Page 2 of 14 FirstFirst 12345612 ... LastLast
Results 11 to 20 of 139

Thread: Adobe updates/advisories

  1. #11
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Flash Player v11.2.202.235 released

    FYI...

    Flash Player v11.2.202.235 released - 0-day Fix
    - https://www.adobe.com/support/securi...apsb12-09.html
    May 4, 2012
    CVE number: http://web.nvd.nist.gov/view/vuln/de...=CVE-2012-0779
    Platform: All Platforms
    Summary: ... an object confusion vulnerability (CVE-2012-0779) that could cause the application to crash and potentially allow an attacker to take control of the affected system. There are reports that the vulnerability is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious file delivered in an email message. The exploit targets Flash Player on Internet Explorer for Windows* only. Adobe recommends users of Adobe Flash Player 11.2.202.233 and earlier versions for Windows, Macintosh and Linux update to Adobe Flash Player 11.2.202.235... Users of Adobe Flash Player 11.1.115.7 and earlier versions on Android 4.x devices should update to Adobe Flash Player 11.1.115.8. Users of Adobe Flash Player 11.1.111.8 and earlier versions for Android 3.x and earlier versions should update to Flash Player 11.1.111.9...
    * Priority 1: This update resolves vulnerabilities being targeted, or which have a higher risk of being targeted, by exploit(s) in the wild for a given product version and platform. Adobe recommends administrators install the update as soon as possible...
    > https://blogs.adobe.com/psirt/2012/0...apsb12-09.html

    Download: https://www.adobe.com/products/flash...ribution3.html

    Android: https://market.android.com/details?i...be.flashplayer
    ___

    Flash test site: http://www.adobe.com/software/flash/about/

    Flash Player update closes critical object confusion hole
    Severity: High Severity
    - http://atlas.arbor.net/briefs/
    Published: Monday, May 07, 2012
    Adobe Flash update addresses critical security hole.
    Analysis: This vulnerability has been used in active attacks although they are apparently not widespread attacks. Attackers will often use newer vulnerabilities and 0days on special targets of high value first. At some point, the exploit code will leak or a post-compromise analysis will reveal the vulnerability and/or the exploit involved and then the gates open for more compromise activity by others with a variety of motives.
    Source: http://h-online.com/-1568704

    - https://www.us-cert.gov/current/#ado...advisory_for14
    May 4, 2012

    - http://www.securitytracker.com/id/1027023
    May 4 2012 - "... vulnerability is being actively exploited against Flash Player on Internet Explorer in targeted cases. Microsoft Vulnerability Research (MSVR) reported this vulnerability..."

    Last edited by AplusWebMaster; 2012-05-09 at 13:45.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  2. #12
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Adobe Black Tuesday for May 2012

    FYI...

    Adobe Black Tuesday for May 2012
    ___

    APSB12-13 Security update available for Adobe Shockwave Player
    - https://www.adobe.com/support/securi...apsb12-13.html
    5/8/2012
    CVE number: CVE-2012-2029, CVE-2012-2030, CVE-2012-2031, CVE-2012-2032, CVE-2012-2033
    Platform: Windows and Macintosh
    ... security update for Adobe Shockwave Player 11.6.4.634 and earlier versions for Windows and Macintosh. This update addresses vulnerabilities that could allow an attacker who successfully exploits these vulnerabilities to run malicious code on the affected system. Adobe recommends users of Adobe Shockwave Player 11.6.4.634 and earlier for Windows and Macintosh update to Adobe Shockwave Player 11.6.5.635... available here: http://get.adobe.com/shockwave/ ... addresses -critical- vulnerabilities in the software....

    APSB12-12 Security bulletin for Adobe Flash Pro
    - https://www.adobe.com/support/securi...apsb12-12.html
    5/8/2012
    CVE number: CVE-2012-0778
    Platform: Windows and Macintosh
    ... security upgrade for Adobe Flash Professional CS5.5 (11.5.1.349) and earlier for Windows and Macintosh. This upgrade addresses a vulnerability that could allow an attacker who successfully exploits this vulnerability to take control of the affected system. Adobe has released Adobe Flash Professional CS6, which addresses this vulnerability... (paid upgrade)... addresses a -critical- vulnerability in the software...

