Adobe Reports Critical Flash Vulnerability

LOS ANGELES — Adobe has issued a warning about a critical vulnerability in the current versions of some of its most popular software products; the latest in a series of similar warnings to affect the software giant.

According to the company, the affected programs are Flash Player (v9.0.159.0 and v10.0.22.87) for Windows, Macintosh and Linux operating systems, and the authplay.dll component that ships with Adobe Reader and Acrobat v9.x for Windows, Macintosh and UNIX operating systems.

"This vulnerability (CVE-2009-1862) could cause a crash and potentially allow an attacker to take control of the affected system," stated a company release. "There are reports that this vulnerability is being actively exploited in the wild via limited, targeted attacks against Adobe Reader v9 on Windows."

Adobe is in the process of developing a fix and expects to provide an update for Flash Player before July 30 and an update for Adobe Reader and Acrobat by July 31.

"Deleting, renaming, or removing access to the authplay.dll file that ships with Adobe Reader and Acrobat v9.x mitigates the threat for those products, but users will experience a non-exploitable crash or error message when opening a PDF that contains SWF content," Adobe advises.

According to the company, the authplay.dll that ships with Adobe Reader and Acrobat 9.x for Windows is typically located at C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll or C:\Program Files\Adobe\Acrobat 9.0]\Acrobat\authplay.dll.

"Windows Vista users should consider enabling UAC (User Access Control) to mitigate the impact of a potential exploit. Flash Player users should exercise caution in browsing untrusted websites," Adobe further cautioned, adding that "Adobe is in contact with Antivirus and Security vendors regarding the issue and recommend users keep their anti-virus definitions up to date."

John Bambenek of US-CERT's SANS Internet Storm Center says that the vulnerability is currently being exploited by malicious sites as well as via link injection into legitimate websites as part of a drive-by attack.

US-CERT is advising Windows users to disable Flash in Adobe Reader 9 and to disable the Flash Player — a move which would render most tube sites unusable to their visitors and brings with it broader implications for the online adult community and consumer's access to our wares.

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Age Verification: FSC's Mike Stabile Reports from the Frontlines

Two years into the religiously-inspired crusade to ban free access to adult material in the U.S. through carefully drafted "age verification" legislation, the constant onslaught of state-by-state proposals and laws — many of them copied from each other — can be hard to follow.

Written Erotica Platform 'Hevvn' Launches

Hevvn, a new platform aimed at erotica writers seeking to publish, promote and profit from their work, debuted Thursday.

Sssh.com's Angie Rowntree Speaks at Brown University

Sssh.com founder Angie Rowntree spoke at a Brown University class last week, discussing several topics related to adult filmmaking.

Online Industry Veteran Joe E. Passes Away

Online industry veteran Joe E has passed away, according to friends and industry associates.

Judge Acquits Backpage Defendants of Most Charges Before 2nd Retrial

A federal judge acquitted former co-owner of Backpage.com Michael Lacey and two co-defendants on most of the counts remaining from the protracted trial launched against the website operators by the Justice Department in 2018.

Adult Time Partners With Animation Studio 3DGspot

Adult Time has signed a deal to distribute content on its streaming platform from animation studio 3DGspot.

Georgia Gov. Brian Kemp Signs Age Verification Bill Into Law

Republican Gov. Brian Kemp this week signed into law a bill that includes provisions requiring age verification for viewing adult content in Georgia, mirroring legislation being sponsored around the country by anti-porn religious conservative activists.

AEBN Publishes Popular Searches by Country for February, March

AEBN has released the popular searches from its straight and gay theaters in more than three dozen countries during February and March.

HardWerk Relaunches Through YourPaysitePartner

HardWerk.com has relaunched through YourPaysitePartner (YPP).

Aylo Asks Judge to Trim Sweeping GDP-Related Lawsuit

Aylo asked a California federal judge during a hearing on Monday to drop trafficking claims from a sweeping lawsuit brought by a former GirlsDoPorn model.

Show More