Windows, Linux users should download new Player; Apple patched Mac OS X's version Monday
Adobe Systems Inc. patched its Flash Player earlier this week, fixing nine critical vulnerabilities that hackers could use to attack Windows, Mac and Linux machines.
The update addresses at least nine flaws–CVE-2007-6242, CVE-2007- 4768, CVE-2007-5275, CVE-2007- 6243, CVE-2007- 6244, CVE-2007- 6245, CVE-2007-4324, CVE-2007- 6246, CVE-2007-5476–across all platforms. Versions affected include Adobe Flash Player 9.0.48.0 and earlier, 8.0.35.0 and earlier, and 7.0.70.0 and earlier.
Adobe, which recommends that everyone updgrade to the new player, says an attacker could use those aforementioned vulnerabilities to take control of a system.
Two of the nine vulnerabilities are “input validation errors” that could “lead to the potential execution of arbitrary code.” Adobe adds:
“These vulnerabilities could be accessed through content delivered from a remote location via the user’s web browser, email client, or other applications that include or reference the Flash Player.”
"Multiple input validation errors have been identified in Flash Player 9.0.48.0 and earlier that could lead to the potential execution of arbitrary code," Adobe said in the advisory posted on the company's site. "These vulnerabilities could be accessed through content delivered from a remote location via the user's Web browser, e-mail client or other applications that include or reference the Flash Player."
Danish vulnerability tracker Secunia ASP collectively tagged the nine bugs as "highly critical," its second-from-the-top threat ranking.
The flaws can be exploited using malicious .swf files, a vector graphics format specific to Flash. Specifically, said Adobe, the vulnerabilities could be used to conduct cross-site scripting attacks, run DNS rebinding attacks that circumvent firewall defenses and elevate privileges on servers hosting Flash content.
Google Inc.'s security team was credited by Adobe with reporting two of the nine vulnerabilities, while a team at Stanford University received a nod for notifying Adobe of another pair of bugs.
"Users are recommended to update to the most current version of Flash Player available for their platform," Adobe said. The update, dubbed Flash Player 9.0.115.0, can be downloaded from the Adobe site. Solaris users, however, must download a beta of the updated Player to protect their machines.
Mac OS X users who refreshed their operating system with the 41-fix Security Update 2007-009, which Apple issued Monday, already have the revised Flash Player in hand, and don't need to take additional action.
According to Adobe, people who must rely on the older Flash Player 7 should download and install the patched version of that edition instead of 9.0.115.0. The patched Player 7 can be found here.
Search This Blog
Saturday, December 22, 2007
Microsoft confirms IE update snafu
Microsoft (NSDQ: MSFT) on Tuesday issued support documentation to address Internet Explorer problems caused by last week's security patch.
"We have been working with a small number of customers that reported issues related to the installation of MS07-069," said Kieron Shorrock, the Microsoft Security Response program manager responsible for Internet Explorer, in a blog post. "Specifically, on a Windows XP Service Pack 2 (SP2)-based computer, Internet Explorer 6 may stop responding when you try to a visit a Web site."
Microsoft Corp. acknowledged late yesterday that security patches issued last week for Internet Explorer (IE) crippled the browser for some users, but rather than rework the fix, the company offered up a registry hack work-around.
The confirmation and work-around came a week after users installed Security Update MS07-069 on Dec. 11, and users immediately began reporting that they were unable to connect to the Internet with IE or that the browser kept crashing. MS07-069, one of seven bulletins issued on December's "Patch Tuesday," fixed four critical vulnerabilities in IE 5.01, IE6 and IE7.
Although Microsoft had said on Monday that it was investigating the reports, yesterday the company owned up to the problem. "On a Windows XP Service Pack 2-based computer, Internet Explorer 6 may stop responding when you try to a visit a Web site," said Kieron Shorrock, the program manager responsible for IE at the Microsoft Security Response Center (MSRC).
In a later post to the MSRC blog, however, Shorrock downplayed the problem, saying, "We have been working with a small number of customers that reported issues related to the installation of MS07-069." He claimed that the bug appeared only in what he called "a customized installation."
