Page 10 of 11 FirstFirst ... 67891011 LastLast
Results 91 to 100 of 107

Thread: Old Adobe updates/advisories

  1. #91
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Adobe - multiple critical updates

    FYI...

    Adobe - multiple critical updates

    Flash Player- critical update
    - http://www.adobe.com/support/securit...apsb11-18.html
    June 14, 2011 - "A critical vulnerability has been identified in Adobe Flash Player 10.3.181.23 and earlier versions... Adobe recommends... update to Adobe Flash Player 10.3.181.26... Note:... does -not- affect the Authplay.dll component that ships with Adobe Reader and Acrobat..."
    CVE number: CVE-2011-2110
    Direct download current version - executable Flash Player installer... to your Desktop, then double-click to install.
    - http://fpdownload.adobe.com/get/flas..._player_ax.exe
    For IE ...
    - http://fpdownload.adobe.com/get/flas...ash_player.exe
    For Firefox, other browsers, etc...

    Flash test site: http://www.adobe.com/software/flash/about/

    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2011-2110
    Last revised: 06/17/2011
    CVSS v2 Base Score: 10.0 (HIGH)

    - http://www.securitytracker.com/id/1025651
    Jun 14 2011 - CVE-2011-2110
    ... This vulnerability is being actively exploited via targeted web pages.
    Impact: A remote user can create Flash content that, when loaded by the target user, will execute arbitrary code on the target user's system.
    Solution: The vendor has issued a fix 10.3.181.26*...

    - http://secunia.com/advisories/44964/
    Release Date: 2011-06-15
    Criticality level: Extremely critical...
    NOTE: The vulnerability is reportedly being actively exploited in targeted attacks... 10.3.181.23 and earlier...
    Solution: Apply updates... (10.3.181.26)...
    ___

    Reader and Acrobat - critical updates
    - http://www.adobe.com/support/securit...apsb11-16.html
    June 14, 2011 - "Critical vulnerabilities have been identified in Adobe Reader X (10.0.1) and earlier versions for Windows, Adobe Reader X (10.0.3) and earlier versions for Macintosh, and Adobe Acrobat X (10.0.3) and earlier...
    Adobe recommends users of Adobe Reader X (10.0.3) and earlier versions for Windows and Macintosh update to Adobe Reader X (10.1). For users of Adobe Reader 9.4.4 and earlier versions for Windows and Macintosh, who cannot update to Adobe Reader X (10.1), Adobe has made available updates, Adobe Reader 9.4.5 and Adobe Reader 8.3...
    Adobe recommends users of Adobe Acrobat X (10.0.3) for Windows and Macintosh update to Adobe Acrobat X (10.1). Adobe recommends users of Adobe Acrobat 9.4.4 and earlier versions for Windows and Macintosh update to Adobe Acrobat 9.4.5, and users of Adobe Acrobat 8.2.6 and earlier versions for Windows and Macintosh update to Adobe Acrobat 8.3... Users can utilize the product's update mechanism..."
    CVE numbers: CVE-2011-2094, CVE-2011-2095, CVE-2011-2096, CVE-2011-2097, CVE-2011-2098, CVE-2011-2099, CVE-2011-2100, CVE-2011-2101, CVE-2011-2102, CVE-2011-2103, CVE-2011-2104, CVE-2011-2105, CVE-2011-2106
    ... before 8.3, 9.x before 9.4.5, and 10.x before 10.1...
    - http://www.securitytracker.com/id/1025658
    June 14 2011
    Impact: Denial of service via network, Execution of arbitrary code via network, User access via network...
    Version(s): 8.x - 8.2.6, 9.x - 9.4.4, 10.x - 10.0.3
    Solution: The vendor has issued a fix (8.3, 9.4.5, 10.1).
    ___

    Shockwave Player - critical update
    - http://www.adobe.com/support/securit...apsb11-17.html
    June 14, 2011 - "Critical vulnerabilities have been identified in Adobe Shockwave Player 11.5.9.620 and earlier versions... Adobe recommends users of Adobe Shockwave Player 11.5.9.620 and earlier versions upgrade to the newest version 11.6.0.626, available here: http://get.adobe.com/shockwave/ "
    CVE number: CVE-2011-0317, CVE-2011-0318, CVE-2011-0319, CVE-2011-0320, CVE-2011-0335, CVE-2011-2108, CVE-2011-2109, CVE-2011-2111, CVE-2011-2112, CVE-2011-2113, CVE-2011-2114, CVE-2011-2115, CVE-2011-2116, CVE-2011-2117, CVE-2011-2118, CVE-2011-2119, CVE-2011-2120, CVE-2011-2121, CVE-2011-2122, CVE-2011-2123, CVE-2011-2124, CVE-2011-2125, CVE-2011-2126, CVE-2011-2127
    ___

