The Small Business Consultancy

Archive: February 2009

Security Update for Adobe Flash Player

Hot on the heels of the Acrobat Reader security problem, a flaw has been discovered in the Adobe Flash Player. To quote the Adobe Security Bulletin for this problem:

A potential vulnerability has been identified in Adobe Flash Player 10.0.12.36 and earlier that could allow an attacker who successfully exploits this potential vulnerability to take control of the affected system. A malicious SWF must be loaded in Flash Player by the user for an attacker to exploit this potential vulnerability. Additional vulnerabilities have been addressed in this update. Adobe recommends users update to the most current version of Flash Player available for their platform.

You can check the version of Flash Player installed by visiting the Adobe About Flash Player webpage.

It is vital to upgrade to 10.0.22.87 immediately. Get it HERE.

We’ve found it is better to uninstall the old version before installing the new one.

Technorati Tags: , ,

Hackers Exploiting Security Hole in Acrobat Reader

A very serious security problem has been been discovered with Adobe Acrobat Reader that affects both 8.1.2 and 9.0.0 versions. This newly discovered security vulnerability is being actively exploited, albeit it in small scale so far, by the bad guys.

Adobe won’t have a security patch until March 12th for v9 and thereafter for v8.

Some security products already detect the exploit attacks as a virus, but the following workaround should mitigate against the attacks being used by the bad guys until a patch is available:

  1. Start Acrobat Reader.
  2. Select Edit -> Preferences -> Javascript.
  3. Uncheck the box that says Enable Acrobat JavaScript.
  4. Close the preferences dialog box and exit Acrobat Reader.

More information on this security problem can be in the following web articles:

The Register article : "New in-the-wild attack targets fully-patched Adobe Reader"

Adobe Security Bulletin: "Buffer overflow issue in versions 9.0 and earlier of Adobe Reader and Acrobat "

Remember, the bad guys are out to get you, so be safe!

Technorati Tags: , , ,