Readers: 26 | Updated: 05-31

Symantec now says current Flash Player safe from attack

Translate Into:

Symantec Thursday said that "suspicious behavior" by a captured exploit had led it to mistakenly conclude that the most up-to-date standalone versions of Adobe System's Flash Player are vulnerable to ongoing attacks from Chinese servers.

But a Symantec researcher said earlier Thursday that Flash Player 9.0.124.0, the currently-available version of the popular multimedia player, is not vulnerable to the ongoing attacks. Just yesterday, Ben Greenbaum, a senior research manager in Symantec's security response group, had claimed that while Flash Player 9.0.124.0 plug-ins were safe, standalone editions of the program were not.

"All versions Version 9.0.124.0 on all platforms, plug-ins and standalone, are not vulnerable," Greenbaum said Thursday.

The switch was the third change in Symantec's analysis in the last two days.

On Tuesday, Symantec first warned that legitimate Web sites were redirecting unwitting users to one of several Chinese servers, which in turn were trying multiple exploits, including some aimed at Flash Player. Then, Symantec said that older versions of the Adobe software -- version 9.0.115.0, which was replaced in early April -- and the current 9.0.124.0 could be successfully exploited.

Based on that analysis, Symantec dubbed the vulnerability a "zero-day" bug, meaning it was unpatched, and dangerous to anyone with Flash installed.

Later on Tuesday, however, Symantec backtracked from the zero-day label. "Originally, it was believed that this issue was unpatched and unknown, but further technical analysis has revealed that it is very similar to the previously reported Adobe Flash Player Multimedia File Remote Buffer Overflow Vulnerability (BID 28695), discovered by Mark Dowd of IBM," Symantec said.

Even so, Greenbaum maintained yesterday that while the vulnerability wasn't new, the in-the-wild exploit was effective against standalone versions of Flash Player 9.0.124.0. "Not all the versions are patched correctly," he said Wednesday.

Thursday, however, Greenbaum said that Symantec had come to the erroneous conclusion based on tests of the standalone Linux version of Flash Player 9.0.124.0. "While testing against the latest [Linux] version, we saw behaviors consistent with a successful exploit that failed to deliver the payload," he explained Thursday. "[But] the exploit was not, in fact, successful against the latest version."

In a follow-up e-mail, a Symantec spokesman spelled it out in more technical detail. "The latest Linux player, when used to open the exploit file, would abruptly exit silently," said the spokesman. "Stack analysis revealed several internally-handled segmentation faults, which is not normally desired behavior for a program." That behavior, in fact, is often a sign of a successful exploit that then uses incorrect offsets or payload code, he added.

"Further research was unable to produce a successful full exploitation and Adobe confirmed that what we had observed was in fact expected and by design," the spokesman said.

For its part, Adobe stuck to its Wednesday claim that the current Flash Player 9.0.124.0 is not vulnerable. "This exploit does not appear to include a new, unpatched vulnerability as has been reported elsewhere," said Adobe spokesman Mark Rozen. "Customers with Flash Player 9.0.124.0 should not be vulnerable to this exploit."

Greenbaum said that spurious results on Windows test systems had also contributed to Symantec's claims that some versions of 9.0.124.0 were at risk. "We were also seeing compromises on the Windows side," he admitted, "on the latest version of Flash that we downloaded from Adobe's site." Later, Symantec's researchers realized that they had not downloaded an additional patch; when they did and retested, they found the Windows edition to be safe.

"We apologize for the confusion," said Greenbaum. But he defended the analysis, noting that changing updates are common in the security trade as researchers spend more time investigating a problem.

Adobe has recommended that Flash users double-check the version they're running and update to 9.0.124.0 if necessary. Adobe maintains an About Flash Player page that displays the current plug-in version from any browser. Users, however, must run the check for each installed browser.

Computerworld is an InfoWorld affiliate.



From The Blogs

World,Fashion, Entertainment

06-21
To Chineses people - when would you be angry ?
Suffer from insomnia and I get up from my bed again, I read this following writing in Deng Weibiao's blog.The bank have no responsibility for the fake money out from ATM.Depositors take responsibility... 查看全文

Internet Observation

2007
Internet: Born of current and Die of current
The media is the oldest "eyeball" economy.The reason is very simple. Since nobody knows you, listens to you,  then you don't have the power to influence others. If you are not one of the parties, neit... 查看全文

Socyberty

04-13
How the Two-Party System is But a Dictatorship in Disguise
The Democratic and the Republican party seem to be very different. Certainly staunch Democrats and Republicans can't seem to stand each other. Yet there seems to be one thing both parties have in comm... 查看全文

2007
Turkey lawmakers OK possible Iraq attack
By CHRISTOPHER TORCHIA, Associated Press Writer 1 hour, 11 minutes agoISTANBUL, Turkey - Parliament authorized the government Wednesday to send troops into northern Iraq to root out Kurdish rebels who... 查看全文

Brazen Careerist by Penelope Trunk

05-18
How I got my current favorite mentor
The first time it hit me how important mentors are is four years ago, when I interviewed Ellen Fagenson Eland, former professor at George Mason University. She gave me stunning statistics about how im... 查看全文

World,Fashion, Entertainment

06-02
Express Condolences to the Victims in Wenchuan Earthquake of Sichuan on May 12th
Express our condolences to the victims in Wenchuan earthquake of Sichuan on May 12th,2008.Wish them rest in Heaven.Wish the survivals restrain their grief ,and live bravely and strongly to reconstruct... 查看全文

Yanko Design

04-04
Current Currency
Great Britain is set to change their change. Their Royal Mint just announced the winning designs for their coin currency refresh. 26 year old graphic artist, Matthew Dents heraldic design was chosen a... 查看全文

Environmental News Blog|Environmental Graffiti

05-14
China Earthquake: News Gets Grimmer by the Hour
One has to wonder what exactly Asia has done to anger the violent Old Testament God recently, as the damage from Cyclone Nargis and now the 7.8 magnitude earthquake striking China have left the contin... 查看全文

Film School Rejects

05-14
Stone Reminds Us that Bush is Still President [Opinions]
Despite what the media would have you believe, a freakish monster made up of spare parts from Hillary Clinton and Barack Obama is not the current President. Apparently, some squirrelly little guy from... 查看全文

Think Simple Now

07-10
20 Ways to Attack Shyness
Photo by Jordan Fraker. See more of his work here. Can you remember the last time you stepped into a room full of strangers and felt that self-conscious and awkward feeling rush over you? Or that hear... 查看全文
More Articles
Elanso is a professional online platform which provides translation service for corporate or individule clients, opportunities for translation practice and translation jobs, and translation tool/software-download. Our online translators provide about 186 languages' translation service, including Japanese,Korean, French, German, Spanish, etc, among which, 20,000 are English translators. And some big translation service companies in Shanghai, Beijing, Nanjing also registered here.