    Hotfix available for ColdFusion
    - http://www.adobe.com/support/securit...apsb11-14.html
    June 14, 2011 - "Important vulnerabilities have been identified in ColdFusion 9.0.1 and earlier versions for Windows, Macintosh and UNIX. These vulnerabilities could lead to a cross-site request forgery (CSRF) or a remote denial-of-service (DoS). Adobe recommends users update their product...
    Adobe recommends affected ColdFusion customers update their installation using the instructions provided in the technote:
    - http://kb2.adobe.com/cps/907/cpsid_90784.html ..."
    CVE number: CVE-2011-0629, CVE-2011-2091
    ___

    LiveCycle Data Services, LiveCycle ES, and BlazeDS - Security update
    - http://www.adobe.com/support/securit...apsb11-15.html
    June 14, 2011 - "Two important security vulnerabilities have been identified in LiveCycle Data Services and BlazeDS. These vulnerabilities affect LiveCycle Data Services 3.1, 2.6.1, 2.5.1 and earlier versions for Windows, Macintosh and UNIX, and LiveCycle 9.0.0.2, 8.2.1.3, 8.0.1.3 and earlier versions for Windows, Linux and UNIX. These vulnerabilities also affect BlazeDS 4.0.1 and earlier versions. Adobe recommends users update their product...
    Solution... " Use the URL above for instructions and links.
    CVE number: CVE-2011-2092, CVE-2011-2093

    Last edited by AplusWebMaster; 2011-06-20 at 19:21.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  2. #92
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Flash v10.3.181.34 released

    FYI...

    - http://www.adobe.com/support/security/
    No advisory posted - yet. (released in new version of Chrome)

    Fixes in Flash Player 10.3.181.34
    - http://kb2.adobe.com/cps/901/cpsid_9...in_10.3.181.34
    Jira bugs
    [FP-###] denotes bugs that are filed in the Adobe Flash Player Bug and Issue Management System https://bugs.adobe.com/flashplayer
    [FP-5317] Flash Player crashes when a high definition video is played in -any- browser (2848668)
    [FP-6143] Flash app does not resize properly when wmode=transparent
    [FP-6163] During 'Press Esc to exit full screen message' Flash player does not allow to load swf which loads another swf into SWFLoader. (2808217)
    [FP-6198] url is being returned escaped in Flash Player 10.2, but wasn't in Flash Player 10.1 (2812702)
    [FP-6230] DisplacementMapFilter doesn't work when movie is scaled (2814161)...
    Browser...
    Chrome: Printing SWFs is not enabled in Google Chrome. We are working with Google to address this issue. (2490502)
    Safari: Printing SWFs is not enabled in Safari on Windows platforms. We are investigating this issue with Apple. (2490502)
    Firefox: [FP-19322] In Firefox, a FaultEvent returns a status code of zero, ignoring the status returned by the web server (2827551)
    Content Hero game at http://www.fishhf.com/ fails to load when using Firefox 3 (2834776)
    When using Firefox 4 on Ubuntu Operating System, videos at new.music.yahoo.com fail to play (2840163)
    Internet Explorer: [FP-6597] In Internet Explorer, tab navigation may stop working after tabbing to the end of Flash content ( 2849526)...
    ___

    Direct download current version - executable Flash Player installer... to your Desktop, then double-click to install.
    - http://fpdownload.adobe.com/get/flas..._player_ax.exe
    For IE ...
    - http://fpdownload.adobe.com/get/flas...ash_player.exe
    For Firefox, other browsers, etc...

    Flash test site: http://www.adobe.com/software/flash/about/

    Last edited by AplusWebMaster; 2011-06-30 at 15:58.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  3. #93
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Post 60% of Adobe Reader users unpatched...

    FYI...

    60% of Adobe Reader users unpatched...
    - http://www.darkreading.com/taxonomy/...e/id/231001642
    Jul 13, 2011 - "Six out of every 10 users of Adobe Reader are running unpatched versions of the program, leaving them vulnerable to a variety of malware attacks... In a study of its own antivirus users, Avast Software found that 60.2 percent of those with Adobe Reader were running a vulnerable version of the program... More than 80 percent of Avast users run a version of Adobe Reader... Brad Arkin, senior director of product security and privacy at Adobe, agreed with the Avast analysis. "We find that most consumers don’t bother updating a free app, such as Adobe Reader, as PDF files can be viewed in the older version," he said... Malware PDF exploit packages will typically look for a variety of security weaknesses in the targeted computer, attacking when an uncovered vulnerability is discovered..."

    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  4. #94
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Adobe -critical- updates released

    FYI...

