Results 1 to 10 of 107

Thread: Old Adobe updates/advisories

Threaded View

Previous Post Previous Post   Next Post Next Post
  1. #11
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Shockwave Player vuln - update v11.5.0.600 available

    FYI...

    Shockwave Player vuln - update v11.5.0.600 available
    - http://www.adobe.com/support/securit...apsb09-08.html
    June 23, 2009 - "A critical vulnerability has been identified in Adobe Shockwave Player 11.5.0.596 and earlier versions. This vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected system... To resolve this issue, Shockwave Player users on Windows should -uninstall- Shockwave version 11.5.0.596 and earlier on their systems, restart, and install Shockwave version 11.5.0.600, available here: http://get.adobe.com/shockwave/ . This issue is remotely exploitable..."

    - http://voices.washingtonpost.com/sec..._for_adob.html
    June 25, 2009 - "...Readers should be aware that by default this patch will also try to install Symantec's Norton Security Scan, a clever marketing tool by Symantec that checks to see if you have malware on your system and then prompts you to buy their software to remove any found items. I find the bundling of a serious security update with this otherwise useless tool annoying, and potentially counter-productive... did they borrow the idea from the people pushing rogue anti-virus products (or was it the other way around?) At any rate, if you don't want this extra software, be sure to deselect that option before proceeding with the update."

    http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-1860
    http://web.nvd.nist.gov/view/vuln/de...=CVE-2009-2186

    - http://secunia.com/advisories/35544/2/
    Release Date: 2009-06-24
    Critical: Highly critical
    Impact: System access
    Where: From remote
    Solution Status: Vendor Patch
    Software: Shockwave Player 11.x ...
    Solution: Uninstall versions prior to 11.5.0.600, restart the system, and install version 11.5.0.600:
    http://get.adobe.com/shockwave/

    - http://www.us-cert.gov/current/#adob..._for_shockwave
    June 24, 2009

    Last edited by AplusWebMaster; 2009-06-29 at 18:54. Reason: Added Secunia, US-CERT, and SecurityFix links...
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •