John at myITforum.com

Mostly gadgets, but I'll occassionally get sidetracked...

Adobe pulls a fast one…

What a way to have immediate deployment of a new product…don’t patch your old products to fix a vulnerability, release a new one…

Security Bulletin for Flash Player and Security Advisory for Flash Professional CS3

The big news today is that CS4 has launched, along with Flash Player 10. We have released a Security Bulletin to correspond with the Flash Player 10 release. Flash Player 10 addresses Flash Player-specific aspects of the overall clickjacking issue that has been making news recently, and also includes a mitigation for recent clipboard attacks as well as other security enhancements. For customers who cannot upgrade to Flash Player 10, a Flash Player 9 update is currently scheduled for early November. We’ve also posted a Security Advisory for Flash Professional CS3, informing customers of potential issues with malformed SWF files. Note that Flash CS4, and Flash Player, are not vulnerable to these issues.

We’d like to thank Robert Hansen and Jeremiah Grossman once again for their help, and extend special thanks to Liu Die Yu of TopsecTianRongXin for working with us on the clickjacking issue.

Posted by David Lenoe on October 15, 2008 10:59 AM | Permalink

Comments

skissinger said:

You know, I don't mind... if flashplayer 10 a) installs via SMS. b) uninstalls. at all. (some iterations of fp9 didn't actually let you do so--I had to adjust their MSI w/a transform).  as an extra added bonus, c) upgrades from 9, by actually removing 9.  Versions of fp9 would sometimes not actually remove the old versions' files, just add new stuff and mess with the registry.

I haven't looked at fp 10 yet.  And I may never do; my job responsibilities have changed. And I don't think I want to look at it just for fun.

# October 15, 2008 10:26 PM

Roger said:

I'm a bit surprised there hasn't been a security bulletin forcing users to pay to upgrade from Adobe Acrobat 8 to 9.

# October 16, 2008 12:08 AM