{"id":9370,"date":"2011-09-08T18:53:47","date_gmt":"2011-09-08T22:53:47","guid":{"rendered":"http:\/\/rbach.net\/blog\/?p=9370"},"modified":"2021-01-11T17:48:26","modified_gmt":"2021-01-11T22:48:26","slug":"adobe-still-full-of-holes","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/adobe-still-full-of-holes\/","title":{"rendered":"Adobe Flash Still Full of Holes"},"content":{"rendered":"<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-9740\" style=\"border: 0pt none; margin-left: 3px; margin-right: 3px;\" title=\"Adobe Flash Still Full of Holes\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/2011\/08\/adobe_bugs.jpg?resize=100%2C75&#038;ssl=1\" alt=\"Adobe Flash Still Full of Holes\" width=\"100\" height=\"75\" \/><\/p>\n<p><em>I wrote about <a title=\"Adobe\" href=\"https:\/\/www.adobe.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Adobe&#8217;s<\/a> (<a title=\"NASDAQ : ADBE\" href=\"https:\/\/www.tradingview.com\/symbols\/NASDAQ-ADBE\/\" target=\"_blank\" rel=\"noopener noreferrer\">ADBE<\/a>) problem with writing secure software <a href=\"https:\/\/wp.me\/p2wgaW-L5\" target=\"_blank\" rel=\"noopener noreferrer\">earlier<\/a>.<\/em> The problems still exists according to an article in <a title=\"www.net-security.org\" href=\"https:\/\/www.helpnetsecurity.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Help Net Security<\/em><\/a>. The article lays out claims by <a title=\"Google\" href=\"https:\/\/www.google.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Google<\/a> (<a title=\"NASDAQ : GOOG\" href=\"https:\/\/www.tradingview.com\/symbols\/NASDAQ-GOOG\/\" target=\"_blank\" rel=\"noopener noreferrer\">GOOG<\/a>) researcher <a title=\"Tavis Ormandy\" href=\"http:\/\/googleonlinesecurity.blogspot.com\/search?q=Tavis+Ormandy\" target=\"_blank\" rel=\"noopener noreferrer\">Tavis Ormandy<\/a> that he notified Adobe of <strong>some 400 holes in\u00a0 <a title=\"Adobe Flash Player\" href=\"https:\/\/www.adobe.com\/products\/flashplayer\/\" target=\"_blank\" rel=\"homepage noopener noreferrer\">Flash Player<\/a><\/strong>. According the the article, Adobe fell short on the latest Flash patch. In the article Mr. Ormandy claims that Adobe&#8217;s latest release of Flash:<\/p>\n<ul>\n<li><a href=\"https:\/\/web.archive.org\/web\/20170512072333\/http:\/\/www.adobe.com\/software\/flash\/about\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-9738 \" style=\"border: 0pt none; margin-left: 3px; margin-right: 3px;\" title=\"adobe_flash_logo\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/2011\/08\/adobe_flash_logo.jpg?resize=68%2C68&#038;ssl=1\" alt=\"\" width=\"68\" height=\"68\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/2011\/08\/adobe_flash_logo.jpg?w=225&amp;ssl=1 225w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/2011\/08\/adobe_flash_logo.jpg?resize=150%2C150&amp;ssl=1 150w\" sizes=\"auto, (max-width: 68px) 100vw, 68px\" \/><\/a>Only patched 13 fixed holes in the application, failed to document other holes; and<\/li>\n<li>Did not give credit to those that found the bugs using a technique called <a title=\"Fuzz testing\" href=\"https:\/\/secure.wikimedia.org\/wikipedia\/en\/wiki\/Fuzz_testing\" target=\"_blank\" rel=\"noopener wikipedia noreferrer\">fuzzing<\/a> to reveal the bugs.<\/li>\n<\/ul>\n<p>the Google researchers wrote on their blog, &#8220;<em>The initial run of the ongoing effort resulted in about 400 unique crash signatures, which were logged as 106 individual <a title=\"Security bug\" href=\"https:\/\/secure.wikimedia.org\/wikipedia\/en\/wiki\/Security_bug\" target=\"_blank\" rel=\"noopener wikipedia noreferrer\">security bugs<\/a> \u2026 each crash was treated as though it were potentially exploitable and addressed by <a title=\"Adobe\" href=\"https:\/\/www.crunchbase.com\/company\/adobe-systems\" target=\"_blank\" rel=\"noopener noreferrer\">Adobe<\/a>. In the final analysis, the Flash Player update Adobe shipped earlier this week contained about 80 code changes to fix these bugs.