On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

November 17th, 2008

Adobe AIR hits 'critical' security turbulence

Posted by Ryan Naraine @ 1:59 pm

Categories: Adobe, Arbitrary Code Execution, Browsers, Data theft, Exploit code, Flash, Java, Malware, Passwords, Patch Watch, Responsible disclosure, Web 2.0

Tags: Adobe Systems Inc., Adobe AIR, Macromedia Flash Player, Scripting Languages, Security, Software/Web Development, Web Development, Ryan Naraine

Adobe Air update fixes critical vulnerabilityBuried in today’s flurry of feel-good Adobe news is this less flattering nugget:  Adobe AIR is vulnerable to several critical vulnerabilities that could expose users to code execution attacks.

The company released AIR 1.5 with fixes for previously discussed flaws in Flash Player (which is embedded into AIR) and a patch for a separate issue that allows the execution of untrusted JavaScript with elevated privileges.

As this bulletin explains, the issues are all remotely exploitable:

  • A vulnerability has been identified in Adobe AIR 1.1 and earlier that could allow an attacker who successfully exploits this potential vulnerability to execute untrusted JavaScript with elevated privileges. An Adobe AIR application must load data from an untrusted source to trigger this potential vulnerability. In addition, AIR 1.5 includes a Flash Player update to resolve the critical issues outlined in Flash Player Security Bulletin APSB08-22, as well as issues included in Flash Player Security Bulletins APSB08-20 and APSB08-18. Adobe recommends AIR customers update to Adobe AIR 1.5. These issues are remotely exploitable.

Adobe recommends all users of Adobe AIR 1.1 and earlier versions upgrade to the newest version AIR 1.5 by downloading it from the AIR Download Center, or by using the auto-update mechanism within the product when prompted.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 6 Talkback(s)
Actually..
The problem isn't that it was fixed.

The problem is that is happened to begin with. On a product that the user didn't even want to install! It gets installed automatically whether you like it to not (unless you don't use Adobe products).... (Read the rest)
Posted by: AzuMao Posted on: 11/19/08 You are currently: a Guest | | Terms of Use
And thanks to AIR being bunding anticompetitively with Reader...  PB_z | 11/17/08
I hate the bundle....  JoeMama_z | 11/17/08
AIR = the suck  mikes2nd | 11/19/08
Negative hook for a story about security improvements  bcswartz | 11/18/08
RE: Adobe AIR hits 'critical' security turbulence  dorkiedorkfromdorktown | 11/19/08
Actually..  AzuMao | 11/19/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here