Avast WEBforum

Other => General Topics => Topic started by: nmb on July 23, 2009, 08:42:10 AM

Title: Another zero day in Adobe flash player
Post by: nmb on July 23, 2009, 08:42:10 AM
Hello everyone,

just found this new 0-day article in ISC,

http://isc.sans.org/diary.html?storyid=6847

avast doesn't detect it.(link in the article to virus total tells this)
Title: Re: Another zero day in Adobe flash player
Post by: DavidR on July 23, 2009, 03:31:55 PM
Very interesting article, and especially the "Regarding Flash, NoScript is your best help here, of course."

Presumable this is also sidestepped if you don't use Adobe's PDF reader, but something like FoxitPDF reader, etc.

Quote
It appears that even when JavaScript support is disabled in Adobe Reader that the exploit still works, so at the moment there are no reliable protection mechanisms (except not using Adobe Reader?).

So yet more advice to use firefox with NoScript and don't use Adobe Acrobat PDF reader ;D
Title: Re: Another zero day in Adobe flash player
Post by: nmb on July 23, 2009, 03:35:08 PM
list of other pdf readers (sometimes these are advised to use, previously when there were adobe exploits):

http://www.pdfreaders.org/
Title: Re: Another zero day in Adobe flash player
Post by: cinchez on July 23, 2009, 04:30:58 PM
Oh God!

Does Disabling the Adobe Acrobat Plug-in for FF works?

I have NoScript as well..

-AnimeLover^^
Title: Re: Another zero day in Adobe flash player
Post by: nmb on July 23, 2009, 04:37:40 PM
@addict

yes that should work for a pdf file. if you use noscript then you are safe as mentioned in the article..
Title: Re: Another zero day in Adobe flash player
Post by: DavidR on July 23, 2009, 04:38:21 PM
Does Disabling the Adobe Acrobat Plug-in for FF works?

I have NoScript as well..

Not if the PDF file which would normally be viewed on-line (using the FF plug-in) is downloaded and opened with Adobe PDF reader, as the vulnerability is also in the reader as well as adobe flash.

NoScript will only protect against the vulnerability in the flash player and then only if you haven't allowed the site to run scripts and also allow flash (NoScript, Options, Plugins tab, Forbid Adobe Flash).
Title: Re: Another zero day in Adobe flash player
Post by: nmb on July 23, 2009, 04:43:45 PM
accept with david r
Title: Re: Another zero day in Adobe flash player
Post by: Hermite15 on July 23, 2009, 04:49:32 PM
geez it's the second time in a very short time there's a bad vulnerability in adobe products...

edit: last time that concerned "reader" only and they advised to disable JavaScript (until the fix would be available): in the reader settings itself.
Title: Re: Another zero day in Adobe flash player
Post by: cinchez on July 23, 2009, 04:51:10 PM
Thanks nmb and DavidR^^

-AnimeLover^^
Title: Re: Another zero day in Adobe flash player
Post by: nmb on July 23, 2009, 04:52:54 PM
always welcome
Title: Re: Another zero day in Adobe flash player
Post by: DavidR on July 23, 2009, 06:09:46 PM
Thanks nmb and DavidR^^

-AnimeLover^^

You're welcome.
Title: Re: Another zero day in Adobe flash player
Post by: nmb on July 23, 2009, 10:54:44 PM
Why turning off Javascript won't help this time

check this blog:

http://blog.fireeye.com/research/2009/07/actionscript_heap_spray.html
Title: Re: Another zero day in Adobe flash player
Post by: Hermite15 on July 23, 2009, 11:01:37 PM
Why turning off Javascript won't help this time

check this blog:

http://blog.fireeye.com/research/2009/07/actionscript_heap_spray.html

oh, thanks for that link  ;)
Title: Re: Another zero day in Adobe flash player
Post by: nmb on July 25, 2009, 05:57:48 AM
hello everyone,

update :

Adobe 'zero-day' flaw is eight months old : http://blogs.zdnet.com/security/?p=3792
Title: Re: Another zero day in Adobe flash player
Post by: cinchez on July 25, 2009, 06:07:54 AM
WTF!?

Cant believe Adobe hasnt updated their products yet! >:(

What a fatal flaw!

-AnimeLover^^
Title: Re: Another zero day in Adobe flash player
Post by: nmb on July 25, 2009, 06:16:27 AM
@addict

according to this :http://www.adobe.com/support/security/advisories/apsa09-03.html the patch will be released on july 30.
Title: Re: Another zero day in Adobe flash player
Post by: DavidR on July 25, 2009, 03:13:32 PM
update :

Adobe 'zero-day' flaw is eight months old : http://blogs.zdnet.com/security/?p=3792

Nothing new there, same happens in other companies, one notable one ;D

So in this case, day 0 must mean they haven't even started.
Title: Re: Another zero day in Adobe flash player
Post by: nmb on July 25, 2009, 03:15:15 PM
So in this case, day 0 must mean they haven't even started.

well said.
Title: Re: Another zero day in Adobe flash player
Post by: hlecter on July 25, 2009, 03:28:50 PM
Don't know of this mitigating of the PDF document attack vector has been posted, if not it is by now:   :)

http://www.kb.cert.org/vuls/id/259425

I have renamed the 2 files mentioned in the article because I have to use Adobe Reader.

It doesn't mitigate the direct Flash vuln, so that's another story.


HL
Title: Re: Another zero day in Adobe flash player
Post by: Hermite15 on July 27, 2009, 11:53:20 AM
Adobe promises fix for critical Flash hole next week:
http://www.theregister.co.uk/2009/07/24/adobe_flash_patch_pre_alert/

Security advisory for Adobe Reader, Acrobat and Flash Player:
http://www.adobe.com/support/security/advisories/apsa09-03.html

Quote
Users may monitor the latest information on the Adobe Product Security Incident Response Team blog at the following URL:  http://blogs.adobe.com/psirt or by subscribing to the RSS feed here: http://blogs.adobe.com/psirt/atom.xml.