har har, porky pork, oinky oink, so long Ted Stevens you parasite).
I was once offered a job at the Department of Wildlife. I took one look at their computers and wondered what would be the appropriate response: Running away screaming OR sauntering out laughing?
In any case, if you've ever wondered why it's so incredibly easy for The Red Hacker Alliance in Red China and other such scum to hack into US government computers, look no further for your answer. Much as I hated the Bush League, much as I'd like to support the Obama Era, this stupid state of affairs continues. Note the fact that the Obama Administration hired ex-Microsoft executives and coders to help them solve their computer security crisis. That's right! They hired the CAUSE of the problem to SOLVE the problem.
(o_0)
Hmm. What would be the appropriate response? I'll leave it to you to decide.
CUL8R!
Stay safe.
Stay secure.
Don't touch my cookies.
;-Derek
--
Friday, August 13, 2010
Adobe Flash, AIR, PDF, Acrobat and Reader:
Security Statistics Sources
--
Earlier today, I was helping out a reader at MacDailyNews.com who had the following question:
Earlier today, I was helping out a reader at MacDailyNews.com who had the following question:
'BSOD' asks: "Does anyone have statistics on exactly how many security holes have been opened up by Flash, Air, and PDF? I think that we need to see that stat."My answer is of general interest. Therefore, I am posting it here for your reading pleasure:
You can dig around at the CVE site for each of them. CVE stands for Common Vulnerabilities and Exposures. It keeps track of each reported software security problem:
http://cve.mitre.org/
Wikipedia.org also covers each of them and gives a general description of their security:
Adobe Flash: "As of May 17, 2010, The Flash Player has 77 CVE entries, 34 of which have been ranked with a high severity (leading to arbitrary code execution), and 40 ranked medium."
Adobe PDF: "On March 30, 2010 security researcher Didier Stevens reported an "exploit" that causes an arbitrary executable to be run when a PDF file is opened, after the user accepts a warning prompt. The exploit works in several different PDF viewers including Adobe Reader and Foxit Reader."
And, earlier this year Adobe were embarrassed into creating the Adobe Product Security Incident Response Tearm (PSIRT). You can keep up with their blog here:
http://blogs.adobe.com/psirt/
Adobe maintain their Security Bulletins and Advisories page, going back to 2005, here:
http://www.adobe.com/support/security/
• There are approximately 88 Adobe Flash security bulletins.
• There are 6 Adobe PDF security bulletins.
• There are over 100 Adobe Acrobat security bulletins.
• There are over 100 Adobe Reader security bulletins.
• The only Adobe AIR related bulletin is the Adobe Flash bulletin from June 10, 2010.
Wednesday, August 11, 2010
New CRITICAL Adobe Flash Player v10.1.82.76
& Adobe Air v2.0.3 Updates
--
Today Adobe updated Flash Player to version 10.1.82.76 and Adobe Air to version 2.0.3. The updates patch 6 CRITICAL security holes. Here are the security patch details:
Lately, Adobe's Flash Player has been considered the most dangerous application for Mac OS X from a security point of view. It is important to keep track of ALL Adobe updates at this point in time. We are still waiting for NEW updates to Adobe Acrobat and Adobe Reader that patch security holes announced last week HERE.
--
Today Adobe updated Flash Player to version 10.1.82.76 and Adobe Air to version 2.0.3. The updates patch 6 CRITICAL security holes. Here are the security patch details:
Critical vulnerabilities have been identified in Adobe Flash Player version 10.1.53.64 and earlier. These vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system.The download links are provided on Adobe's Security Bulletin page HERE.
This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-0209).
This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2188).
This update resolves multiple memory corruption vulnerabilities that could lead to code execution (CVE-2010-2213).
This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2214).
This update resolves a vulnerability that could lead to a click-jacking attack. (CVE-2010-2215).
This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2216).
Adobe recommends users of Adobe Flash Player 10.1.53.64 and earlier versions update to Adobe Flash Player 10.1.82.76. Adobe recommends users of Adobe AIR 2.0.2.12610 and earlier versions update to Adobe AIR 2.0.3.
