Adobe warns of zero-day Flash, Reader vulnerability; Windows, Mac, Linux, Solaris, Android affected

Security

Adobe released a security bulletin today warning of a critical, zero-day vulnerability in their Reader and Flash Player software. The bulletin notes that an unpactched system could “crash [your system] and potentially allow an attacker to take control of the affected system.” The vulnerability is affecting:

  • Adobe Flash Player 10.1.85.3 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems
  • Adobe Flash Player 10.1.95.2 and earlier for Android
  • Adobe Reader 9.4 and earlier 9.x versions for Windows, Macintosh and UNIX
  • Adobe Acrobat 9.4 and earlier 9.x versions for Windows and Macintosh
  • Adobe Reader and Acrobat 8.x are confirmed not vulnerable. Adobe Reader for Android is not affected by this issue.

Adobe is promising an update to fix the issue by November 9. Hit the read link to read more and for mitigation instructions for your specific platform.

Read

66 Comments
  • Sandy S. Schwartz.

    I’m a contract lawyer in Manhattan and thus very smart. I notice that this zero day venerability just adds fuel to the fire that Steve Jobs burns about how bad Flash is and antiquated. I wouldn’t be surprised if Apple has hackers behind this “zero day.”

    • FireGVW

      except for how, if as a lawyer you should, read the whole title and article it effects Macs as well. just not iphones because he left it out of them.

      • Sandy S. Schwartz.

        I did. They want it to affect everybody to prove their point. Besides it will be shored up by Nov 9th and if theres a virus Apple Store will help you.

      • FireGVW

        o i’m sorry it effects iphones too because its a adobe reader problem as well. so now your arguement now has now basis.

      • FireGVW

        so your saying they want to crash their own systems to prove a point? sound like an evil archvilian to me, not anything like steve jobs….. wait a minute!

      • Dave

        iPhones don’t have Adobe Reader installed, they have a PDF reader written by Apple

      • FireGVW

        i plused you cause i was wrong, feel free to minus my comment into oblivian… i should get an award tho. first person ever to admit their wrong on BGR

      • Andrew

        Lol. iPhones don’t use Adobe Reader!

      • Sandy S. Schwartz.

        thats implied in my post smart guy.

      • FireGVW

        where and how? the only mention of apple is how you think they’re behind all this?

    • Ben

      Yes, I can see your intelligence showing- your spelling is impeccable :)

      venerability != vulnerability

      • Sandy S. Schwartz.

        Big deal this is a blog dude. I wrote it very fast.

      • http://BoyGeniusReport.com Mentat

        Use your real name in a blog = FAIL

    • Dave

      Or, you know, maybe Jobs could be telling it like he sees it? Software vulnerabilities have been around as long as software.

      Adobe have been traditionally worse than other companies at putting processes in place to stop them from happening. Hackers have never needed Steve Jobs to encourage them to attack something installed on ~97% of web browsers.

      The one thing that is for certain – it is 100% up to Adobe to fix this on all platforms or you are at risk. What if they give up on yours; what if they decide that WebOS or WM6.5 isn’t worth the bother of fixing this one? You’re out of luck!

      Do you _really_ want a future where one company who doesn’t really care has control of the entire web’s security and future or maybe should we be all fighting for an open web instead?

      • DigitalFreak

        QUOTE: Do you _really_ want a future where one company who doesn’t really care has control of the entire web’s security and future or maybe should we be all fighting for an open web instead?

        You mean like Microsoft with their 90% plus market share domination on desktop OS?

      • Dave

        Absolutely like that!! I’d be just as disappointed if we all relied on Microsoft’s IE6 ActiveX plugin formats. Or anything equivalent from Apple. Or Google’s new Chrome plugins, sorry, apps.

        But the fact that it’s Adobe means it’s worse because they seem quite incompetent and too small a company to deal with the security issues properly. Microsoft have at least responded with some good security in Win7 and IE9

      • MicroNix

        Come on now. You don’t buy that Microsoft Win7 and IE anything is more secure than their prior versions? If you watch the monthly Microsoft security patches (affectionately named “patch Tuesday” every second Tuesday of the month), there is no OS or IE version that is exempt from the blast of patches. Most range from XP all the way through 7 and Windows 2003 server through 2008. And Microsoft has had some of its biggest number of monthly patches ever just in the last 6 – 8 months. To say Microsoft has gotten more secure on ANYTHING Windows related is laughable.

