Adobe update available for Flash but no fix for the PDF Reader…yet.
June 11, 2010
As promised earlier in the week, Adobe has released the update for Flash and it is available for download.
The easiest way to update is to visit the adobe update site and follow in on screen instructions for your browser and operating system.
If you have installed a beta version of the Flash player you are advised to remove this first before installing the update. Adobe have full instructions on how to remove Abode Flash Player.
But if you are having issues, simply follow Adobes Common Issues help page.
Reader
Adobe Reader still suffers from the vulnerability but Adobe announced that “We expect to provide an update for Adobe Reader and Acrobat 9.3.2 for Windows, Macintosh and UNIX by June 29, 2010.”
In the mean time, you can mitigate against infection using the following methods.
Adobe Reader and Acrobat – Windows
Deleting, renaming, or removing access to the authplay.dll file that ships with Adobe Reader 9.x and Acrobat 9.x mitigates the threat for those products, but users will experience a non-exploitable crash or error message when opening a PDF file that contains SWF content.
The authplay.dll that ships with Adobe Reader 9.x and Acrobat 9.x for Windows is typically located at C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll for Adobe Reader or C:\Program Files\Adobe\Acrobat 9.0\Acrobat\authplay.dll for Acrobat.
Adobe Reader 9.x – Macintosh
- Go to the Applications->Adobe Reader 9 folder.
- Right Click on Adobe Reader
- Select Show Package Contents
- Go to the Contents->Frameworks folder
- Delete or move the AuthPlayLib.bundle file
Acrobat Pro 9.x – Macintosh
- Go to the Applications->Adobe Acrobat 9 Pro folder.
- Right Click on Adobe Acrobat Pro
- Select Show Package Contents
- Go to the Contents->Frameworks folder
- Delete or move the AuthPlayLib.bundle file
Adobe Reader 9.x- UNIX
- Go to installation location of Reader (typically a folder named Adobe)
- Within it browse to Reader9/Reader/intellinux/lib/ (for Linux) or Reader9/Reader/intelsolaris/lib/ (for Solaris)
- Remove the library named "libauthplay.so.0.0.0"