Lately, Adobe's Flash Player has been considered the most dangerous application for Mac OS X from a security point of view. It is important to keep track of ALL Adobe updates at this point in time. We are still waiting for NEW updates to Adobe Acrobat and Adobe Reader that patch security holes announced last week HERE.
--
Tuesday, July 13, 2010
Windows Users ONLY:
Adobe Screw Up Yet-Again!
Acrobat & Reader Updates
DON'T Fix PDF Security Hole
--
For Frack's sake! Adobe = Idiotic Security.
I'm patience counting again: 1 - 2 - 3 . . .
NOTE: This is ONLY a Windows user problem. We Mac OS X users can sit back and gasp. But we are NOT affected (as far as we can tell at this time).
We know Adobe security is bad. We know their attitude toward their security problems is bad. But now we can verify that Adobe are indeed idiots at security. This incident throws their security incompetence into a whole other ballpark.
Enough ranting from me. Windows Users, read and weap this message from Intego:
Last Adobe Reader and Acrobat Update Doesn’t Fix PDF Bug
"... It turns out that Adobe’s fix was not enough. Adobe is aware of the issue and will be issuing an update to the update soon."
Keep in mind, Mac users, that if you use Windows you ARE affected. This means if you load Windows via virtualization or natively via Boot Camp. This PDF exploit is active in-the-wild. Beware.
Again, only Acrobat 8 and Reader 8 are safe. You can roll back to those versions and you're fine. It's Windows versions 9.x that are being exploited. Do NOT use them at this time on the Internet. Do NOT use them with any PDF file that you have not verified as 100% authentic and safe.
And of course, if you're affected, write Adobe a great big 'Thank You' note for being so kind, caring and conscientious toward their customers. /s
[Newbies: "/s" designates sarcasm]
--
For Frack's sake! Adobe = Idiotic Security.
I'm patience counting again: 1 - 2 - 3 . . .
NOTE: This is ONLY a Windows user problem. We Mac OS X users can sit back and gasp. But we are NOT affected (as far as we can tell at this time).
We know Adobe security is bad. We know their attitude toward their security problems is bad. But now we can verify that Adobe are indeed idiots at security. This incident throws their security incompetence into a whole other ballpark.
Enough ranting from me. Windows Users, read and weap this message from Intego:
Last Adobe Reader and Acrobat Update Doesn’t Fix PDF Bug
"... It turns out that Adobe’s fix was not enough. Adobe is aware of the issue and will be issuing an update to the update soon."
Keep in mind, Mac users, that if you use Windows you ARE affected. This means if you load Windows via virtualization or natively via Boot Camp. This PDF exploit is active in-the-wild. Beware.
Again, only Acrobat 8 and Reader 8 are safe. You can roll back to those versions and you're fine. It's Windows versions 9.x that are being exploited. Do NOT use them at this time on the Internet. Do NOT use them with any PDF file that you have not verified as 100% authentic and safe.
And of course, if you're affected, write Adobe a great big 'Thank You' note for being so kind, caring and conscientious toward their customers. /s
[Newbies: "/s" designates sarcasm]
--
Tuesday, June 29, 2010
They're Here!
Adobe CRITICAL Updates:
Acrobat & Reader & Flash Player
--
As promised, Adobe skipped their dopey 'quarterly' security update schedule and pushed out updates to Adobe Acrobat, Reader and Flash Player before the end of June. Gee thanks. Let's hope this incident puts the 'quarterly' security update stooopidity in the grave where it belongs.
Before I send you to the sources, I get to be a grumbling curmudgeon. Be warned that Adobe made the process of updating Adobe Acrobat, Reader and Flash Player yet-another PITA with a number of pages to click through to just download the things. So apparently, whoever made Adobe updating the most heinous process in the entire computer community, has not yet been fired from the company.
What A Shame.
For your pleasure, I have dug through the pages of Adobe bureaucratic garbage for you in order to provide direct download URLs:
Acrobat 9.3.3 Pro update
Adobe Reader 9.3.3 update for Intel Macs
Adobe Reader 9.3.3 update for PPC Macs
Adobe Flash Player 10.1.53.64
The simple URL for Flash Player is courtesy of my pals at VersionTracker.com
REMINDER: If you have installed the Mac OS X 10.6.4 update and/or Apple Security Update 2010-004, you have NOT NOT NOT updated to this CRITICAL latest version of Flash Player. Apple only included the old dangerous version. Thankfully, Apple's updater does not remove the newer version if you already installed it.
