Showing posts with label AC. Show all posts
Showing posts with label AC. Show all posts

Flash Exploit can nail early versions of Android

0 comments Posted by ADMIN on Wednesday, April 13, 2011

Adobe has announced a critical vulnerability in Flash Player 10.2.153.1 and earlier versions which may, and we do underscore MAY, affect early versions of the Android OS. The vulnerability causes a crash and could also allow a savvy attacker to take control of affected systems. It is usually triggered by an infect .swf file embedded into a Microsoft Word document delivered as an email attachment. Now, granted, this is going to be rare for the Android platform but Adobe felt it important enough to mention that early versions of the Bot OS may be affected.


So if you have an old G1 that you’re hanging onto, you may want to steer clear of using Flash until adobe gets a fix out, which is currently scheduled for June 14, 2011 as part of their quarterly security update schedule. Yeah, June. You’d think if Adobe though this was important enough to mention, and exploits always are, that they’d have a regular update schedule like Microsoft does with Windows. I mean, QUARTERLY?

Then again, if you are still using an G1 or early model Android handset, you’re probably WAY due to upgrade anyway. There’s plenty of great handsets out there and many are free. I mean, we know the G1 was the first and all, but come on, get with the program! Seriously, this likely much ado about nothing for your average AC reader, but its always a good idea to keep up on what attackers are trying to do in case something pops up that nobody saw comin.


Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat

Release date: April 11, 2011

Vulnerability identifier:APSA11-02

CVE number: CVE-2011-0611

Platform: See “Affected software versions” section below for details
Summary

A critical vulnerability exists in Flash Player 10.2.153.1 and earlier versions (Adobe Flash Player 10.2.154.25 and earlier for Chrome users) for Windows, Macintosh, Linux and Solaris, Adobe Flash Player 10.2.156.12 and earlier versions for Android, and the Authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.2) and earlier 10.x and 9.x versions for Windows and Macintosh operating systems.

This vulnerability (CVE-2011-0611) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being exploited in the wild in targeted attacks via a Flash (.swf) file embedded in a Microsoft Word (.doc) file delivered as an email attachment, targeting the Windows platform. At this time, Adobe is not aware of any attacks via PDF targeting Adobe Reader and Acrobat. Adobe Reader X Protected Mode mitigations would prevent an exploit of this kind from executing.

We are in the process of finalizing a schedule for delivering updates for Flash Player 10.2.x and earlier versions for Windows, Macintosh, Linux, Solaris and Android, Adobe Acrobat X (10.0.2) and earlier 10.x and 9.x versions for Windows and Macintosh, Adobe Reader X (10.0.2) for Macintosh, and Adobe Reader 9.4.3 and earlier 9.x versions for Windows and Macintosh. Because Adobe Reader X Protected Mode would prevent an exploit of this kind from executing, we are currently planning to address this issue in Adobe Reader X for Windows with the next quarterly security update for Adobe Reader, currently scheduled for June 14, 2011.
Affected software versions

* Adobe Flash Player 10.2.153.1 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems
* Adobe Flash Player 10.2.154.25 and earlier for Chrome users
* Adobe Flash Player 10.2.156.12 and earlier for Android
* The Authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.2) and earlier 10.x and 9.x versions for Windows and Macintosh operating systems

NOTE: Adobe Reader 9.x for UNIX, Adobe Reader for Android, and Adobe Reader and Acrobat 8.x are not affected by this issue.
Severity rating

Adobe categorizes this as a critical issue.
Details

A critical vulnerability exists in Flash Player 10.2.153.1 and earlier versions (Adobe Flash Player 10.2.154.25 and earlier for Chrome users) for Windows, Macintosh, Linux and Solaris, Adobe Flash Player 10.2.156.12 and earlier versions for Android, and the Authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.2) and earlier 10.x and 9.x versions for Windows and Macintosh operating systems.

This vulnerability (CVE-2011-0611) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being exploited in the wild in targeted attacks via a Flash (.swf) file embedded in a Microsoft Word (.doc) file delivered as an email attachment, targeting the Windows platform. At this time, Adobe is not aware of any attacks via PDF targeting Adobe Reader and Acrobat. Adobe Reader X Protected Mode mitigations would prevent an exploit of this kind from executing.

We are in the process of finalizing a schedule for delivering updates for Flash Player 10.2.x and earlier versions for Windows, Macintosh, Linux, Solaris and Android, Adobe Acrobat X (10.0.2) and earlier 10.x and 9.x versions for Windows and Macintosh, Adobe Reader X (10.0.2) for Macintosh, and Adobe Reader 9.4.3 and earlier 9.x versions for Windows and Macintosh. Because Adobe Reader X Protected Mode would prevent an exploit of this kind from executing, we are currently planning to address this issue in Adobe Reader X for Windows with the next quarterly security update for Adobe Reader, currently scheduled for June 14, 2011.

Users may monitor the latest information on the Adobe Product Security Incident Response Team blog at http://blogs.adobe.com/psirt or by subscribing to the RSS feed at http://blogs.adobe.com/psirt/atom.xml.