"This isn't a widespread issue," Shorrock added.
That would come as a surprise to users such as Harold Decker, who manages 35 Windows XP SP2 machines at San Diego-based Gold Peak Industries NA Inc. Even though Decker described his shop's systems as "pretty plain," 29% of the PCs that installed last week's IE update had trouble accessing the Web.
Microsoft Security Bulletin MS07-069 addresses four privately reported vulnerabilities that could allow remote code execution if the user of the affected system visits a malicious Web page. MS07-069 is rated critical.
The Microsoft Knowledge Base article for Microsoft Security Bulletin MS07-069, KB942615, has been updated to acknowledge the issue. And article KB946627 explains how to edit the Windows registry to fix the instability introduced to Internet Explorer by the security patch.
According to Shorrock, the IE issue arises as a result of customization and isn't widespread.
Nonetheless, many of those affected are expressing puzzlement that Microsoft would recommend a technically tricky procedure like editing the Windows registry rather than fixing and reissuing the patch.
"With hundreds of users here running XP SP2 with IE6, how can Microsoft be serious that the solution is to edit each registry?" said Phil Shannon on the IEBlog. "Is this some sort of joke? It would be easier to have each user install Mozilla Firefox and stop using IE completely."
"We have been working with a small number of customers that reported issues related to the installation of MS07-069," said Kieron Shorrock, the Microsoft Security Response program manager responsible for Internet Explorer, in a blog post. "Specifically, on a Windows XP Service Pack 2 (SP2)-based computer, Internet Explorer 6 may stop responding when you try to a visit a Web site."
Microsoft Corp. acknowledged late yesterday that security patches issued last week for Internet Explorer (IE) crippled the browser for some users, but rather than rework the fix, the company offered up a registry hack work-around.
The confirmation and work-around came a week after users installed Security Update MS07-069 on Dec. 11, and users immediately began reporting that they were unable to connect to the Internet with IE or that the browser kept crashing. MS07-069, one of seven bulletins issued on December's "Patch Tuesday," fixed four critical vulnerabilities in IE 5.01, IE6 and IE7.
Although Microsoft had said on Monday that it was investigating the reports, yesterday the company owned up to the problem. "On a Windows XP Service Pack 2-based computer, Internet Explorer 6 may stop responding when you try to a visit a Web site," said Kieron Shorrock, the program manager responsible for IE at the Microsoft Security Response Center (MSRC).
In a later post to the MSRC blog, however, Shorrock downplayed the problem, saying, "We have been working with a small number of customers that reported issues related to the installation of MS07-069." He claimed that the bug appeared only in what he called "a customized installation."
"This isn't a widespread issue," Shorrock added.
That would come as a surprise to users such as Harold Decker, who manages 35 Windows XP SP2 machines at San Diego-based Gold Peak Industries NA Inc. Even though Decker described his shop's systems as "pretty plain," 29% of the PCs that installed last week's IE update had trouble accessing the Web.
Microsoft Security Bulletin MS07-069 addresses four privately reported vulnerabilities that could allow remote code execution if the user of the affected system visits a malicious Web page. MS07-069 is rated critical.
The Microsoft Knowledge Base article for Microsoft Security Bulletin MS07-069, KB942615, has been updated to acknowledge the issue. And article KB946627 explains how to edit the Windows registry to fix the instability introduced to Internet Explorer by the security patch.
According to Shorrock, the IE issue arises as a result of customization and isn't widespread.
Nonetheless, many of those affected are expressing puzzlement that Microsoft would recommend a technically tricky procedure like editing the Windows registry rather than fixing and reissuing the patch.
"With hundreds of users here running XP SP2 with IE6, how can Microsoft be serious that the solution is to edit each registry?" said Phil Shannon on the IEBlog. "Is this some sort of joke? It would be easier to have each user install Mozilla Firefox and stop using IE completely."
Subscribe to:
Posts (Atom)