      • Sup

        @MicroNix
        To say that IE and Windows aren’t secure OSes is quite a shallow point of view. Although I use Chrome because I prefer the minimalist approach, IE and Windows receive a bunch of updates due to the fact that Microsoft is always making an attempt to keep their products secure at all angles. I mean, I would rather have a company that pushes out dozens of updates on their product than one that doesn’t push out updates at all. Actually, that’s how antivirus, malware, and spyware programs work. If it isn’t kept updated, it can’t be kept safe.

    • DigitalFreak

      You’re not a contract lawyer your some ignorant M$ fanboi who lives in his parents basement and works at McDonalds shitting out their burger patties.

      It just boggles the mind that idiots like you actually take the time to utterly idiotic posts and think the average person is stupid enough to believe it. Here’s some advice to you Schwartz stop downloading porn, get out of the basement, get a real job, get a girlfriend and see what you can do about losing your virginity..

    • Sandy S. Schwartz.

      I really don’t think I deserve minuses on this one. Just think about it. Job’s hates that Android now has flash.

      • DigitalFreak

        I don’t think you deserve minuses either. I simply think you deserve a real brain.

      • DJPitaB

        Why would he hate that? Not only is Flash terribly slow and unreliable on Android (even moreso than on a desktop computer), but if you really did believe that Apple was behind all this, then wouldn’t Steve Jobs actually love the fact that Android’s Flash capabilities make it vulnerable to the security issue? It would give the iPhone that much more of an advantage… It’s clear that your logic is seriously flawed, and I pity anyone who ever employs you as a lawyer.

    • brswa

      You are the reason for a ban hammer on blogs. No one cares that your a contract lawyer (read: Burger King employee) who lives in Manhattan (read: Parent’s Basement) and your no contribution comment to every post here on BGR.
      Please quit trolling and have an opinion from now on. And yes, sue me, since you’ve already told that to countless other readers on here.

    • bob

      I think I hired you as an escort once

      • bob

        Sandy i mean ;)

    • John Peters

      The iPhone and Mac are very prone to viruses and hacks. Apple should fix their own problems before they hack others. Apple sucks!

    • Thomas32811

      You’re not as smart as you think you are. Your misspelled vulnerability…

  • TheNewReign

    Nah, Flash a problem?

    • TheTrueNewReign

      I’m with you on that sarcastic one. !!! haha

  • Fernando

    but, but thats unpossible for a vulnorability to be present on mac, the commercials told me so….

    • Sandy S. Schwartz.

      I think he’s being sarcastic so I’m giving you a plus.

  • Tariq Aziz

    I caused it.

  • Brilliant Idea

    How about we call it ASCHMOBIE? wahahahahahhaha!

  • Goofan (aka Apple Hater)

    I knew it sandy is right. This was done by the evil Cupertino empire to destroy all that’s good (ie google.) I can’t believe how low apple is willing to go to destroy our lords st google. Evil evil!!!!!

  • Herbert Maxwell “The Gonz” Martin

    Adobe flash is “dying” in favor of HTML5 pushed by Google and Apple. Hmmm Wonder who is causing an attack on Flash?

  • DigitalFreak

    Eric Schmidt creeps me out. When he smiles he reminds me of a huge mutant rat that’s had its DNA spliced with human DNA.

    • Goofan (aka Apple Hater)

      Ah! How dare you insult the perfect one. As far as goofans are concerned Eric is PERFECT in every possible way and so is google.

      • DigitalFreak

        I’m seeing an invasion of the body snatchers scenario in the ranks of Google. Only difference from the movie is the body snatchers all look like mutant rat people (Eric Schmidt).

      • Goofan (aka Apple Hater)

        Eric told us goofans flash was perfect and I trust him and google 1000%. I’m convinced apple is behind this.

      • DigitalFreak

        Oh my God….the mutant rat people got to you already didn’t they? The real Goofan is now a pile of goo fertilizing the flowerbeds outside the head Google offices.

      • Goofan (aka Apple Hater)

        Yes they did. I’m so confused. Nevertheless I trust in a higher power and that’s google and their tireless warrior Eric Schmidt!