THEREFORE: If you haven't already, you must DIY install the Adobe Flash Player version 10.1.53.64. Apple won't do it for you. I don't know why! They just won't.
--
As promised, Adobe skipped their dopey 'quarterly' security update schedule and pushed out updates to Adobe Acrobat, Reader and Flash Player before the end of June. Gee thanks. Let's hope this incident puts the 'quarterly' security update stooopidity in the grave where it belongs.
Before I send you to the sources, I get to be a grumbling curmudgeon. Be warned that Adobe made the process of updating Adobe Acrobat, Reader and Flash Player yet-another PITA with a number of pages to click through to just download the things. So apparently, whoever made Adobe updating the most heinous process in the entire computer community, has not yet been fired from the company.
What A Shame.
For your pleasure, I have dug through the pages of Adobe bureaucratic garbage for you in order to provide direct download URLs:
Acrobat 9.3.3 Pro update
Adobe Reader 9.3.3 update for Intel Macs
Adobe Reader 9.3.3 update for PPC Macs
Adobe Flash Player 10.1.53.64
The simple URL for Flash Player is courtesy of my pals at VersionTracker.com
REMINDER: If you have installed the Mac OS X 10.6.4 update and/or Apple Security Update 2010-004, you have NOT NOT NOT updated to this CRITICAL latest version of Flash Player. Apple only included the old dangerous version. Thankfully, Apple's updater does not remove the newer version if you already installed it.
THEREFORE: If you haven't already, you must DIY install the Adobe Flash Player version 10.1.53.64. Apple won't do it for you. I don't know why! They just won't.
--
Saturday, June 5, 2010
New Adobe Security Holes:
Get Pwned Via Flash Player, Acrobat
or Adobe Reader
--
RISK: CRITICAL
--
RISK: CRITICAL
--
Adobe have posted a warning that current versions of Flash Player, Acrobat and Adobe Reader have a DANGEROUS security hole that is currently being exploited out in the wild. Here are some reading sources:Security Advisory for Flash Player, Adobe Reader and Acrobat
Adobe Warns of Critical Flaw in Flash, Acrobat & Reader
The first article above is direct from Adobe. The second article is analysis by Brian Krebs, a professional computer security journalist.
You can keep track of the progress in patching this latest set of Adobe holes at either of these sites:
Adobe Security Bulletins and Advisories
Adobe Product Security Incident Response Team (PSIRT)
Because this set of security holes has been found to be exploited in the wild, I can only advise that you do NOT use any of the affected Adobe products with ANY files you encounter via the Internet.1) Get a plugin for your web browser that TURNS OFF FLASH. (They are available for both WebKit and Mozilla based browsers). Use it and don't watch any Flash until a finished update is provided by Adobe.
2) Only open your own, or verified safe PDF files via Acrobat or Adobe Reader.
If you want to be super-duper safe, trash the Adobe Flash Plugin. You will find it here on your Mac:
/Library/Internet Plug-ins/Flash Player.plugin
Wait until the finished v10.1 Flash Player plugin has been released and install it at that time. The current unsafe Mac version of Adobe Flash Player is v10.0.45.2. When the finished version of Flash Player v10.1 is available, you will find it HERE.
--
Saturday, August 1, 2009
Adobe Releases Security Patched Reader and Acrobat v9.1.3
--
As promised, on Friday, July 31, Adobe released security patched versions of Acrobat and Adobe Reader. The links in the previous article about the subject should get you started, but I've provided them again below.
NOTE: verify that you are downloading and installing versions 9.1.3 of Reader and Acrobat and not an earlier version. The download page for the Acrobat 9.1.3 update is clear regarding versions. However, the Acrobat Reader page is NOT. Therefore, after you download and install "the latest version" of Reader, go under the Help menu to "Check for Updates...". Otherwise you may have only installed an earlier version of Reader without the new security patches.
