Results 1 to 10 of 139

Thread: Adobe updates/advisories

Threaded View

Previous Post Previous Post   Next Post Next Post
  1. #11
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Flash 16.0.0.287 released

    FYI...

    Flash 16.0.0.287 released
    - https://helpx.adobe.com/security/pro...apsb15-02.html
    Jan 22, 2015
    CVE number: https://web.nvd.nist.gov/view/vuln/d...=CVE-2015-0310
    Platform: All Platforms
    Summary: Adobe has released security updates for Adobe Flash Player for Windows, Macintosh and Linux. These updates address a vulnerability that could be used to circumvent memory randomization mitigations on the Windows platform. Adobe is aware of reports that an exploit for CVE-2015-0310 exists in the wild, which is being used in attacks against older versions of Flash Player. Additionally, we are investigating reports that a -separate- exploit for Flash Player 16.0.0.287 and earlier also exists in the wild. For the latest information, please refer to the PSIRT blog here*.
    * http://blogs.adobe.com/psirt/
    Adobe recommends users update their product installations to the latest versions:
    - Users of the Adobe Flash Player desktop runtime for Windows and Macintosh should update to Adobe Flash Player 16.0.0.287.
    - Users of the Adobe Flash Player Extended Support Release should update to Adobe Flash Player 13.0.0.262.
    - Users of Adobe Flash Player for Linux should update to Adobe Flash Player 11.2.202.438.
    - Adobe Flash Player installed with Google Chrome, as well as Internet Explorer on Windows 8.x, will automatically update to version 16.0.0.287.
    Affected software versions
    - Adobe Flash Player 16.0.0.257 and earlier versions
    - Adobe Flash Player 13.0.0.260 and earlier 13.x versions
    - Adobe Flash Player 11.2.202.429 and earlier versions for Linux
    Solution: Adobe recommends users update their software installations by following the instructions below:
    - Adobe recommends users of the Adobe Flash Player desktop runtime for Windows and Macintosh update to Adobe Flash Player 16.0.0.287 by visiting the Adobe Flash Player Download Center, or via the update mechanism within the product when prompted.
    - Adobe recommends users of the Adobe Flash Player Extended Support Release should update to version 13.0.0.262 by visiting:
    > http://helpx.adobe.com/flash-player/...-versions.html.
    - Adobe recommends users of Adobe Flash Player for Linux update to Adobe Flash Player 11.2.202.438 by visiting the Adobe Flash Player Download Center.
    - Adobe Flash Player installed with Google Chrome will be automatically updated to the latest Google Chrome version, which will include Adobe Flash Player 16.0.0.287.
    - Adobe Flash Player installed with Internet Explorer for Windows 8.x will be automatically updated to the latest version, which will include Adobe Flash Player 16.0.0.287.

    For IE:
    - http://download.macromedia.com/get/f...6_active_x.exe
    For Firefox and other Plugin-based browsers:
    - http://download.macromedia.com/get/f..._16_plugin.exe

    Flash test site: http://www.adobe.com/software/flash/about/

    - https://helpx.adobe.com/security/pro...apsa15-01.html
    Updated: Jan 22, 2015 - "... We are aware of reports that this vulnerability is being actively exploited in the wild via drive-by-download attacks against systems running Internet Explorer and Firefox on Windows 8 and below. Adobe expects to have a patch available for CVE-2015-0311 during the week of January 26..."
    ___

    - http://www.securitytracker.com/id/1031609
    CVE Reference: https://cve.mitre.org/cgi-bin/cvenam...=CVE-2015-0310
    Jan 22 2015
    Impact: Disclosure of system information
    Fix Available: Yes Vendor Confirmed: Yes
    This vulnerability is being actively exploited...
    Version(s): 16.0.0.257 and prior; 13.0.0.260 and prior 13.x versions ...
    Solution: The vendor has issued a fix (16.0.0.287, ESR 13.0.0.262)...

    Last edited by AplusWebMaster; 2015-01-24 at 14:33.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •