Share

Related Links

Related Stories

  • Adobe fixes Flash flaw in five days
    Adobe has quietly fixed the 'critical' security flaw affecting its Flash and Reader software that it revealed earlier this week. The issue has been fixed in an urgent patch folded in with a raft of updates that are claimed to solve 32 documented problems with Adobe's software.
  • Adobe accelerates Flash Player fixes
    Adobe announced that it will issue an unscheduled security patch to address vulnerabilities found in its Flash Player operating on Windows, Mac, and Linux. The company expects to have this fix ready by June 10.
  • Adobe warns of critical multi-platform security flaw
    Adobe has released a major warning over a critical vulnerability in its Flash Player 10.0.45.2 and earlier editions for Windows, Apple Mac, Linux and Solaris platforms.
  • Applications under attack says Microsoft, Adobe
    Many in the security field agree that attack vectors have rapidly moved from exploiting operating system vulnerabilities to the application layer. Security specialists from Microsoft and Adobe lent their opinions as to why this is the case.
  • Latest Mac OS X version still needs Adobe update
    The latest version of the Mac OS X operating system includes Adobe's Flash Player, but it is not the latest patched version.

Top 5 Stories

News

Latest Mac OS X version still needs Adobe update

16 June 2010

The latest version of the Mac OS X operating system includes Adobe's Flash Player, but it is not the latest patched version.

Mac users who update to version 10.6.4 of the operating system should ensure their Flash Player is updated to version 10.1.53.64, said Brad Arkin, director, product security and privacy at Adobe Systems.

However, Mac OS 10.6.4 does not appear to downgrade users who have previously updated to Flash Player 10.1.53.64, so there is no need for them to reapply the update, he said.

On June 10, Adobe rushed out a fix for zero-day vulnerabilities in its Flash Player for Windows, Mac and Linux to fix vulnerabilities reported in a security advisory by the software firm on June 4.

Adobe confirmed that criminals have been exploiting the flaw using malicious Flash swf files, which are typically opened by the web browser's Flash Player plugin, or through PDFs that have maliciously encoded Flash components embedded inside them.

Those malicious PDFs are typically opened by Reader or Acrobat, which include their own versions of Flash Player, due to be patched on June 29.

The updated software from Adobe fixes 32 vulnerabilties, but it is still unclear when a similar update will be issued for Flash Player on Solaris.

Adobe's Flash and Reader software have become prime hacking targets in the past year because of the software's large install base.

The company is considering increasing the frequency of security updates along the same lines as Microsoft's monthly Patch Tuesday, Arkin has said in recent weeks.

This story was first published by Computer Weekly

This article is featured in:
Application Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.