Those patch download links again:
1) Adobe Flash Player v10.0.32.18. There is a special patch for version 9 users to v9.0.246.0.
2) Adobe Air v1.5.2.
3) Adobe Reader v9.1.3.
4) Acrobat v9.1.3.
Glad to be of service!
--
As promised, on Friday, July 31, Adobe released security patched versions of Acrobat and Adobe Reader. The links in the previous article about the subject should get you started, but I've provided them again below.
NOTE: verify that you are downloading and installing versions 9.1.3 of Reader and Acrobat and not an earlier version. The download page for the Acrobat 9.1.3 update is clear regarding versions. However, the Acrobat Reader page is NOT. Therefore, after you download and install "the latest version" of Reader, go under the Help menu to "Check for Updates...". Otherwise you may have only installed an earlier version of Reader without the new security patches.
Those patch download links again:
1) Adobe Flash Player v10.0.32.18. There is a special patch for version 9 users to v9.0.246.0.
2) Adobe Air v1.5.2.
3) Adobe Reader v9.1.3.
4) Acrobat v9.1.3.
Glad to be of service!
--
Thursday, July 30, 2009
Critical Adobe Security Patches Arrive, Again
--
I just gotta rant for a couple paragraphs:
The most disappointing thing I learned this week is that Adobe knew about this current crop of security holes last December, 2008. So why are we only learning about it now and only getting patches now. Didn't I say Adobe sucks?
And isn't it amusing that Adobe patched up one slew of security holes last month, and waited on this slew of further security holes. What do they do over at their offices? Argue about whether to patch? How to patch? When to patch? How long can they delay it without people saying 'Adobe sucks"? I know they have a messed up work culture over there. Get with it dummies!
The Patches:
1) Adobe Flash Player v10.0.32.18. There is a special patch for version 9 users to v9.0.246.0.
2) Adobe Air v1.5.2
3) Adobe Reader v9.1.3 - Theoretically available Friday, July 31
4) Acrobat v9.1.3 - Theoretically available Friday, July 31
NOTE: Verify which version you have downloaded. Adobe often don't mark what specific version you are downloading. Instead they may tell you that you are downloading "the latest version" when in fact you are NOT. You need to DIY update whatever you downloaded to the actual 'latest version'. Adobe provide no warning whatsoever. Adobe know about this problem and maybe will stop this practice in the future.
As I say ad nauseam: We're still in the Stone Age of Computing, and in the future they will pity us for the clunky junky stuff we had to put up with. (o_0)
--
I just gotta rant for a couple paragraphs:
The most disappointing thing I learned this week is that Adobe knew about this current crop of security holes last December, 2008. So why are we only learning about it now and only getting patches now. Didn't I say Adobe sucks?
And isn't it amusing that Adobe patched up one slew of security holes last month, and waited on this slew of further security holes. What do they do over at their offices? Argue about whether to patch? How to patch? When to patch? How long can they delay it without people saying 'Adobe sucks"? I know they have a messed up work culture over there. Get with it dummies!
The Patches:
1) Adobe Flash Player v10.0.32.18. There is a special patch for version 9 users to v9.0.246.0.
2) Adobe Air v1.5.2
3) Adobe Reader v9.1.3 - Theoretically available Friday, July 31
4) Acrobat v9.1.3 - Theoretically available Friday, July 31
NOTE: Verify which version you have downloaded. Adobe often don't mark what specific version you are downloading. Instead they may tell you that you are downloading "the latest version" when in fact you are NOT. You need to DIY update whatever you downloaded to the actual 'latest version'. Adobe provide no warning whatsoever. Adobe know about this problem and maybe will stop this practice in the future.
As I say ad nauseam: We're still in the Stone Age of Computing, and in the future they will pity us for the clunky junky stuff we had to put up with. (o_0)
--
Saturday, July 25, 2009
July's Round of Critical Adobe Vulnerabilities: New, Fresh, Dangerous
--
For those of you who took earlier advice from Intego or myself and killed off ADOBE READER, good work, because Adobe have released yet-another CRITICAL SECURITY ADVISORY! But this time it also includes FLASH as well as Acrobat. You knew it had to happen. Tsk tsk Adobe.
