Categories: SecurityWorkspace

Adobe Backtracks On Patching ‘PR Disaster’

Adobe has decided to provide a software patch for a security flaw in Photoshop Creative Suite 5 (CS5), after previously sparking outrage by saying it would leave the flaw unpatched, so anyone who wanted to use the software securely would have to pay for an upgrade to the next version, CS6.

A fierce backlash apparently caused the vendor to think again: a security bulletin now promises a patch that will resolve the vulnerabilities in Adobe Photoshop CS5. Adobe is also working on patches for other vulnerabilities affecting CS5 products.

“We are in the process of resolving the vulnerabilities addressed in these Security Bulletins in Adobe Illustrator CS5.x, Adobe Photoshop CS5.x (12.x) and Adobe Flash Professional CS5.x, and will update the respective Security Bulletins once the patches are available,” the company said in a blog post.

The vulnerabilities could have allowed an attacker to take control of an affected system.

A PR nightmare?

A number of industry experts criticised Adobe for asking people to pay twice if they wanted to have a secure product. Graham Cluley, senior technology consultant at Sophos, said the update was “clearly preferable to Adobe customers’ only option being to pay hundreds of dollars to fix their software.”

Cluley had initially labelled the move “a PR disaster” for Adobe. “At first when I heard the news I thought there must be some mistake. Maybe Adobe’s security advisories had been worded poorly and although upgrading – for example, to PhotoShop CS6 – would fix the vulnerability, the firm would also roll out a free patch to users of earlier versions,” Cluley said in a blog post.

Adobe products have had a history of serious security flaws, but the company has usually moved fast to kill off threats, without charging users. In December, the company took some flak for not moving to patch some zero-day vulnerabilities when it said it would.

However, in April, it emerged Apple had reported more vulnerabilities than any other tech vendor in the first quarter of 2012.

Think you know security? Try our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Tesla Backs Away From Gigacasting Manufacturing – Report

Tesla retreats from pioneering gigacasting manufacturing process, amid cost cutting and challenges at EV giant

13 hours ago

US Urges No AI Control Of Nuclear Weapons

No skynet please. After the US, UK and France pledge human only control of nuclear…

15 hours ago

LastPass Separates From Parent After Security Incidents

New chapter for LastPass as it becomes an independent company to focus on cybersecurity, after…

17 hours ago

US To Ban Huawei, ZTE From Certifying Wireless Kit

US FCC seeks to ban Chinese telecom firms at centre of national security concerns from…

21 hours ago

Anthropic Launches Enterprise-Focused Claude, Plus iPhone App

Two updates to Anthropic's AI chatbot Claude sees arrival of a new business-focused plan, as…

23 hours ago