PDA

View Full Version : [NEWS] 0 day Flash Player


GmG
28-10-2010, 17:08
Description
A vulnerability has been reported in Adobe Flash Player, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an unspecified error and can be exploited to execute arbitrary code.

The vulnerability is reported in version 10.1.85.3. Other versions may also be affected.

NOTE: The vulnerability is currently being actively exploited.



http://secunia.com/advisories/41917


A Security Advisory (APSA10-05) has been posted in regards to a new Flash Player, Adobe Reader and Acrobat issue (CVE-2010-3654). A critical vulnerability exists in Adobe Flash Player 10.1.85.3 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems; Adobe Flash Player 10.1.95.2 and earlier versions for Android; and the authplay.dll component that ships with Adobe Reader 9.4 and earlier 9.x versions for Windows, Macintosh and UNIX operating systems, and Adobe Acrobat 9.4 and earlier 9.x versions for Windows and Macintosh operating systems. This vulnerability (CVE-2010-3654) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against Adobe Reader and Acrobat 9.x. Adobe is not currently aware of attacks targeting Adobe Flash Player.

Adobe Reader and Acrobat 8.x, and Adobe Reader for Android are confirmed not vulnerable. Mitigations for Adobe Reader and Acrobat 9.x are included in the Security Advisory.

We are in the process of finalizing a fix for the issue and expect to provide an update for Adobe Flash Player 10.x for Windows, Macintosh, Linux and Android by November 9, 2010. We expect to make available an update for Adobe Reader and Acrobat 9.4 and earlier 9.x versions during the week of November 15, 2010.

We will continue to provide updates on this issue via the Security Advisory section of the Adobe website as well as the Adobe PSIRT blog.


http://blogs.adobe.com/psirt/2010/10/security-advisory-for-adobe-flash-player-adobe-reader-and-acrobat-apsa10-05.html

sampei.nihira
29-10-2010, 16:39
http://contagiodump.blogspot.com/2010/10/potential-new-adobe-flash-player-zero.html

Nel link sopra il dropper, che consente di testare la vulnerabiltà, in formato zip protetto da pass.
Sarebbe interessante se qualcuno si cimenta con EMET 2.0 per vedere di mitigare la vulnerabiltà prima del 9/11 ovviamente.

c.m.g
30-10-2010, 11:32
Adobe, una falla senza patch (http://punto-informatico.it/3024192/PI/News/adobe-una-falla-senza-patch.aspx) su punto informatico

FulValBot
30-10-2010, 12:16
mmm ma esce direttamente la versione 10.2 o un fix per quello 10.1 ?

sampei.nihira
05-11-2010, 15:24
Signori, ci sarebbe da aggiornare la versione "malata" di flash con la nuova "sana". ;)

Per ogni utente che legge la notizia ed aggiorna mi aspetto almeno un tè (ai giapponesi piace il tè :O :) ) offerto a questo pescatore.

Buon cambio di versione.