Here is where you can read all about it. I'm not going to quote the advisory. Just know that it was written by someone who is Windows-centric and it provides NO HELP for Mac users. Brilliant! Typical! ... As they say in Britain.
So I came up with my own stopgap probably sort of solution if you insist upon keeping Adobe Reader, Acrobat and the Flash Plug-in on your system. I originally posted this over at MacDailyNews.com. Please note that the preference setting names in Acrobat can be slightly different from the names I provide here for Adobe Reader. Otherwise, the setting changes are identical:
(If you really need to view web page embedded Flash files, try using FireFox running with the latest version of the DownloadHelper extension and download them onto your computer. I love it. Extra crunchy. Also be sure to use the NoScript extension for added safety from bad JavaScript. And be super duper safe by adding on the McAfee SiteAdvisor extension. And to have almost god-like security be sure to add in ...).
--
For those of you who took earlier advice from Intego or myself and killed off ADOBE READER, good work, because Adobe have released yet-another CRITICAL SECURITY ADVISORY! But this time it also includes FLASH as well as Acrobat. You knew it had to happen. Tsk tsk Adobe.
Here is where you can read all about it. I'm not going to quote the advisory. Just know that it was written by someone who is Windows-centric and it provides NO HELP for Mac users. Brilliant! Typical! ... As they say in Britain.
So I came up with my own stopgap probably sort of solution if you insist upon keeping Adobe Reader, Acrobat and the Flash Plug-in on your system. I originally posted this over at MacDailyNews.com. Please note that the preference setting names in Acrobat can be slightly different from the names I provide here for Adobe Reader. Otherwise, the setting changes are identical:
WHAT TO DO, my best guesstimation:Alternatives: Use Apple's Preview to open, view and create PDF files. To play Flash files that are not stuck in web pages, I use MPEG Streamclip. For web page embedded Flash files, you're hosed. Sorry. Write hate mail to Adobe.
Since the information Adobe provided is Windows-centric and a total FAIL for Mac users, seeing as Mac OS X has no-such-thing as .dll files, here is what I guesstimate is what's required to stop this vulnerability:
1) In Adobe Reader Preferences, go to "Multimedia Trust (Legacy)" and UNCHECK "Allow Multimedia Operations". That should kill running any Flash crap in PDF files.
2) In the Preferences, go to "Trust Manager" and UNCHECK "Allow opening of non-PDF file attachments with external applications". That should prevent any embedded Flash crap from running anywhere else on your computer as well.
3) In the Preferences, go to "JavaScript" and UNCHECK "Enable Acrobat JavaScript". That will disable a PDF from even being able to call the Flash plug-in for embedded Flash crap. (Considering the sewer of malware code that JavaScript has become, thank you Microsoft, I'd leave JavaScript off FOREVER if you want to seriously be safe).
*** Or to be extra special safe: Delete BOTH Adobe Reader AND their Flash plug-in from your computer. :-)
AND! Delete these folders, if you've got them:
/Applications/Utilties/Adobe Utilities/Adobe Updater5
and
/Applications/Utilties/Adobe Utilities/Adobe Updater6
AND AND! To be extra special safe, do a Get Info on the Adobe Utilities folder, noted above, and LOCK IT! This will prevent any installers from replacing the nasty Adobe Updater folders and the auto-installation garbage they contain, preventing Adobe from reinstalling Adobe Reader or Flash.
RIP Adobe insecure buggy crapware. :-P
NOTE: If you use other Adobe software, be sure to DIY check for updates on Adobe's website regularly. Adobe has some great software! But they also make some crap insecure software. Protect yourself. :-D
(If you really need to view web page embedded Flash files, try using FireFox running with the latest version of the DownloadHelper extension and download them onto your computer. I love it. Extra crunchy. Also be sure to use the NoScript extension for added safety from bad JavaScript. And be super duper safe by adding on the McAfee SiteAdvisor extension. And to have almost god-like security be sure to add in ...).
--
Wednesday, April 29, 2009
Dump Adobe Reader? Yeah, why not.