      • MicroNix

        As opposed to someone in a black turtleneck who uses the word magical in every sentence making him a fairy?

      • DigitalFreak

        You want him bad don’t you?

    • Fernando

      He looks nothing like master splinter

      • DigitalFreak

        His black turtleneck does remind me of a sith from Star Wars though

  • Jack Evan

    Is it just me who thinks that everytime I come across name “Adobe” in news, it’s definitely got to do with some serious security flaw being discovered/ patched in one of their crappy software?

    • Mgl323

      I’m pretty sure they’re other people that think how you do.

  • Mgl323

    Oh Adobe, you never change do you.

    • http://www.innovatoys.com/ Cindy Auligny

      Maybe :-)

  • craphos

    unfortunately, vulnerabilities will continue to pop up on flash. it’s sad, but jobs is somewhat right… flash will die sooner or later. i’m a windows mobile user, but i’ve seen flash on android devices also and looks like 1Ghz is still not enough.

    • DigitalFreak

      Agreed. All the videos I’ve run across has shown flash slow some pretty powerful smart phones to a crawl. I wish Adobe would get its act together and admit they screwed up and go back to rewriting its core flash codes so people could actually have a good user experience with flash.

      • MicroNix

        Hmm, that’s funny indeed since I’m able to watch flash video on an original Droid with no slowness in the video. The videos you ran across aren’t from Apple’s big bad testing lab where they proved that holding *any* smartphone with a death grip interferes with the signal were they?

      • DigitalFreak

        Don’t be such a Fandroid and practice some free thought. If you must know the videos I ran across were from various users on youtube who ran android handsets as well as CNET and TechnoBuffalo hands on videos. Unlike others on here I don’t drink anyone’s cool-aid and reserve judgment on a certain subject until I’ve done the proper research and made my own decision based on what I’ve read and seen as well as asked others with first hand experience.

        Flash as a technology mobile or otherwise is shit. Its especially bad on mobile technology and besides being buggy it kills your battery life, hogs processor power thereby slowing down your handset and is an all around shit user experience. I know enough people who have used it and say its shit. When the vast majority of people I know who use it say its shit and there’s enough reviews also saying its shit THEN ITS SHIT. End of discussion.

      • jason6g

        i agree, original droid flash is smooth as butter for me. granted im overclocked to 1ghz but still.

        as for the flash haters, it has its flaws, but unfortunately its almost everyone on the web. until someone comes up with a better technology that becomes more widespread, ill continue to enjoy flash.

        im also mindful with my information, not paranoid, but im conscious enough to not keep anything important on any of my devices that are connected. everything will have its flaws. whether its a galaxy s that cant sync email, or a macbook that has a flickering display.

  • phoo

    Its time to trash Flash for Good and Adobe

    Flush em! worthless nonsense

    there is absolutely no reason to
    use them.

    FLUSH!!!

  • Neo

    Flash FAIL.

  • jonathan

    Sounds like Jobs and Apple were right and HTML5 is the future. This is not so good news for the haters. Seriously even without this security flaw, flash is slowly on it’s way out.

    Posted from BGR Mobile (iPhone).

  • MacMan

    Flash sucks what’s new ?

  • Elektra

    So in the meantime, what do those devices that support Adobe Flash do? Oh yeah, they can’t do anything but wait for Adobe to fix it. Exactly the reason why Apple does want to support it for their ipad and iphone. Flash support is too dependent on Adobe.

    • Goofan (aka Apple Hater)

      Gosh don’t worry. Google and Eric trust Adobe and because of that and because Eric and Google have told us to, we should TRUST THEM. They will protect us. Believe me!

      • MicroNix

        Do you just take a stupid pill every time you wake up in the morning?

      • DigitalFreak

        I think he takes the whole bottle

  • http://www.uggbootshop.org uggbootshop.org

    Gaft Gave, ugg boots

    • DigitalFreak

      Could you please just f%# off and stop the spamming crap

  • Da Girl Impressa

    Talikin bout flash won’t impress gurls.

    • DigitalFreak

      No but I’m sure really flashing them will. Once you post bail come back and tell us how that worked out for you.

blog comments powered by Disqus