Page 6 of 14 FirstFirst ... 2345678910 ... LastLast
Results 51 to 60 of 139

Thread: Adobe updates/advisories

  1. #51
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Flash 11.9.900.170, Shockwave 12.0.7.148 released

    FYI...

    Flash 11.9.900.170 released
    - http://helpx.adobe.com/security/prod...apsb13-28.html
    Dec 10, 2013
    CVE numbers:
    - https://web.nvd.nist.gov/view/vuln/d...=CVE-2013-5331 - 9.3 (HIGH)
    "... as exploited in the wild in December 2013."
    - https://web.nvd.nist.gov/view/vuln/d...=CVE-2013-5332 - 10.0 (HIGH)
    Platform: All Platforms
    Summary: Adobe has released security updates for Adobe Flash Player 11.9.900.152 and earlier versions for Windows and Macintosh and Adobe Flash Player 11.2.202.327 and earlier versions for Linux. These updates address vulnerabilities that could cause a crash and potentially allow an attacker to take control of the affected system. Adobe is aware of reports that an exploit designed to trick the user into opening a Microsoft Word document with malicious Flash (.swf) content exists for CVE-2013-5331. Adobe Flash Player 11.6 and later provide a mitigation against this attack.
    Adobe recommends users update their product installations to the latest versions:
    • Users of Adobe Flash Player 11.9.900.152 and earlier versions for Windows and Macintosh should update to Adobe Flash Player 11.9.900.170.
    • Users of Adobe Flash Player 11.2.202.327 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.332.
    • Adobe Flash Player 11.9.900.152 installed with Google Chrome will automatically be updated to the latest Google Chrome version, which will include Adobe Flash Player 11.9.900.170 for Windows, Macintosh and Linux.
    • Adobe Flash Player 11.9.900.152 installed with Internet Explorer 10 will automatically be updated to the latest Internet Explorer 10 version, which will include Adobe Flash Player 11.9.900.170 for Windows 8.0
    • Adobe Flash Player 11.9.900.152 installed with Internet Explorer 11 will automatically be updated to the latest Internet Explorer 11 version, which will include Adobe Flash Player 11.9.900.170 for Windows 8.1
    • Users of Adobe AIR 3.9.0.1210 and earlier versions for Windows and Macintosh should update to Adobe AIR 3.9.0.1380.
    • Users of Adobe AIR 3.9.0.1210 and earlier versions for Android should update to Adobe AIR 3.9.0.1380.
    • Users of the Adobe AIR 3.9.0.1210 SDK and earlier versions should update to the Adobe AIR 3.9.0.1380 SDK.
    • Users of the Adobe AIR 3.9.0.1210 SDK & Compiler and earlier versions should update to the Adobe AIR 3.9.0.1380 SDK & Compiler...

    - https://www.adobe.com/products/flash...ribution3.html

    Flash test site:
    - http://www.adobe.com/software/flash/about/

    - http://helpx.adobe.com/flash-player.html

    Adobe AIR
    - http://get.adobe.com/air/

    - https://secunia.com/advisories/55948/
    Criticality: Highly Critical
    ___

    Shockwave 12.0.7.148 released
    - http://helpx.adobe.com/security/prod...apsb13-29.html
    Dec 10, 2013
    CVE numbers:
    - https://web.nvd.nist.gov/view/vuln/d...=CVE-2013-5333 - 10.0 (HIGH)
    - https://web.nvd.nist.gov/view/vuln/d...=CVE-2013-5334 - 10.0 (HIGH)
    Platform: Windows and Macintosh
    Summary: Adobe has released a security update for Adobe Shockwave Player 12.0.6.147 and earlier versions on the Windows and Macintosh operating systems. This update addresses a vulnerability that could allow an attacker, who successfully exploits this vulnerability, to run malicious code on the affected system. Adobe recommends users of Adobe Shockwave Player 12.0.6.147 and earlier versions update to Adobe Shockwave Player 12.0.7.148 using the instructions provided in the "Solution" section below.
    Affected software versions: Adobe Shockwave Player 12.0.6.147 and earlier versions for Windows and Macintosh.
    Solution: Adobe recommends users of Adobe Shockwave Player 12.0.6.147 and earlier versions update to the newest version 12.0.7.148, available here:
    - http://get.adobe.com/shockwave/

    - https://secunia.com/advisories/55952/
    Criticality: Highly Critical

    Last edited by AplusWebMaster; 2014-01-05 at 17:14.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  2. #52
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Adobe Reader/Acrobat - Prenotification Security Advisory

    FYI...