&#8221;<\/em><\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"wp-image-9736 alignright\" style=\"border: 0pt none; margin-left: 3px; margin-right: 3px;\" title=\"Adobe Flash Still Full of Holes\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/2011\/08\/malware1.jpg?resize=90%2C90&#038;ssl=1\" alt=\"Adobe Flash Still Full of Holes\" width=\"90\" height=\"90\" \/><\/p>\n<p><em>Help Net Security<\/em> notes that after an initial silence on the matter, Adobe told <em>Computerworld<\/em>, that Mr. Ormandy had reported some 80 bugs in Flash Player, but defended their decision to not list all the vulnerabilities in the released security bulletins by saying that it usually doesn&#8217;t reveal or mention vulnerabilities found internally &#8211; by them or their partners. Also, the question is whether all those 80 flaws would lead to an exploitable hole. It seems that Adobe believes that only holes get a <a title=\"Common Vulnerabilities and Exposures\" href=\"http:\/\/en.wikipedia.org\/wiki\/Common_Vulnerabilities_and_Exposures\" target=\"_blank\" rel=\"noopener wikipedia noreferrer\">CVE number<\/a>.<\/p>\n<h6>Related articles<\/h6>\n<ul>\n<li><a href=\"http:\/\/9to5google.com\/2011\/08\/10\/google-engineer-claims-adobe-hid-embarrassingly-high-number-of-flash-player-bugs\/\" target=\"_blank\" rel=\"noopener noreferrer\">Google engineer claims Adobe hid &#8220;embarrassingly high&#8221; number of Flash Player bugs<\/a> (9to5google.com)<\/li>\n<\/ul>\n<p><strong>What do you think?<\/strong><\/p>\n<div id=\"polls-14\" class=\"wp-polls\">\n\t<form id=\"polls_form_14\" class=\"wp-polls-form\" action=\"\/index.php\" method=\"post\">\n\t\t<p style=\"display: none;\"><input type=\"hidden\" id=\"poll_14_nonce\" name=\"wp-polls-nonce\" value=\"f24995c4aa\" \/><\/p>\n\t\t<p style=\"display: none;\"><input type=\"hidden\" name=\"poll_id\" value=\"14\" \/><\/p>\n\t\t<p style=\"text-align: left;\"><strong>Is Flash still worth it?<\/strong><\/p><div id=\"polls-14-ans\" class=\"wp-polls-ans\"><ul class=\"wp-polls-ul\">\n\t\t<li><input type=\"radio\" id=\"poll-answer-41\" name=\"poll_14\" value=\"41\" \/> <label for=\"poll-answer-41\">Yes, I have to have my YouTube<\/label><\/li>\n\t\t<li><input type=\"radio\" id=\"poll-answer-42\" name=\"poll_14\" value=\"42\" \/> <label for=\"poll-answer-42\">No, Bring on HTML5<\/label><\/li>\n\t\t<\/ul><p style=\"text-align: center;\"><input type=\"button\" name=\"vote\" value=\"   Vote   \" class=\"Buttons\" onclick=\"poll_vote(14);\" onkeypress=\"poll_result(14);\" \/><\/p><p style=\"text-align: center;\"><a href=\"#ViewPollResults\" onclick=\"poll_result(14); return false;\" onkeypress=\"poll_result(14); return false;\" title=\"View Results Of This Poll\">View Results<\/a><\/p><\/div>\n\t<\/form>\n<\/div>\n<div id=\"polls-14-loading\" class=\"wp-polls-loading\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/plugins\/wp-polls\/images\/loading.gif?resize=16%2C16&#038;ssl=1\" width=\"16\" height=\"16\" alt=\"Loading ...\" title=\"Loading ...\" class=\"wp-polls-image\" \/>&nbsp;Loading ...<\/div>\n\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a>\u00a0about IT, careers and anything else that catches his attention since 2005. You can follow him at\u00a0<a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google researchers say they found over 400 holes in Adobes Flash Player by fuzzing and only 13 holes were fixed by Adobe in the last patch<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[3045,742,736,1767,1805,741,536,92,23,4],"class_list":["post-9370","post","type-post","status-publish","format-standard","hentry","category-security","tag-3045","tag-adbe","tag-adobe-systems","tag-bug","tag-flash","tag-fuzz-testing","tag-goog","tag-google","tag-malware","tag-security"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/9370","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=9370"}],"version-history":[{"count":11,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/9370\/revisions"}],"predecessor-version":[{"id":131372,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/9370\/revisions\/131372"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=9370"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=9370"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=9370"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}