Zero Day Exploits Target Flash
Adobe scrambles to release patches for vulnerable Flash Player.
Adobe engineers worked overtime the past two weeks to restore security (and public confidence) in the ubiquitous Adobe Flash, which has been in the news recently with some high-profile zero-day exploits.
Adobe announced a patch on January 22 for a recent vulnerability (CVE-2015-0310) based on faulty memory protection. The patch applies to Windows, Mac OS, and Linux systems. According to security expert Kafeine, the exploit has already been integrated into the latest versions of the Angler exploit kit, a universal tool used by attackers. The attack was apparently used to install versions of the Bedep, a malware tool used for ad fraud.
The version of the attack detected in the wild appeared to focus on IE and Windows systems and could even compromise a fully updated version of Windows 8.1. However, researchers could not rule out the possibility of the attack being used with Mac and Linux systems as well. A later version of Angler appears to have been adapted to attack Firefox as well.
A related exploit (CVE-2015-0311) was also discovered in the wild and patched through a second emergency fix a week later.
Users are advised to install the patches as soon as possible.
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters
Support Our Work
Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.
News
-
Kali Linux Waxes Nostalgic with BackTrack Mode
For those who've used Kali Linux since its inception, the changes with the new release are sure to put a smile on your face.
-
Gnome 50 Smooths Out NVIDIA GPU Issues
Gamers rejoice, your favorite pastime just got better with Gnome 50 and NVIDIA GPUs.
-
System76 Retools Thelio Desktop
The new Thelio Mira has landed with improved performance, repairability, and front-facing ports alongside a high-quality tempered glass facade.
-
Some Linux Distros Skirt Age Verification Laws
After California introduced an age verification law recently, open source operating system developers have had to get creative with how they deal with it.
-
UN Creates Open Source Portal
In a quest to strengthen open source collaboration, the United Nations Office of Information and Communications Technology has created a new portal.
-
Latest Linux Kernel RC Contains Changes Galore
Linux kernel 7.0-rc3 includes more changes than have been made in a single release in recent history.
-
Nitrux 6.0 Now Ready to Rock Your World
The latest iteration of the Debian-based distribution includes all kinds of newness.
-
Linux Foundation Reports that Open Source Delivers Better ROI
In a report that may surprise no one in the Linux community, the Linux Foundation found that businesses are finding a 5X return on investment with open source software.
-
Keep Android Open
Google has announced that, soon, anyone looking to develop Android apps will have to first register centrally with Google.
-
Kernel 7.0 Now in Testing
Linus Torvalds has announced the first Release Candidate (RC) for the 7.x kernel is available for those who want to test it.