    Prenotification Security Advisory for Adobe Reader and Acrobat
    - http://helpx.adobe.com/security/prod...apsb14-01.html
    Jan 9, 2014 - "Adobe is planning to release security updates on Tuesday, January 14, 2014 for Adobe Reader and Acrobat XI (11.0.05) and earlier versions for Windows and Macintosh... This Security Advisory will be replaced with the Security Bulletin upon release of the update on Tuesday, January 14, 2014..."

    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  3. #53
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Flash 12.0.0.38, Reader/Acrobat 11.0.06 released

    FYI...

    Flash 12.0.0.38 released
    - http://helpx.adobe.com/security/prod...apsb14-02.html
    Jan 14, 2014
    CVE number: CVE-2014-0491, CVE-2014-0492
    Platform: All Platforms
    Summary: Adobe has released security updates for Adobe Flash Player 11.9.900.170 and earlier versions for Windows and Macintosh and Adobe Flash Player 11.2.202.332 and earlier versions for Linux. These updates address vulnerabilities that could potentially allow an attacker to take control of the affected system. Adobe recommends users update their product installations to the latest versions:
    - Users of Adobe Flash Player 11.9.900.170 and earlier versions for Windows Internet Explorer should update to Adobe Flash Player 12.0.0.38.
    - Users of Adobe Flash Player 11.9.900.170 and earlier versions for NPAPI plugin-based browsers on Windows should update to Adobe Flash Player 12.0.0.43
    - Users of Adobe Flash Player 11.9.900.170 and earlier versions for Macintosh should update to Adobe Flash Player 12.0.0.38.
    - Users of Adobe Flash Player 11.2.202.332 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.335.
    - Adobe Flash Player 11.9.900.170 installed with Google Chrome will automatically be updated to the latest Google Chrome version, which will include Adobe Flash Player 12.0.0.41 for Windows, Macintosh and Linux.
    - Adobe Flash Player 11.9.900.170 installed with Internet Explorer 10 will automatically be updated to the latest Internet Explorer 10 version, which will include Adobe Flash Player 12.0.0.38 for Windows 8.0.
    - Adobe Flash Player 11.9.900.170 installed with Internet Explorer 11 will automatically be updated to the latest Internet Explorer 11 version, which will include Adobe Flash Player 12.0.0.38 for Windows 8.1.
    -- Users of Adobe AIR 3.9.0.1380 and earlier versions for Windows and Macintosh should update to Adobe AIR 4.0.0.1390.
    - Users of Adobe AIR 3.9.0.1380 and earlier versions for Android should update to Adobe AIR 4.0.0.1390.
    - Users of the Adobe AIR 3.9.0.1380 SDK and earlier versions should update to the Adobe AIR 4.0.0.1390 SDK.
    - Users of the Adobe AIR 3.9.0.1380 SDK & Compiler and earlier versions should update to the Adobe AIR 4.0.0.1390 SDK & Compiler...

