I've seen Adobe do quite a few security announcements over the years but I've never actually seen any of the exploits in action or explained. I'm really curious how serious these exploits really are and if they are actually practical (or more theoretical). Any references greatly appreciated.
New Adobe Flash 0day, have a nice weekend
51–60 of 74 posts
Re: New Adobe Flash 0day, have a nice weekend
#52Adobe Reader and Acrobat on MacOSX also include a file named authplay.dll ? (Any chance Apple's 'Preview' PDF-reading capabilities are similarly vulnerable?)
Apple's 'Preview' PDF viewer has lots of security vulnerabilities. Simple fuzzing will quickly find plenty of 0day.
Re: New Adobe Flash 0day, have a nice weekend
#53Re: New Adobe Flash 0day, have a nice weekend
#54Shouldn't a fix come out with that announcement? If they're offering a temporary fix, shouldn't they at least push that temp fix as an update, and fully update the issue later? This leaves the non-technically inclined out in the cold, and informs those who may not know of the exploit of its existence. Just something as simple as removing authplay.dll for Acrobat and Reader, and even upgrading the current version of F…
Since it's already in the wild, better to let people know so they can use the workaround.
Re: New Adobe Flash 0day, have a nice weekend
#55Shouldn't a fix come out with that announcement? If they're offering a temporary fix, shouldn't they at least push that temp fix as an update, and fully update the issue later? This leaves the non-technically inclined out in the cold, and informs those who may not know of the exploit of its existence. Just something as simple as removing authplay.dll for Acrobat and Reader, and even upgrading the current version of F…
I believe its Adobe policy to only announce security issues if a fix is available. At least, that's how the policy was a few years back. I assume it's still the same.
Re: New Adobe Flash 0day, have a nice weekend
#56Shouldn't a fix come out with that announcement? If they're offering a temporary fix, shouldn't they at least push that temp fix as an update, and fully update the issue later? This leaves the non-technically inclined out in the cold, and informs those who may not know of the exploit of its existence. Just something as simple as removing authplay.dll for Acrobat and Reader, and even upgrading the current version of F…
Securing and maintaining software up-to-date in a non-intrusive way is hard in a way that works for all (ie, personal computers and large networks of computers), I think it is also a good business opportunity.
Re: New Adobe Flash 0day, have a nice weekend
#57Earlier quoted context omitted.
I'm not quite sure what the relevancy of this is, unless you're actually such a rabid Apple hater that you automatically see any mention of Adobe flaws as an argument for Apple or somesuch.
Lots of software has security problems. It's pretty rare that any of them show up on the front page of HN. They just tend to blend into background noise as "not interesting" unless it's particularly interesting to the community for some reason. Given that one of Job's major points for not allowing Flash on iDevices was the security of the platform, the only conclusion one can draw for having a security notice show up…
No, I think it was mostly the irrelevancy that got you downvoted.
"you successfully made the connection between Adobe and Apple."
Umm, what you posted was a link to something about Apple, so yeah, I think I could be justified in believing that was the connection you were trying to make.
"I bet there was never an Adobe Flash related security posting on the front page of HN."
http://news.ycombinator.com/item?id=164725 http://news.ycombinator.com/item?id=1105508 http://news.ycombinator.com/item?id=801713 http://news.ycombinator.com/item?id=164725
"Apple is also not free from issues with its platform. Yet these never make it to the front page of HN."
http://news.ycombinator.com/item?id=876334 http://news.ycombinator.com/item?id=684743
"It's pretty rare that any of them show up on the front page of HN."
http://news.ycombinator.com/item?id=1129882 http://news.ycombinator.com/item?id=692036 http://news.ycombinator.com/item?id=690592 http://news.ycombinator.com/item?id=872533 http://news.ycombinator.com/item?id=709869 http://news.ycombinator.com/item?id=393009
"the only conclusion one can draw for having a security notice show up on the front page is that there are a lot of Adobe haters out there."
The only conclusion? Really? Some people might be interested because it is an unfixed vulnerability actively being exploited in software that's on 95% of PCs. Just a thought.
"Apple wouldn't provide the necessary APIs"
You're certainly not approaching this from a standpoint of hating Apple, if that's the interpretation you put on the abysmal performance of Flash on OS X for many many years. I should note that Silverlight has always had stellar performance relative to Flash on any Mac I've used them on.
"unwanted counter information"
Or again, complete irrelevancy.
Re: New Adobe Flash 0day, have a nice weekend
#58Chromium v6.0.417.0
Re: New Adobe Flash 0day, have a nice weekend
#59Did anybody else read "The Flash Player 10.1 Release Candidate (...) does not appear to be vulnerable" as "we ran the exploit and it didn't work"?
Re: New Adobe Flash 0day, have a nice weekend
#60Chromium + Flash + Linux vulnerable as well? How does one a) even know what version of flash is embedded in Chromium b) other than constantly killing the flash process how does one disable flash in Chromium Chromium v6.0.417.0
After finding out about this 'sploit, I looked in vain for the authplay.dll . It turns out I had a newer build that wasn't listed as vulnerable (and I couldn't find the file itself, where does it usually reside?).