    APSB12-11 Security bulletin for Adobe Photoshop
    - https://www.adobe.com/support/securi...apsb12-11.html
    5/8/2012
    CVE number: CVE-2012-2027, CVE-2012-2028
    Platform: Windows and Macintosh
    ... security upgrade for Adobe Photoshop CS5.5 and earlier for Windows and Macintosh. This upgrade addresses vulnerabilities that could allow an attacker who successfully exploits these vulnerabilities to take control of the affected system. Adobe has released Adobe Photoshop CS6, which addresses these vulnerabilities... (paid upgrade)... could lead to code execution CVE-2012-2027, Bugtraq ID 52634, which references:
    http://www.securityfocus.com/bid/52634/ This upgrade resolves a buffer overflow vulnerability that could lead to code execution (CVE-2012-2028)... addresses a -critical- vulnerability in the software...

    APSB12-10 Security bulletin for Adobe Illustrator
    - https://www.adobe.com/support/securi...apsb12-10.html
    5/8/2012
    CVE numbers: CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, CVE-2012-2026
    Platform: Windows and Macintosh
    ... security upgrade for Adobe Illustrator CS5.5 and earlier for Windows and Macintosh. This upgrade addresses vulnerabilities that could allow an attacker who successfully exploits these vulnerabilities to take control of the affected system. Adobe has released Adobe Illustrator CS6, which addresses these vulnerabilities... (paid upgrade)... addresses -critical- vulnerabilities in the software...
    ___

    - https://secunia.com/advisories/49086/ - Shockwave Player
    - https://secunia.com/advisories/47116/ - Flash Pro
    - https://secunia.com/advisories/48457/ - Photoshop
    - https://secunia.com/advisories/47118/ - Illustrator

    - http://www.securitytracker.com/id/1027037 - Shockwave Player
    - http://www.securitytracker.com/id/1027045 - Flash Pro
    - http://www.securitytracker.com/id/1027046 - Photoshop
    - http://www.securitytracker.com/id/1027047 - Illustrator

    Last edited by AplusWebMaster; 2012-05-10 at 00:33.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  3. #13
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Adobe to release patches for CS5.x ...

    FYI...

    Adobe to release patches for CS5.x ...
    - http://h-online.com/-1574341
    12 May 2012 - "Adobe has announced* – through changes to the security advisories it issued earlier this week – that it is developing patches for the critical holes in the CS5.x versions of Adobe Photoshop, Illustrator and Flash Professional, after previously advising users that they needed to buy the just-released CS6 versions of the applications... Adobe has given no schedule for the availability of patches. In the original 8 May advisories, the company had said only that users of these products would need to purchase the upgrade from the CS5 and CS5.5 versions to the, just shipping on 7 May, CS6 versions to close the critical holes they were detailing; a move that was seen as effectively charging for security fixes..."
    * https://blogs.adobe.com/psirt/2012/0...apsb12-12.html
    May 11, 2012 - "... We are in the process of resolving the vulnerabilities addressed in these Security Bulletins in Adobe Illustrator CS5.x, Adobe Photoshop CS5.x (12.x) and Adobe Flash Professional CS5.x, and will update the respective Security Bulletins once the patches are available..."
    ___

    Adobe Photoshop CS5 Collada File Processing Buffer Overflow Vulnerability
    - https://secunia.com/advisories/49160/
    Release Date: 2012-05-15
    Criticality level: Highly critical
    Solution Status: Unpatched...

    Adobe Photoshop...
    - http://securitytracker.com/id/1027063
    Date: May 15 2012
    Impact: Execution of arbitrary code via network, User access via network
    Version(s): CS5.1; possibly other versions...

    Last edited by AplusWebMaster; 2012-05-16 at 00:50.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  4. #14
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Arrow Adobe Illustrator and Photoshop fixes released

    FYI...