    - https://www.adobe.com/products/flash...ribution3.html

    Flash test site:
    - http://www.adobe.com/software/flash/about/

    - http://helpx.adobe.com/flash-player.html

    Adobe AIR
    - http://get.adobe.com/air/
    ___

    Adobe Reader/Acrobat 11.0.06 released
    - http://helpx.adobe.com/security/prod...apsb14-01.html
    Jan 14, 2014
    CVE Numbers: CVE-2014-0493, CVE-2014-0495, CVE-2014-0496
    Platform: Windows and Macintosh
    Summary: Adobe has released security updates for Adobe Reader and Acrobat XI (11.0.05) and earlier versions for Windows and Macintosh. These updates address vulnerabilities that could cause a crash and potentially allow an attacker to take control of the affected system. Adobe recommends users update their product installations to the latest versions:
    - Users of Adobe Reader XI (11.0.05) for Windows and Macintosh should update to Adobe Reader XI 11.0.06.
    - For users of Adobe Reader X (10.1.8 ) and earlier versions for Windows and Macintosh, who cannot update to Adobe Reader XI (11.0.06), Adobe has made available the update Adobe Reader X (10.1.9).
    - Users of Adobe Acrobat XI (11.0.05) for Windows and Macintosh should update to Adobe Acrobat XI (11.0.06).
    - For users of Adobe Acrobat X (10.1.8 ) and earlier versions for Windows and Macintosh, who cannot update to Adobe Acrobat XI (11.0.06), Adobe has made available the update Adobe Acrobat X (10.1.9)...
    Adobe Reader: Users on Windows and Macintosh can utilize the product's update mechanism... Update checks can be manually activated by choosing Help > Check for Updates.
    Adobe Acrobat: Users can utilize the product's update mechanism... Update checks can be manually activated by choosing Help > Check for Updates...

    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  4. #54
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Adobe Digital Editions v3.0 released

    FYI...

    Adobe Digital Editions v3.0 released
    - https://secunia.com/advisories/56578/
    Release Date: 2014-01-23
    Criticality: Highly Critical
    Where: From remote
    Impact: System access
    CVE Reference(s): CVE-2014-0494
    ... vulnerability is reported in version 2.0.1.
    Solution: Upgrade to version 3.0.
    Original Advisory:
    http://helpx.adobe.com/security/prod...apsb14-03.html

    - http://www.adobe.com/products/digita.../download.html

    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  5. #55
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Flash 12.0.0.44 released

    FYI...

    Flash 12.0.0.44 released
    - http://helpx.adobe.com/security/prod...apsb14-04.html
    Feb 4, 2014
    CVE number: https://web.nvd.nist.gov/view/vuln/d...=CVE-2014-0497 - 10.0 (HIGH)
    Platform: All Platforms
    Summary: Adobe has released security updates for Adobe Flash Player 12.0.0.43 and earlier versions for Windows and Macintosh and Adobe Flash Player 11.2.202.335 and earlier versions for Linux. These updates address a critical vulnerability that could potentially allow an attacker to remotely take control of the affected system. Adobe is aware of reports that an exploit for this vulnerability exists in the wild, and recommends users update their product installations to the latest versions:
    - Users of Adobe Flash Player 12.0.0.43 and earlier versions for Windows and Macintosh should update to Adobe Flash Player 12.0.0.44.
    - Users of Adobe Flash Player 11.2.202.335 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.336.
    - Adobe Flash Player 12.0.0.41 installed with Google Chrome will automatically be updated to the latest Google Chrome version, which will include Adobe Flash Player 12.0.0.44 for Windows, Macintosh and Linux.
    - Adobe Flash Player 12.0.0.38 installed with Internet Explorer 10 will automatically be updated to the latest Internet Explorer 10 version, which will include Adobe Flash Player 12.0.0.44 for Windows 8.0.
    - Adobe Flash Player 12.0.0.38 installed with Internet Explorer 11 will automatically be updated to the latest Internet Explorer 11 version, which will include Adobe Flash Player 12.0.0.44 for Windows 8.1...
    These updates address -critical- vulnerabilities in the software...

    - https://www.adobe.com/products/flash...ribution3.html

    Flash test site:
    - http://www.adobe.com/software/flash/about/

    - http://helpx.adobe.com/flash-player.html
    ___

    - https://secunia.com/advisories/56737/
    Release Date: 2014-02-05
    Criticality: Extremely Critical
    Where: From remote
    Impact: System access
    Solution Status: Vendor Patch
    ... vulnerability is actively exploited in the wild.
    Reported as a 0-Day...
    CVE Reference: CVE-2014-0497
    Solution: Update to a fixed version...

    - http://atlas.arbor.net/briefs/index#375357101
    High Severity
    6 Feb 2014

    CVE-2014-0497 – a 0-day vulnerability
    - https://www.securelist.com/en/blog/8..._vulnerability
    Feb 5, 2014

    Last edited by AplusWebMaster; 2014-02-07 at 19:34.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  6. #56
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Shockwave Player 12.0.9.149 released

    FYI...

    Shockwave Player 12.0.9.149 released
    - http://helpx.adobe.com/security/prod...apsb14-06.html
    Feb 11, 2014
    CVE number:
    - https://web.nvd.nist.gov/view/vuln/d...=CVE-2014-0500 - 10.0 (HIGH)
    - https://web.nvd.nist.gov/view/vuln/d...=CVE-2014-0501 - 10.0 (HIGH)
    Platform: Windows and Macintosh
    Summary: Adobe has released a security update for Adobe Shockwave Player 12.0.7.148 and earlier versions on the Windows and Macintosh operating systems. This update addresses critical vulnerabilities that could potentially allow an attacker to remotely take control of the affected system... Adobe recommends users of Adobe Shockwave Player 12.0.7.148 and earlier versions update to the newest version 12.0.9.149, available here:
    - http://get.adobe.com/shockwave/
    ___

    Test Shockwave
    - http://www.adobe.com/shockwave/welcome/
    ___

    - https://secunia.com/advisories/56740/
    Release Date: 2014-02-11
    Criticality: Highly Critical
    Where: From remote
    Impact: System access
    CVE Reference(s): CVE-2014-0500, CVE-2014-0501
    Solution: Update to version 12.0.9.149

    Last edited by AplusWebMaster; 2014-02-13 at 02:36.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  7. #57
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Flash 12.0.0.70 released

    FYI...

    Flash 12.0.0.70 released
    - http://helpx.adobe.com/security/prod...apsb14-07.html
    Feb 20, 2014
    CVE number:
    - https://web.nvd.nist.gov/view/vuln/d...=CVE-2014-0498 - 10.0 (HIGH)
    - https://web.nvd.nist.gov/view/vuln/d...=CVE-2014-0499 - 7.8 (HIGH)
    - https://web.nvd.nist.gov/view/vuln/d...=CVE-2014-0502 - 10.0 (HIGH)
    Last revised: 02/21/2014 - "... as exploited in the wild in February 2014..."
    Platform: All Platforms
    Summary: Adobe has released security updates for Adobe Flash Player 12.0.0.44 and earlier versions for Windows and Macintosh and Adobe Flash Player 11.2.202.336 and earlier versions for Linux. These updates address vulnerabilities that could potentially allow an attacker to take control of the affected system. Adobe is aware of reports that an exploit for CVE-2014-0502 exists in the wild, and recommends users update their product installations to the latest versions:
    - Users of Adobe Flash Player 12.0.0.44 and earlier versions for Windows and Macintosh should update to Adobe Flash Player 12.0.0.70.
    - Users of Adobe Flash Player 11.2.202.336 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.341.
    - Adobe Flash Player 12.0.0.44 installed with Google Chrome will automatically be updated to the latest Google Chrome version, which will include Adobe Flash Player 12.0.0.70 for Windows, Macintosh and Linux.
    - Adobe Flash Player 12.0.0.44 installed with Internet Explorer 10 will automatically be updated to the latest Internet Explorer 10 version, which will include Adobe Flash Player 12.0.0.70 for Windows 8.0.
    - Adobe Flash Player 12.0.0.44 installed with Internet Explorer 11 will automatically be updated to the latest Internet Explorer 11 version, which will include Adobe Flash Player 12.0.0.70 for Windows 8.1.
    - Users of Adobe AIR 4.0.0.1390 and earlier versions for Android should update to Adobe AIR 4.0.0.1628.
    - Users of the Adobe AIR 4.0.0.1390 SDK and earlier versions should update to the Adobe AIR 4.0.0.1628 SDK.
    - Users of the Adobe AIR 4.0.0.1390 SDK & Compiler and earlier versions should update to the Adobe AIR 4.0.0.1628 SDK & Compiler...

    - https://www.adobe.com/products/flash...ribution3.html

    Flash test site:
    - http://www.adobe.com/software/flash/about/

    - http://helpx.adobe.com/flash-player.html

    Adobe AIR
    - http://get.adobe.com/air/
    ___

    - https://secunia.com/advisories/57057/
    Release Date: 2014-02-21
    Criticality: Extremely Critical
    Where: From remote
    Impact: Exposure of sensitive information, System access...
    Solution:
    Update to a fixed version...

    Last edited by AplusWebMaster; 2014-02-21 at 18:31.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  8. #58
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Flash 12.0.0.77 released

    FYI...

    Flash 12.0.0.77 released
    - http://helpx.adobe.com/security/prod...apsb14-08.html
    March 11, 2014
    CVE number:
    - https://web.nvd.nist.gov/view/vuln/d...=CVE-2014-0503 - 6.4
    - https://web.nvd.nist.gov/view/vuln/d...=CVE-2014-0504 - 5.0
    Platform: All Platforms
    Summary: Adobe has released security updates for Adobe Flash Player 12.0.0.70 and earlier versions for Windows and Macintosh and Adobe Flash Player 11.2.202.341 and earlier versions for Linux. These updates address -important- vulnerabilities, and Adobe recommends users update their product installations to the latest versions:
    - Users of Adobe Flash Player 12.0.0.70 and earlier versions for Windows and Macintosh should update to Adobe Flash Player 12.0.0.77
    - Users of Adobe Flash Player 11.2.202.341 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.346
    - Adobe Flash Player 12.0.0.70 installed with Google Chrome will automatically be updated to the latest Google Chrome version, which will include Adobe Flash Player 12.0.0.77 for Windows, Macintosh and Linux.
    - Adobe Flash Player 12.0.0.70 installed with Internet Explorer 10 will automatically be updated to the latest Internet Explorer 10 version, which will include Adobe Flash Player 12.0.0.77 for Windows 8.0.
    - Adobe Flash Player 12.0.0.70 installed with Internet Explorer 11 will automatically be updated to the latest Internet Explorer 11 version, which will include Adobe Flash Player 12.0.0.77 for Windows 8.1...

    - https://www.adobe.com/products/flash...ribution3.html

    Flash test site:
    - http://www.adobe.com/software/flash/about/

    - http://helpx.adobe.com/flash-player.html

    Last edited by AplusWebMaster; 2014-03-12 at 21:34.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  9. #59
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Shockwave 12.0.9.150 released

    FYI...

    Shockwave 12.0.9.150 released
    - http://helpx.adobe.com/security/prod...apsb14-10.html
    March 13, 2014
    CVE number: https://web.nvd.nist.gov/view/vuln/d...=CVE-2014-0505 - 10.0 (HIGH)
    Platform: Windows and Macintosh
    Summary: Adobe has released a security update for Adobe Shockwave Player 12.0.9.149 and earlier versions on the Windows and Macintosh operating systems. This update addresses a -critical- vulnerability that could potentially allow an attacker to remotely take control of the affected system. Adobe recommends users of Adobe Shockwave Player 12.0.9.149 and earlier versions update to Adobe Shockwave Player 12.1.0.150 using the instructions provided in the "Solution" section...
    Solution: Adobe recommends users of Adobe Shockwave Player 12.0.9.149 and earlier versions update to the newest version 12.1.0.150, available here:
    - http://get.adobe.com/shockwave/
    ___

    - https://secunia.com/advisories/57277/
    Release Date: 2014-03-14
    Criticality: Highly Critical
    Where: From remote
    Impact: System access...
    ... vulnerability is reported in versions 12.0.9.149 and prior running on Windows and Macintosh.
    Solution: Update to version 12.1.0.150.

    Last edited by AplusWebMaster; 2014-03-14 at 23:30.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  10. #60
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Thumbs down Flash exploit in-the-wild ...

    FYI...

    Flash exploit in-the-wild ...
    - http://www.threattracksecurity.com/i...cve-2014-0502/
    Mar 21, 2014 - "... new exploit in the wild going after a known Adobe vulnerability... detected the file cc.swf delivered via the malicious link hxxp ://java-sky .com/swf/cc.swf**... Only 7/51 antivirus vendors on VirusTotal* detect the malicious payload at the time of this post..."

    * https://www.virustotal.com/en/file/8...d87f/analysis/

    ** 50.62.99.1 - https://www.virustotal.com/en/ip-add...1/information/

    - http://google.com/safebrowsing/diagnostic?site=AS:26496

    - https://web.nvd.nist.gov/view/vuln/d...=CVE-2014-0502 - 10.0 (HIGH)

    Latest Flash version 12.0.0.77
    - http://forums.spybot.info/showthread...l=1#post451165

    Flash test site:
    - http://www.adobe.com/software/flash/about/

    Last edited by AplusWebMaster; 2014-03-22 at 23:00.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •