Live data from Hacker News

New Adobe Flash 0day, have a nice weekend

adobe.com

1–10 of 74 posts

Re: New Adobe Flash 0day, have a nice weekend

#2
Shouldn't a fix come out with that announcement?

If they're offering a temporary fix, shouldn't they at least push that temp fix as an update, and fully update the issue later? This leaves the non-technically inclined out in the cold, and informs those who may not know of the exploit of its existence.

Just something as simple as removing authplay.dll for Acrobat and Reader, and even upgrading the current version of Flash Player to the 10.1 beta, just temporarily… anything other than just announcing it and not patching it at all.

I don't know if this is a standard way of dealing with zero day exploits, but it sure doesn't seem like a good way.

Re: New Adobe Flash 0day, have a nice weekend

#3
post #2

Shouldn't a fix come out with that announcement? If they're offering a temporary fix, shouldn't they at least push that temp fix as an update, and fully update the issue later? This leaves the non-technically inclined out in the cold, and informs those who may not know of the exploit of its existence. Just something as simple as removing authplay.dll for Acrobat and Reader, and even upgrading the current version of F…

Since it's already in the wild, better to let people know so they can use the workaround.

Re: New Adobe Flash 0day, have a nice weekend

#8
post #4

The fix is to install 10.1 RC, and delete/rename/ACL authplay.dll. I wont comment on the whole "use our RC release" as a mitigation path in production env's....

10.1 has had 7 release candidate releases so far. Been running them for a while and they don't seem anymore crashy than 10.0 and the GPU acceleration is nice.

Also it would be a great time to upgrade Firefox to the 3.6.4 release candidate for those using Firefox. Plugin process separation... yummo.

http://blog.mozilla.com/blog/2010/06/01/firefox-3-6-4-releas...

Re: New Adobe Flash 0day, have a nice weekend

#10
post #2

Shouldn't a fix come out with that announcement? If they're offering a temporary fix, shouldn't they at least push that temp fix as an update, and fully update the issue later? This leaves the non-technically inclined out in the cold, and informs those who may not know of the exploit of its existence. Just something as simple as removing authplay.dll for Acrobat and Reader, and even upgrading the current version of F…

I believe its Adobe policy to only announce security issues if a fix is available. At least, that's how the policy was a few years back. I assume it's still the same.
Post reply on HN