Welcome to WebmasterWorld Guest from

Forum Moderators: open

Message Too Old, No Replies

Adobe warns of new Reader and Flash security problems


travelin cat

7:32 pm on Feb 12, 2010 (gmt 0)

WebmasterWorld Administrator travelin_cat is a WebmasterWorld Top Contributor of All Time 10+ Year Member

Adobe yesterday warned of new critical holes in Reader and Flash Player:

A critical vulnerability has been identified in Adobe Flash Player version and earlier. This vulnerability (CVE-2010-0186) could subvert the domain sandbox and make unauthorized cross-domain requests.

Adobe recommends users of Adobe Flash Player and earlier versions update to Adobe Flash Player Adobe recommends users of Adobe AIR version and earlier versions update to Adobe AIR

Adobe is planning to release an update for Adobe Reader 9.3 for Windows, Macintosh and UNIX, Adobe Acrobat 9.3 for Windows and Macintosh, and Adobe Reader 8.2 and Acrobat 8.2 for Windows and Macintosh to resolve critical security issues, including the Flash Player issue described in Security Bulletin APSB10-06. Adobe expects to make these updates available on February 16, 2010.

More from Adobe here. [adobe.com]

and here [adobe.com]


11:51 am on Feb 15, 2010 (gmt 0)

WebmasterWorld Senior Member 5+ Year Member

Adobe needs to stop crashing my computer while attempting to download updates to fix these things too.


1:19 pm on Feb 15, 2010 (gmt 0)

5+ Year Member

This is the reason I do not install their software - I can do without reader, unfortunately I still need flash plugin - is there a better/more secure alternative.


2:30 pm on Feb 15, 2010 (gmt 0)

5+ Year Member

I finally got rid of adobe reader a year ago and use foxit which has a footprint about 10% the size without the phoning home and auto updates.


4:14 pm on Feb 15, 2010 (gmt 0)

5+ Year Member

I really wish there was more competition in the "Flash" player field. With Adobe's the only real solution at the moment, it's the Windows giant-target problem all over again. Endless exploits all aimed at the one thing that everyone will be running.

(I have tried SWFdec and Gnash but they both failed to make sense of the obscenely complex sites that prevail these days.)

If you need (or just enjoy) the "dynamic" content, make sure you're using something like the Firefox add-ons NoScript and "Request Policy" which make it much less likely you'll be stung by drive-by attacks.


11:23 pm on Apr 6, 2010 (gmt 0)

5+ Year Member

Well, the problem is that so many websites can't simply post their information in HTML with "fancy Flash graphics". They want to turn the whole page into some application with attempts to protect their so-called "intellectual property" by making it impossible to copy and paste the text. I have tried running NoScript in Firefox, but so many websites end up looking strange without all the content displayed.

I don't mind seeing a "pretty page". I just wish more webmasters would be minimalists with regards to running scripts.

Featured Threads

Hot Threads This Week

Hot Threads This Month