Adobe backpedals, will now patch software for free
- 13 May, 2012 09:07
- Comments
After being pummeled by customers and security experts for telling users to spend hundreds of dollars on upgrades because it wasn't going to patch critical bugs in older versions of its software, Adobe has reversed course.
The company will now fix the eight vulnerabilities in the one-year-old Illustrator and Flash Professional CS5.5, and the two-year-old Photoshop CS5, an Adobe spokeswoman said via email late Friday.
There will be no charge for the updates.
A post by Adobe's product security response team to its official blog spelled out the change.
"We are in the process of resolving the vulnerabilities addressed in these security bulletins in Adobe Illustrator CS5.x, Adobe Photoshop CS5.x and Adobe Flash Professional CS5.x, and will update the respective security bulletins once the patches are available," the team wrote.
Neither the response team nor the Adobe spokeswoman gave a reason for the change, or even acknowledged the brouhaha prompted by the firm's earlier announcement.
Last week, Adobe said it would not quash the bugs -- one is in Flash Professional, two in Photoshop and five in Illustrator -- and told customers to upgrade to the Creative Suite 6 (CS6) editions if they wanted the patches.
Adobe launched CS6 last month.
The steep upgrade prices, however, triggered anger among users and incredulousness among security researchers.
"For all that they have been doing to revise their face of security, this just brings them right back into the dunce cap seat," said Andrew Storms, director of security operations at nCircle Security, in a Friday interview before Adobe changed its tune.
Upgrade prices for the three applications range from $99 for Flash Professional to $249 for Illustrator, while an upgrade to CS6 Design & Web Premium, the least-expensive edition that includes all three, costs $375.
On Saturday, Storms noted Adobe's reversal.
"So it looks like Adobe is going to patch Photoshop CS5 after all," Storms said on Twitter. "Maybe they listened to all the mad people?"
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer, on Google+ or subscribe to Gregg's RSS feed. His email address is gkeizer@computerworld.com.
See more by Gregg Keizer on Computerworld.com.
Read more about security in Computerworld's Security Topic Center.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- Update to Security Bulletins for Adobe Illustrator (APSB12-10), Adobe Photoshop (APSB12-11) and Adobe Flash Professional (APSB12-12) « Adobe Product Security Incident Response Team (PSIRT) Blog
- Adobe: Pay upgrade price to patch critical bugs - Computerworld
- @gkeizer
- Gregg Keizer - Google+
- Computerworld Gregg Keizer News
- gkeizer@computerworld.com
- Gregg Keizer - Computerworld
- Security Topic Center - Computerworld
- Australian Red Cross Blood Service Enhances the Performance of Its Mission-Critical Applications
- HP Helps NEC Reduce Network Management Costs and Gain Efficiencies
- Defending Against Increasingly Sophisticated Cyber Attacks
- Reference Architectures for Virtualisation
- Cost Savings Through Virtual Patching
-
Australia suspected to have PRISM data: Ludlam
-
Australia Post’s mail business to lose $200 million this year
-
Australia Post’s mail business to lose $200 million this year
-
Microsoft's ambivalence about Office on the Web gives Apple shot with iWork on iCloud
-
3 Lessons Learned From a Failed Customer Feedback Test
-
The SPARC Difference - Reduce Risks, Cut Costs, Power Innovation
Despite current economic factors, IT investment continues to be fueled by the need for better and more agile IT capabilities to support an enterprise’s business strategy, as well as to keep up with the rapidly changing demands of the ‘always-on’ user. However, budgets are squeezed and executives are under pressure to reduce capital expenditure and streamline administrative costs. A key strategy is to consolidate and refresh existing IT infrastructures. In this whitepaper, compliments of Remora, find out what technology can add value and enable you to change the shape of your IT budget and, to transform IT into a force for change and innovation. -
Leading Through Connections – Insights from the Global Chief Executive Officer Study
IBM’s 2012 Global CEO study follows face-to-face discussions with more than 1,700 CEOs and senior public sector leaders from around the globe. The findings examine how CEOs are responding to the complexity of increasingly interconnected organisations, markets, societies and governments. For example, almost one-quarter of CEOs say their organisations operate below par in terms of driving value from data. CEOs have expressed frustration about their inability to capitalise on available information. This is because: “The time available to capture, interpret and act on information is getting shorter and shorter.” CEO, Chemicals and Petroleum, United States Given the need for deeper business insight, the best performing organisations are more adept at converting complex data into insights, and insights into action. Download Entire Report Now. -
Tips Choosing a Cloud Service Provider
Because cloud is still a new and evolving business model, it can be argued that the decision to select a cloud service provider should be approached with even greater diligence than other IT decisions. Many providers use the same term to define very different services, “hybrid cloud” is one example, making it difficult to compare offers. This whitepaper will help enterprises evaluate their options in two critical areas: the cloud service portfolio and the service provider itself. Read now.
