    Adobe Illustrator CS5 (15.0.3) and Adobe Illustrator CS5.5 (15.1.1) released
    - https://www.adobe.com/support/securi...apsb12-10.html
    Last updated: June 4, 2012
    CVE numbers: CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, CVE-2012-2026, CVE-2012-2042
    Platform: Windows and Macintosh
    "... Adobe has released Adobe Illustrator CS5 (15.0.3) and Adobe Illustrator CS5.5 (15.1.1) to address the vulnerabilities highlighted in this security bulletin... users can find the appropriate update for their version/platform here:
    Adobe Illustrator CS5 (15.0.3) for Windows
    - http://download.adobe.com/pub/adobe/...tor_15.0.3.zip
    Adobe Illustrator CS5 (15.0.3) for Macintosh
    - http://download.adobe.com/pub/adobe/...tor_15.0.3.dmg
    Adobe Illustrator CS5.5 (15.1.1) for Windows
    - http://download.adobe.com/pub/adobe/...tor_15.1.1.zip
    Adobe Illustrator CS5.5 (15.1.1) for Macintosh
    - http://download.adobe.com/pub/adobe/...tor_15.1.1.dmg ..."

    Adobe Photoshop vCS5 (12.0.5) and vCS5.1 (12.1.1) released
    - https://www.adobe.com/support/securi...apsb12-11.html
    Last updated: June 4, 2012
    CVE number: CVE-2012-2027, CVE-2012-2028, CVE-2012-2052
    Platform: Windows and Macintosh
    "... Adobe has released Adobe Photoshop CS5 (12.0.5) and Adobe Photoshop CS5.1 (12.1.1) to address the vulnerabilities highlighted in this security bulletin... Adobe recommends... customers update their product installations by following the instructions provided in the the technote:
    http://helpx.adobe.com/photoshop/kb/...photoshop.html ..."

    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  5. #15
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Flash Player v11.3.300.257 - AIR v3.3.0.3610 released

    FYI...

    Flash Player v11.3.300.257 - AIR v3.3.0.3610 released
    - https://www.adobe.com/support/securi...apsb12-14.html
    June 8, 2012
    CVE number:
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2012-2034 - 10.0 (HIGH)
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2012-2035 - 10.0 (HIGH)
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2012-2036 - 10.0 (HIGH)
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2012-2037 - 10.0 (HIGH)
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2012-2038 - 5.0
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2012-2039 - 10.0 (HIGH)
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2012-2040 - 7.2 (HIGH)
    Platform: All Platforms
    Summary: Adobe released security updates for Adobe Flash Player 11.2.202.235 and earlier versions for Windows, Macintosh and Linux, Adobe Flash Player 11.1.115.8 and earlier versions for Android 4.x, and Adobe Flash Player 11.1.111.9 and earlier versions for Android 3.x and 2.x. These updates address vulnerabilities that could cause a crash and potentially allow an attacker to take control of the affected system.
    Adobe recommends users update their product installations to the latest versions:
    - Users of Adobe Flash Player 11.2.202.235 and earlier versions for Windows and Macintosh should update to Adobe Flash Player 11.3.300.257.
    - Users of Adobe Flash Player 11.2.202.235 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.236.
    - Flash Player installed with Google Chrome will be updated automatically, so no user action is required. Google Chrome users can verify that they have updated to Google Chrome version 19.0.1084.56, which includes Adobe Flash Player 11.3.300.257.
    - Users of Adobe Flash Player 11.1.115.8 and earlier versions on Android 4.x devices should update to Adobe Flash Player 11.1.115.9.
    - Users of Adobe Flash Player 11.1.111.9 and earlier versions for Android 3.x and earlier versions should update to Flash Player 11.1.111.10.
    > https://krebsonsecurity.com/wp-conte...13-600x157.png

    Download: https://www.adobe.com/products/flash...ribution3.html

    Android: https://market.android.com/details?i...be.flashplayer

    Flash test site: http://www.adobe.com/software/flash/about/
    ___

    - Users of Adobe AIR 3.2.0.2070 for Windows, Macintosh and Android should update to Adobe AIR 3.3.0.3610...
    Adobe recommends users of Adobe AIR 3.2.0.207 and earlier versions for Windows, Macintosh and Android update to Adobe AIR 3.3.0.3610:
    - http://get.adobe.com/air/?promoid=JOPDE
    Adobe AIR 3.2.0.2070 and earlier versions for Windows, Macintosh and Android... follow the instructions in the Adobe AIR TechNote:
    - http://helpx.adobe.com/air/kb/determ...r-runtime.html
    ___