Adobe actively shares information about this and other vulnerabilities with partners in the security community to enable them to quickly develop detection and quarantine methods to protect users until a patch is available. As always, Adobe recommends that users follow security best practices by keeping their anti-malware software and definitions up to date.

Acknowledgments
Adobe would like to thank Mila Parkour (http://contagiodump.blogspot.com) for working with Adobe on this issue to help protect our customers.

continue reading…

Samsung Intercept Nabs Froyo Starting Today

0 comments Posted by ADMIN on Tuesday, April 12, 2011

We’re getting reports from owners of Virgin Mobile’s lovely Samsung Intercept that they’re being bumped up to Android 2.2 Froyo today, finally, oh joyous day! This update, like most upgrades to newer Android versions, comes after months of speculation. The first date was December 17th of last year, then it was “sometime this spring,” and now it’s today. Today, today, callooh, callay!
This update brings Virgin Mobile-carried Samsung Intercept up to the nearly-newest version of Android, Android 2.2 Froyo. Of course eventually it would be ideal for this phone to be upgraded to Android 2.3 Gingerbread and then 2.x (whatever it’ll be) Ice Cream. Don’t hold your breath! This may well be the last update in the lifespan of said phone. That said, we’ve been taking a peek at the cute little LG Optimus V for the past week, and Virgin’s been treating us well. 

To see if you’re next in line to get the upgrade to Android 2.2 Froyo, just follow the following directions:
Within the next few weeks you will be receiving a prompt on your phone to update your Intercept phone software from 2.1 éclair to 2.2 Froyo. The update process will take 5-15 minutes to complete. Ensure that your phone is charged or connected to AC before clicking Restart and Install. Do not remove your battery during the update process.
Google or Exchange Contacts, Email accounts, Text Messages, Alarms and installed applications will be backed up and restored. A soft reset may be required to re-sync Calendar events. Music files, Photos and Videos are stored on the memory card and are not affected. Memos, Call Logs, Speed Dial numbers, Playlists, Folders, App shortcuts and Widgets will be deleted. Backup any important Memos before proceeding.Speed Dial numbers, Playlists, Folders, App shortcuts and Widgets can be recreated after the update is complete.
After the installation is complete, your phone will restart. You will be prompted to re-enter your Google Account Password.
Froyo 2.2 enhancements include:
· Exchange Active Sync updates
· ability to install applications to external memory card
· improved Bluetooth device support
· Bluetooth Voice dialing
· improved operating system performance
· dedicated phone, application and browser icons on every home screen
Virgin Mobile
[thanks to everyone who sent this in!]

continue reading…

Xperia Play and XPeria Arc pre-order for free on contact from Vodaphone

0 comments Posted by ADMIN on Monday, March 21, 2011

British hand held gamers rejoice! Vodaphone is offering pre-order of the
Sony-Ericsson Xperia Play for FREE with contract. Users who sign up before April first will also receive a free deckstand and six preloaded games (Crash Bandicoot, Fifa 10, Star Battalion, Tetris, Sims 3, Bruce Lee). In addition to the Xperia Play, users who just want a basic Android experience can also preorder the Xperia Arc for free on contract as well.


As outlined here on AC, The Xperia Play is Sony’s first PlayStation certified phone. It has Qualcomm’s optimized Snapdragon processor with a 1GHz CPU and embedded Adreno GPU graphics processor. Other specs include a 4″ TFT screen with Sony’s proprietary Bravia display engine, slide up gaming controls, 5 MP rear facing camera, and it comes with six Playstation One games preloaded out of the box. It will also take advantage of the Tegra Game Network thanks to it’s Playstation Suite of up to 60 games being released over the next year.



The Xperia Arc has a similar 4.2-inch capacitive touchscreen with Reality Display and Mobile Bravia Engine. It’ll be powered by a 1 Ghz processor. It has dual cameras including an 8.1 MP rear facing and front facing Webcam. The 8.1MP is loaded as it can record 720p HD video at 30 frames per second and has Sony’s remarkable Face Tracking utility. Both phones will run Android 2.3 Gingerbread out of the box.

continue reading…

 

Recent Posts

join me on facebook

Follow Me On Twitter

GET TWEETS!

technooguide Team on Twitter Counter.com

About This Blog

TecHnooGuide.blogspot.com started as a personal blog in Jan 2011, under the first domain name TechnooGuide.

TechnooGuide aims to provide the latest news about technology and gadgets, social media, computers, and the internet in general to all the people of the world.

Everything just started as a hobby and passion of the editor-in-chief of this blog to write the latest news in the internet, particularly in the field of technology, gadgets, and computers. The simple passion started to get serious as this blog continue to grow.

I’m optimistic the year 2011 would be a success, but of course that wouldn’t happen without you being part of the community. If there’s anything you have to say, I’d love to hear that. Cheers!

| TecHnooGuide © 2011. All Rights Reserved | Template Style Modified by Ahmed korat & Designed by mohammed Ahmedzai|