保安警報 (A17-08-03): Adobe Flash Player 及 Adobe Reader/Acrobat 產品多個漏洞


 

發布日期: 2017 年 8 月 9 日

  
  

描述:

Adobe 發布了數個安全更新,以應對於Adobe Flash Player和Adobe Acrobat及Reader 中發現的繞過保安限制、類型混亂、記憶體損毀、使用已釋放記憶體錯誤、未能妥善核實數據真確性(insufficient verification of data authenticity)和堆陣滿溢的問題。遠端攻擊者可誘使目標用戶開啓包含特製內容的PDF檔案、網頁、Flash 檔案或含 Flash 內容的文件來攻擊這些漏洞。


受影響的系統:

  • Adobe Flash Player Desktop Runtime (Windows、Macintosh及Linux) 26.0.0.137 和之前版本
  • Adobe Flash Player (Google Chrome) 26.0.0.137 和之前版本
  • Adobe Flash Player (Microsoft Edge及Internet Explorer 11) 26.0.0.137 和之前版本
  • Adobe Acrobat Acrobat Reader 2017 2017.008.30051 和之前版本
  • Adobe Acrobat DC/Acrobat Reader DC Continuous 2017.009.20058 和之前版本
  • Adobe Acrobat DC/Acrobat Reader DC Classic 2015.006.30306 和之前版本
  • Adobe Acrobat/Reader XI 11.0.20 和之前版本

影響:

成功利用這些漏洞可以任意執行程式碼、泄漏資訊或可能控制受影響的系統。


建議:

更新 Adobe Flash Player 和 Adobe Acrobat及Reader 至以下版本以應對以上問題。更新可透過產品本身的自動更新裝置或下列網址更新其軟件:

  • Adobe Flash Player Desktop Runtime 26.0.0.151 (Windows及 Macintosh)

    https://get.adobe.com/flashplayer/
    http://www.adobe.com/products/players/flash-player-distribution.html

  • Adobe Flash Player 26.0.0.151 (Google Chrome)

    https://chromereleases.googleblog.com/

  • Adobe Flash Player 26.0.0.151 (Microsoft Edge and Internet Explorer 11)

    https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV170010

  • Adobe Flash Player 26.0.0.151 (Linux)

    https://get.adobe.com/flashplayer/

  • Adobe Acrobat DC Continuous 2017.012.20093, Acrobat DC Classic 2015.006.30352, Acrobat 2017 2017.011.30059, Acrobat Reader 2017 2017.011.30059, Acrobat XI 11.0.21

    http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows
    http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Mac

  • Adobe Acrobat Reader DC Classic 2015.006.30352, Reader XI 11.0.21

    http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows
    http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Mac

  • Adobe Acrobat Reader DC Continuous 2017.012.20093

    http://get.adobe.com/reader/

若安裝了多個瀏覽器,系統中每個瀏覽器均須更新。Adobe Flash Player 的版本可在以下網址確認:

http://www.adobe.com/software/flash/about/


進一步資訊:

https://helpx.adobe.com/security/products/acrobat/apsb17-24.html
https://helpx.adobe.com/security/products/flash-player/apsb17-23.html
https://www.hkcert.org/my_url/zh/alert/17080902
https://www.us-cert.gov/ncas/current-activity/2017/08/08/Adobe-Releases-Security-Updates
https://blogs.adobe.com/conversations/2017/07/adobe-flash-update.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3016
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3038
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3085
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3113
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3115 (to CVE2017-3124)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11209 (to CVE2017-11212)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11214
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11216 (to CVE2017-11224)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11226 (to CVE2017-11239)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11241 (to CVE2017-11246)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11248 (to CVE2017-11249)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11251 (to CVE2017-11252)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11254 (to CVE2017-11263)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11265
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11267 (to CVE2017-11271)


Back to Advisories