Flash Player, Adobe Reader and Acrobat Vulnerability Exploited in Wild
Sunday, June 6, 2010 at 07:12PM
drStrangeP0rk in Acrobat, Adobe, Exploits, Flash, Reader, Wild

Adobe has issued a security bulletin related to the authplay.dll component in Reader and Acrobat (On the Mac /applications/AdobeReader9/AdobeReader.app/Contents/Frameworks/AuthPlayLib.bundle/Contents/MacOS/AuthPlayLib) and Adobe Flash Player 10.0.45.2. This vulnerability has been exploited in the wild. Adobe has not issued an update or schedule as of now but Flash Player Candidate Release "Gala Preview2" does not appear to be vulnerable. 

Another Solution suggested is removing the AuthPlayLib, this will result in a crash if you open a PDF with Flash content. Users/Administrators should use Preview.app (In Seat-Belt) for PDF files from un-trusted sources. 

Update on Tuesday, June 8, 2010 at 08:47AM by Registered CommenterdrStrangeP0rk

Adobe has stated in recent post that Flash Player 10.1 Release Candidate is confirmed not to be vulnerable and the patch from 10.x is expected to be released June 10, 2010.

http://www.adobe.com/support/security/advisories/apsa10-01.html

Update on Wednesday, June 9, 2010 at 07:30AM by Registered CommenterdrStrangeP0rk

The Adobe Reader and Acrobat will be aviable June 29, 2010. 

http://blogs.adobe.com/psirt/2010/06/update_to_security_advisory_fo.html

 

Update on Thursday, June 10, 2010 at 06:34PM by Registered CommenterdrStrangeP0rk

Update is aviable, you may need to manually download it.

http://blogs.adobe.com/psirt/2010/06/security_bulletin_-_adobe_flas_3.html

Download

http://get.adobe.com/flashplayer/

Visit settings manager and confirm your settings.

http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager.html

Article originally appeared on magmatic.com (http://www.magmatic.com/).
See website for complete article licensing information.