Chicog Posted December 20, 2012 Share Posted December 20, 2012 And I thought Oracle were slow! Adobe to Patch 2-year-old Shockwave Vulnerability Next Year The flaws could allow remote code to be executed, one of the most severe kinds of vulnerabilities By Jeremy Kirk Wed, December 19, 2012 . IDG News Service — Adobe plans in February to close a dangerous hole in its Shockwave application that causes the application to be downgraded when a user launches older multimedia content, allowing hackers to target years-old vulnerabilities. The U.S. Computer Emergency Readiness Team (U.S. CERT) issued an advisory on the vulnerability, which could allow an attacker to deliver malware and execute arbitrary code, considered to be one of the most dangerous kinds of flaws. U.S. CERT notified Adobe of the problem on Oct. 27, 2010, but an Adobe spokesperson said Wednesday that the problem will be closed with the next major upgrade of Shockwave, scheduled for Feb. 12. "We are not aware of any active exploits or attacks in the wild using this particular technique," said Wiebke Lips, senior manager with Adobe corporate communications. Adobe did not consider the issue a high risk to users. Shockwave is used to play content created in Macromedia and Adobe Director, which offers advanced tools for creating interactive content, including Flash. U.S. CERT cited Adobe documentation that says if a user encounters content that does not specify to use the latest Shockwave version 11, an older ActiveX control is downloaded that pulls components of the older Shockwave 10 player. Shockwave uses an ActiveX control when content is requested within Microsoft's Internet Explorer and is present as a plugin in other browsers, according to U.S. CERT. The Shockwave 10 runtime contains vulnerabilities as well as the application's "Xtras," which are components of content. The downgrading of Shockwave to an older version also opens up Adobe's Flash multimedia application for attack, the agency said. "Because of this design, attackers can simply target vulnerabilities in the Shockwave 10 runtime, or any of the Xtras provided by Shockwave 10," U.S. CERT wrote. "For example, the legacy version of Shockwave provides Flash 8.0.34.0, which was released on November 14, 2006 and contains multiple, known vulnerabilities." U.S. CERT has published two other document describing the issues with Xtras and Flash, which Adobe said it is analyzing. The first concerns Shockwave's downgrading to an older Flash version, which affects both Windows and Apple's Mac. The second involves the problem of malicious Xtras. "We are not aware of any active exploits or attacks in the wild using these techniques either," Lips said. Link to comment Share on other sites More sharing options...
pault17 Posted December 21, 2012 Share Posted December 21, 2012 Slow? I'm using Foxit PDF Reader instead of Adobe's Reader.. Adobe Reader has been removed from my system for years. Earlier this week I was prompted by Adobe to restart my system to 'activate' their Reader. It had been (re)installed without my consent. Even better. The default application for PDF files was already set to their reader although I still had to reboot before the application could be used. Sneaky but FAST! Link to comment Share on other sites More sharing options...
Chicog Posted December 21, 2012 Author Share Posted December 21, 2012 I use PDF-XChange myself, but yes, Adobe absolutely suck the big one. However, there is good news on the horizon: http://www.theregister.co.uk/2012/12/20/firefox_20_h264_windows/ Link to comment Share on other sites More sharing options...
astral Posted December 22, 2012 Share Posted December 22, 2012 Not exactly inspiring for such widely used SW Bug reported in 2010 supposed to be fixed in Feb 12 and it is now December. Link to comment Share on other sites More sharing options...
Khun Jean Posted December 22, 2012 Share Posted December 22, 2012 (edited) Six things that will never ever be on my computer. Anything from Apple (iTunes, quicktime) and Adobe (flash, shockwave, reader, AIR). Adobes programmes worked ok a few years since introduction, now they are worse and worse with each update. I try them sometimes to see if it got better, and really it is sad to see the 'improvements'. Apple i think has ulterior motives to make any windows computer impossible to work on and promote their own product. And just to be 'fair'. The MS office suit stays from my computer used for development. It slows it down too much. Notepad Yeah!! Edited December 22, 2012 by Khun Jean Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now