12 Feb 2010
Barely a month after Adobe issued a fix to mend a critical flaw in its Reader and Acrobat products, the company has been forced to rush out another owing to a serious bug in its Flash Player, which received a patch yesterday.
Adobe said in a security bulletin that the vulnerability, identified in Adobe Flash Player version 10.0.42.34 and earlier, could be used by attackers to trick a web browser into executing code remotely.
This means that the browser could make an unauthorised cross domain request and directly install unauthorised software onto users' machines. Such flaws are commonly exploited by malware writers.
The Reader and Acrobat patches are due next Tuesday, as the products are also susceptible to the Flash Player flaw. Adobe usually issues security updates for its software on a quarterly basis.
But the problem is that hackers could understand the nature of the Reader and Acrobat bugs by examining the Flash Player patch and use the information to attack them, although Adobe said that it was not aware of any such activity to date.
Users concerned about the Flash Player flaw being exploited could mitigate the threat by opening documents outside their browser, the company added.
Adobe issued a critical security update addressing eight vulnerabilities in its Reader and Acrobat 9.2 builds for the Mac, Windows and Unix in mid-January. Six of the vulnerabilities, if exploited, would also enable attackers to undertake remote code execution on targeted systems.
The security of Adobe's software has come under greater scrutiny over the past year as attackers have increasingly exploited such vulnerabilities to hack into computers.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Hands on with the highly anticipated Android 4.0 Ice Cream Sandwich hybrid tablet
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
(Roc Search - Network Support Engineer, 2nd line, 3rd...
3rd Line Engineer / Infrastructure Engineer - Berkshire...
MySQL SQL SERVER DBA / Database Administrator - Online...
PMO Analyst - Banking Client A financial organisation...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?