Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Applications
    • Applications
    • Cybersecurity
    • Development

    Adobe Patches Zero-Day XSS Flaw, Six Other Bugs in Flash Player

    Written by

    Fahmida Y. Rashid
    Published February 15, 2012
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The list of security updates IT administrators have to stay on top of this month just got a little longer as Oracle and Adobe released new patches fixing a slew of security vulnerabilities in their products.

      Adobe released a security update addressing seven critical vulnerabilities in its Flash Player software on Feb. 15, a day after it updated critical vulnerabilities in Shockwave Player. The latest Flash update addressed critical vulnerabilities in Adobe Flash Player 11.1.102.55 and earlier versions for Windows, Macintosh, Linux and Solaris. The update also affects Flash Player 11.1.112.61 and earlier versions for Android 4.x and version 11.1.111.5 and earlier for Android 3.x and 2.x.

      While this Flash release is part of Adobe’s scheduled quarterly update, one of the bugs fixed was added in at the last minute, according to an Adobe spokesperson.

      The last-minute bug, CVE-2012-0767, was a universal cross-site scripting vulnerability that could be used to take actions on a user’s behalf on any Website or Webmail provider if the user visits a malicious site. This vulnerability was already being exploited in the wild in targeted attacks against Internet Explorer users on Windows systems, according to Adobe.

      Users were being tricked into clicking on a malicious link delivered in an email message as part of a targeted attack, according to Adobe. Google is credited for reporting this vulnerability in the acknowledgements section of the security advisory.

      Adobe was unable to reproduce the exploit targeting the cross-site scripting vulnerability against the Flash component that ships with Adobe Reader and Acrobat 9.x and later, according to the advisory. In the past, critical vulnerabilities that were first exploited in Flash were later exploited in Reader and Acrobat. That doesn’t appear to be the case with the current exploit.

      The rest of the update addressed four memory corruption vulnerabilities and two security bypass vulnerabilities that could lead to code execution. If exploited, an attacker could potentially be able to take control of the affected system. However, Adobe is not aware of any exploits in the wild targeting these issues.

      €œIt sure would have been nice if Adobe bundled all their patches together,” said Andrew Storms, director of security operations at nCircle, noting that IT administrators have to rethink their patching strategies to include the latest updates with what had already been released.

      Adobe’s Shockwave Player update was released hours before Microsoft’s February Patch Tuesday release. Shortly after that, Oracle released its scheduled update for Java. In the latest security release, Oracle fixed at least 14 security vulnerabilities in the Java Runtime Environment. The new versions are Java 6 update 31 and Java 7 update 3.

      Five vulnerabilities in Java 6 were rated critical and have a Common Vulnerability Scoring System above 9, according to Wolfgang Kandek, CTO of Qualys. These flaws can be exploited through the network without authentication and are capable of providing remote control to the attacker, Kandek said.

      “Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply fixes as soon as possible,” Oracle said in its email advisory.

      Malware developers frequently write exploits targeting Java because it is so ubiquitous, according to Kandek. Oracle estimates Java is installed on more than 3 billion machines worldwide.

      Adobe products are also frequently attacked. Part of the problem with the latest exploits is that products are not being updated promptly, the company warned.

      “The majority of attacks we are seeing are exploiting software installations that are not up-to-date on the latest security updates,” the company wrote.

      It would have also been nice if Adobe could have included some workarounds for the vulnerability while patches are rolled out, Storms said.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.