    Thanks Brian:
    - https://krebsonsecurity.com/2012/06/...-flash-player/
    June 8, 2012
    ___

    Inside Flash Player Protected Mode for Firefox
    - https://blogs.adobe.com/asset/2012/0...r-firefox.html
    June 7, 2012
    > https://blogs.adobe.com/asset/files/..._processes.jpg

    - http://h-online.com/-1614700
    9 June 2012
    ___

    - http://www.securitytracker.com/id/1027139
    CVE Reference: CVE-2012-2034, CVE-2012-2035, CVE-2012-2036, CVE-2012-2037, CVE-2012-2038, CVE-2012-2039, CVE-2012-2040
    Jun 9 2012
    Impact: Disclosure of system information, Disclosure of user information, Execution of arbitrary code via network, User access via network
    Version(s): 11.2.202.235 and prior
    Impact: A remote user can create content that, when loaded by the target user, will execute arbitrary code on the target user's system. A remote user can obtain potentially sensitive information.
    Solution: The vendor has issued a fix (11.3.300.257 for Windows and Mac, 11.2.202.236 for Linux, 11.3.300.257 for Chrome, 11.1.115.9 for Android 4.x, 11.1.111.10 for Android 3.x).
    The vendor's advisory is available at:
    http://www.adobe.com/support/securit...apsb12-14.html

    - https://secunia.com/advisories/49388/
    Last Update: 2012-06-11
    Criticality level: Highly critical
    Impact: Security Bypass, System access
    Where: From remote
    Software: Adobe AIR 3.x, Adobe Flash Player 11.x ...
    Solution: Update to a fixed version.
    Original Advisory: Adobe:
    http://www.adobe.com/support/securit...apsb12-14.html

    - https://www.us-cert.gov/current/#ado...advisory_for15
    June 11, 2012 - 9:11 am

    Last edited by AplusWebMaster; 2012-06-13 at 06:26.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  6. #16
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation ColdFusion v9.0.1 hotfix available...

    FYI...

    ColdFusion v9.0.1 hotfix available...
    - https://www.adobe.com/support/securi...apsb12-15.html
    June 12, 2012
    CVE number: CVE-2012-2041
    Platforms: All
    Summary: Adobe released a security hotfix for ColdFusion 9.0.1 and earlier versions for Windows, Macintosh and UNIX. This update resolves an HTTP response splitting vulnerability in the ColdFusion Component Browser. Adobe recommends users update their product installation using the instructions provided in the "Solution" section below.
    Affected software versions: ColdFusion 9.0.1, 9.0, 8.0.1, and 8.0 for Windows, Macintosh and UNIX
    *Note: ColdFusion 10 for Windows, Macintosh and UNIX is not affected by this issue.
    Solution: Adobe recommends affected ColdFusion customers update their installation using the instructions provided in the technote:
    - http://helpx.adobe.com/coldfusion/kb...apsb12-15.html ...

    - http://www.securitytracker.com/id/1027146
    CVE Reference: CVE-2012-2041
    Jun 12 2012
    Impact: Disclosure of authentication information, Disclosure of user information, Execution of arbitrary code via network, Modification of user information
    Version(s): 8.0, 8.0.1, 9.0, 9.0.1

    Last edited by AplusWebMaster; 2012-06-13 at 00:19.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  7. #17
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Flash crash - Firefox 13 ...

    FYI...

    Firefox v13.0.1 released
    >>> http://forums.spybot.info/showpost.p...0&postcount=28
    June 16, 2012
    ___

    Flash crash - Firefox 13...
    - http://h-online.com/-1619399
    15 June 2012 - "The latest release of the Flash Player plugin, version 11.3, is causing frequent crashes in Firefox 13 on Windows. The problem seems to be related to the recently introduced Protection Mode, which is supposed to make the plugin run in a sandbox to isolate it from the rest of the system. The number of users experiencing this problem is now so large that Mozilla and Adobe are both offering differing solutions for a fix... Users should on -no- account -downgrade- to build 11.2... as it is known to contain critical security vulnerabilities which are currently being actively exploited... users should install Flash Player 10.3*, in which the vulnerabilities in question have been fixed in a similar way to version 11.3 since Adobe is continuing to supply enterprise customers with security patches for Flash 10."

