Adobe warns of Shockwave bug
- 22 October, 2010 11:13
- Comments
Adobe warned Thursday of a critical bug in its Shockwave Player that affects both Windows and Macintosh PCs.
The bug, which was publicly disclosed Thursday, "could cause a crash and potentially allow an attacker to take control of the affected system," Adobe said in a message on its website.
In its security advisory, Adobe said it considers the issue "critical," and is working on a patch for the flaw. The company isn't saying when that patch will ship, however.
So far, there aren't any reports of attacks that leverage the bug, but this type of public disclosure of a serious bug is often a harbinger of future attacks.
Adobe's Reader software has been a regular target for Web-based attacks over the past year, and while the Shockwave Player is used by about half as many people as Reader, it's probably good enough for many hackers.
"Hundreds of millions of computers with Internet connectivity have Shockwave installed, so, this will obviously be an attractive target for attackers," security vendor Symantec said Thursday in an e-mailed statement.
If attacks do become a problem, users can disable Shockwave in their Web browsers until a patch becomes available.
The bug was found by Shahin Ramezany, a security researcher who said he released details of the problem to celebrate the fact that he now has 1,000 followers on Twitter. He had earlier promised to release an Adobe 0day when he crossed that threshold.
Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert's e-mail address is robert_mcmillan@idg.com
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- Adobe Shockwave player rcsL chunk memory corruption 0day
- Security Advisory for Adobe Shockwave Player (APSA10-04) « Adobe Product Security Incident Response Team (PSIRT) Blog
- Adobe - Security Advisories: APSA10-04 - Security Advisory for Adobe Shockwave Player
- Adobe - Shockwave Player Adoption Statistics
- earlier promised to release an Adobe 0day when he crossed that threshold
- @bobmcmillan
- robert_mcmillan@idg.com
-
NBN build gaining momentum daily: Quigley
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Monday Grok: Will Siri crack the walls of GOOG?
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Miercom Report - Plug and Play Switches
Avaya engaged Miercom to evaluate the plug and play features and ease of configuration of the ERS 4548GT- PWR Edge Switch. The energy efficiency of the ERS was compared to similar switches and is discussed in this report as well. Read on. -
The mobile print enterprise - How IT consumerisaton is driving anytime, anywhere printing
The widespread adoption of smartphones and tablets, across Android, BlackBerry and Apple iOS platforms, has broadened the effectiveness of professional workers to remotely support business requirements. A continued reliance on printing amongst many businesses means IT must provide enterprise mobile printing capabilities that are secure and reliable. This not only ensures employees remain productive but also allows mobile printing to be tracked and controlled – vital in an era when many businesses face financial, environmental and security concerns. Read more. -
Security Threat Report 2012
This threat report shares the latest research on hacktivism, online threats, mobile malware, cloud computing, and social network security looking ahead to the coming year.
-
Iphone 3G Portable Genius
-
Bounce, Tumble, and Splash! Simulating the Physical World with Blender 3D
-
Hack Attacks Testing
-
Interaction Design 2E
-
Excel 2007 Formulas
-
Learn CSS
-
Beginning SQL Server 2005 Administration
-
Introduction to Object-oriented Analysis, Objectsoand UML in Plain English 2E Wiley International Edition
-
Code Leader








Comments
Post new comment