--
Intro: I never like articles with a title ending in a question mark. You know what you're going to get: no answer to the question. Therefore, they are typically filler. Yawn on that. So here is my question and answer title. Let's get to the point right off the bat: Adobe Reader is a security risk.
The chatter on the net this past week has come to the conclusion that the long line of security holes in Adobe Reader over the past two years is enough already. Dump the thing. It's like my conclusion from decades past that Windows, among its many disappointments, is too much of a security risk to use professionally. That any business or any government uses it greatly concerns me. But it's not Microsoft bashing day. It's Adobe bashing day. If you don't need Adobe Reader, don't use it. Thankfully, Mac OS X users have Apple's Preview application, which has not got the JavaScript vulnerabilities of Adobe Reader. So use Preview instead. It's not totally immune to infected PDF files, but it's much safer than Adobe Reader.
OK, it's not like anyone's Mac got pwned by using Adobe Reader. There is no malware targeting Macs that I know of that weasels its way in via holes in Adobe Reader. So really there is no major alarm going off telling us to kick Adobe Reader off the bus for having cooties. But considering that Mac OS X is the safest professional operating system on the planet (not that I'm dissing Linux mind you), avoiding Adobe Reader at this time is a very good idea.
Personally, I've been a fan of PDF since Adobe Acrobat version 3. It's brilliant and has only become better over time. Thank you Adobe, and especially thank you for making it an open standard. Its integration into the core of Mac OS X is incredible. However, Adobe allowed in some poor code, including support for the catastrophe oddly known as JavaScript. I'll skip my usual lecture on how it got its misnomer and how it was ruined as a standard by Microsoft. Simply know that it is a security holey mess. Apple has gotten burned by JavaScript in QuickTime since 2006. The same JavaScript insecurities are equally plaguing Adobe Reader. Apple got control of their JavaScript problems. Adobe are still playing catch up.
Me, I'll still continue to use Acrobat. I'll still keep Reader around for when I absolutely need it. And there are indeed times when I require Reader. But I'm also going to keep an eye on the latest Reader problems and continue to update it (manually!) when updates are offered.
--
Intro: I never like articles with a title ending in a question mark. You know what you're going to get: no answer to the question. Therefore, they are typically filler. Yawn on that. So here is my question and answer title. Let's get to the point right off the bat: Adobe Reader is a security risk.
The chatter on the net this past week has come to the conclusion that the long line of security holes in Adobe Reader over the past two years is enough already. Dump the thing. It's like my conclusion from decades past that Windows, among its many disappointments, is too much of a security risk to use professionally. That any business or any government uses it greatly concerns me. But it's not Microsoft bashing day. It's Adobe bashing day. If you don't need Adobe Reader, don't use it. Thankfully, Mac OS X users have Apple's Preview application, which has not got the JavaScript vulnerabilities of Adobe Reader. So use Preview instead. It's not totally immune to infected PDF files, but it's much safer than Adobe Reader.
OK, it's not like anyone's Mac got pwned by using Adobe Reader. There is no malware targeting Macs that I know of that weasels its way in via holes in Adobe Reader. So really there is no major alarm going off telling us to kick Adobe Reader off the bus for having cooties. But considering that Mac OS X is the safest professional operating system on the planet (not that I'm dissing Linux mind you), avoiding Adobe Reader at this time is a very good idea.
Personally, I've been a fan of PDF since Adobe Acrobat version 3. It's brilliant and has only become better over time. Thank you Adobe, and especially thank you for making it an open standard. Its integration into the core of Mac OS X is incredible. However, Adobe allowed in some poor code, including support for the catastrophe oddly known as JavaScript. I'll skip my usual lecture on how it got its misnomer and how it was ruined as a standard by Microsoft. Simply know that it is a security holey mess. Apple has gotten burned by JavaScript in QuickTime since 2006. The same JavaScript insecurities are equally plaguing Adobe Reader. Apple got control of their JavaScript problems. Adobe are still playing catch up.
Me, I'll still continue to use Acrobat. I'll still keep Reader around for when I absolutely need it. And there are indeed times when I require Reader. But I'm also going to keep an eye on the latest Reader problems and continue to update it (manually!) when updates are offered.
--
Subscribe to:
Posts (Atom)