    * http://fpdownload.macromedia.com/get..._10_plugin.exe

    Last edited by AplusWebMaster; 2012-06-16 at 18:23.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  8. #18
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Post Flash v11.3.300.262 - Plugin-based browsers

    FYI...

    Flash Player v11.3.300.262 released
    > http://forums.adobe.com/thread/1027238
    Jun 21, 2012 - "... the Windows Flash Player plug-in for Firefox, Mozilla, Netscape, Opera and other browsers was updated to 11.3.300.262. This release addresses stability issue found in Mozilla Firefox. This build does not address the audio issues reported by some customers but we continue to focus on these problems and will continue to do so until they are resolved. If you continue to have problems with this release, please see this tech note* for suggestions and instructions for reporting these issues to us: Flash Player 11.3 compatibility issues with RealPlayer extension in Mozilla Firefox. For full details on the 11.3 release, please see our release notes**."

    * http://helpx.adobe.com/flash-player/...h-mozilla.html
    Last updated: 2012-06-22

    ** http://helpx.adobe.com/flash-player/...n_Known_Issues
    Last updated: 2012-06-21
    ___

    > https://www.adobe.com/products/flash...ribution3.html

    Windows Flash Player 11.3.300.262 ... Plugin-based browsers:
    > http://download.macromedia.com/get/f..._11_plugin.exe
    ___

    Flash test site: http://www.adobe.com/software/flash/about/

    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  9. #19
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Flash Pro CS5.5 Security Update 11.5.2

    FYI...

    Flash Pro CS5.5 Security Update 11.5.2
    - https://www.adobe.com/support/securi...apsb12-12.html
    Last Updated: June 25, 2012
    CVE number: http://web.nvd.nist.gov/view/vuln/de...=CVE-2012-0778 - 10.0 (HIGH)
    Platform: Windows and Macintosh
    Summary: Adobe released a security update for Adobe Flash Professional CS5.5 (11.5.1.349 and earlier) for Windows and Macintosh. This update addresses a vulnerability that could allow an attacker who successfully exploits this vulnerability to take control of the affected system. Note that Adobe Flash Professional CS6 (12.0.0.481) for Windows and Macintosh addresses this vulnerability. No update is required for users of Adobe Flash Professional CS6 (12.0.0.481) for Windows and Macintosh.
    Affected software versions: Adobe Flash Professional CS5.5 (11.5.1.349 and 11.5.0.325) and earlier versions for Windows and Macintosh
    Solution: Adobe has released Adobe Flash Professional CS5.5 (11.5.2.349) to address the vulnerability highlighted in this security bulletin. Adobe recommends Adobe Flash Professional CS5.5 (11.5.1.349 and earlier) customers update their product installation by following the instructions provided in the technote:
    - http://helpx.adobe.com/flash/kb/flas...ty-update.html
    ...The Security Update is available for download at:
    - https://www.adobe.com/support/flash/...html#flashCS55
    ... This update addresses a critical vulnerability in the software.
    Revisions:
    June 25, 2012 - Added information on release of update to Adobe Flash Professional CS5.5 (11.5.1.349 and 11.5.0.325).

    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  10. #20
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Lightbulb Flash v11.3.300.265 released

    FYI...

    Flash v11.3.300.265 released
    - http://forums.adobe.com/message/4551666#4551666
    Jul 11, 2012 - "Flash Player 11.3 Update
    Today, Flash Player 11.3.300.265 for Windows and Macintosh was released to address critical audio and stability issues.
    For full details on the 11.3 release, please see our release notes.
    http://www.adobe.com/support/documen...easenotes.html ..."

    Download:
    > https://www.adobe.com/products/flash...ribution3.html

    Flash test site: http://www.adobe.com/software/flash/about/
    2012.07.11
    ... The table below contains the latest Flash Player version information:
    Windows:
    Internet Explorer (and other browsers that support Internet Explorer ActiveX controls and plug-ins) 11.3.300.265
    Firefox, Mozilla, Netscape, Opera (and other plugin-based browsers) 11.3.300.265
    Chrome 11.3.300.265
    Macintosh:
    OS X Firefox, Opera, Safari 11.3.300.265
    Chrome 11.3.300.265

    Last edited by AplusWebMaster; 2012-07-11 at 22:28.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •