Alert Number: 073109-01
Alert Date: 07/31/09
Alert Title: Update available for *UNPATCHED* Adobe Flash Player vulnerability
Update-to: 072309-02 "*UNPATCHED* vulnerability for Adobe Acrobat, Reader, Flash Player"
OS/Platform/Application:
Adobe Flash Player
(on Windows, Mac, Linux, and UNIX systems)
Category: UPDATE
Severity: HIGH
Attention: Flash Player Users, System Administrators, Desktop Support Personnel.
Summary: Adobe systems has released an updated version (10.0.32.18) of its popular Flash player. This update fixes a critical vulnerability in the application. Adobe and other Internet security resources have confirmed that the vulnerability is currently being actively exploited on the public Internet at this time.
Recommended Actions: Readers are encouraged to update their Flash Player to version 10.0.32.18 as soon as possible. Flash Player does not automatically check for and install updates. Users can use the About Flash Player page (link provided below) to determine their current version and also download the updated version as well.
NOTE: Flash player installations are specific to browser brands. If you use more than one web browser (i.e., Internet Explorer and Mozilla Firefox) you will need to install Flash updates for each. To check and update Flash versions you can visit the About Flash Player page (link provided below) with each browser you use and follow the download instructions.
NOTE: Information about the Flash Player vulnerability was released along with details of another (separate) vulnerability in Adobe Acrobat and Reader. At the time of this writing (7:55 AM 7/31/09) the update for Acrobat and Reader has not yet been released. Adobe systems has stated that an update will be made available for Acrobat and Reader on 7/31/09; readers are encouraged to look for an updated version of this software to be made available soon.
Readers are encouraged to share this alert with family, friends, and associates.
ITS Actions: N/A
Resources:
About Flash Player page (checks current version and provides link for update):
http://www.adobe.com/software/flash/about/
Adobe Security Advisory:
http://www.adobe.com/support/security/bulletins/apsb09-10.html
ALARM Alert 072309-02 (provides information on original vulnerability):
http://www.albany.edu/its/alerts_archive_2009_4059.htm