    > https://www.adobe.com/support/security/

    Flash Player v10.3.183.5 released
    - https://www.adobe.com/support/securi...apsb11-21.html
    Last updated: August 12, 2011
    Platform: All platforms
    Summary: Critical vulnerabilities have been identified in Adobe Flash Player 10.3.181.36 and earlier versions... upgrade to the newest version 10.3.183.5...

    Direct download current version - executable Flash Player installer... to your Desktop, then double-click to install.
    - http://fpdownload.adobe.com/get/flas..._player_ax.exe
    For IE ...
    - http://fpdownload.adobe.com/get/flas...ash_player.exe
    For Firefox, other browsers, etc...

    Flash test site: http://www.adobe.com/software/flash/about/

    CVSS Severity: 10.0 (HIGH)
    "... before 10.3.183.5..."
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2011-2130
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2011-2134
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2011-2135
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2011-2136
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2011-2137
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2011-2138
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2011-2139
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2011-2140
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2011-2414
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2011-2415
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2011-2416
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2011-2417
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2011-2424 - Last revised: 08/16/2011
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2011-2425
    ___

    Adobe AIR v2.7.1 released
    - https://krebsonsecurity.com/2011/08/...shockwave-air/
    August 10, 2011 - "... flaws exist in Adobe AIR (before 2.7.1) for Windows, Mac and Android. Using an application that requires Adobe AIR (Tweetdeck or Pandora, for example) should prompt you to update to the latest version, AIR 2.7.1. If you don’t see a prompt to update the program, the latest version of AIR is available here*..."
    * http://get.adobe.com/air/
    ___

    Shockwave Player v11.6.1.629 released
    - https://www.adobe.com/support/securi...apsb11-19.html
    August 9, 2011
    CVE number: CVE-2010-4308, CVE-2010-4309, CVE-2011-2419, CVE-2011-2420, CVE-2011-2421, CVE-2011-2422, CVE-2011-2423.
    Platform: Windows and Macintosh
    Summary: Critical vulnerabilities have been identified in Adobe Shockwave Player 11.6.0.626 and earlier versions on the Windows and Macintosh operating systems. These vulnerabilities could allow an attacker, who successfully exploits these vulnerabilities, to run malicious code on the affected system... update to Adobe Shockwave Player 11.6.1.629... earlier versions upgrade to the newest version 11.6.1.629 available here:
    - http://get.adobe.com/shockwave/

    (Note: You may not have, want, or need Shockwave installed...)
    Test Shockwave: https://www.adobe.com/shockwave/welcome/
    ___

    Flash Media Server v4.0.3 v3.5.7 released
    - https://www.adobe.com/support/securi...apsb11-20.html
    August 9, 2011

    Photoshop CS5 and CS5.1 updates available
    - https://www.adobe.com/support/securi...apsb11-22.html
    August 9, 2011

    RoboHelp updates available
    - https://www.adobe.com/support/securi...apsb11-23.html
    August 9, 2011

    Last edited by AplusWebMaster; 2011-08-17 at 14:09.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  5. #95
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Post Flash Player v10.3.183.7 - addresses compatibility issues...

    FYI...

    Flash Player 10.3 Release Notes
    - http://kb2.adobe.com/cps/901/cpsid_90194.html

    Flash Player v10.3.183.7
    - http://kb2.adobe.com/cps/901/cpsid_9...ain_10.3.183.7
    "Adobe Flash Player 10.3.183.7 addresses compatibility issues:
    - Calls to gotoAndPlay() and gotoAndStop() no longer fail in some Flash applications which load shared libraries (2943612).
    - TextField instances which specify a negative offset (x property contains a negative value) now correctly flow the text horizontally instead of vertically (2941680).
    - Improved performance in some cases when displaying complex animations (2941931).
    - MSI versions of the Flash Player Installer now properly install the Native Settings Manager control panel on Windows (2939928).
    - Flash applications at certain websites (http://www.justin.tv, http://heylenmichel.de) now load correctly (2939645, 2944081)."
    ___

    Direct download current version - executable Flash Player installer... to your Desktop, then double-click to install.
    - http://fpdownload.adobe.com/get/flas..._player_ax.exe
    For IE ...
    - http://fpdownload.adobe.com/get/flas...ash_player.exe
    For Firefox, other browsers, etc...

    Flash test site: http://www.adobe.com/software/flash/about/

    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  6. #96
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Adobe Reader/Acrobat - critical updates: APSB11-24

    FYI...

    Adobe Reader and Acrobat - critical updates
    - https://www.adobe.com/support/securi...apsb11-24.html
    September 13, 2011
    CVE numbers: CVE-2011-1353, CVE-2011-2431, CVE-2011-2432, CVE-2011-2433, CVE-2011-2434, CVE-2011-2435, CVE-2011-2436, CVE-2011-2437, CVE-2011-2438, CVE-2011-2439, CVE-2011-2440, CVE-2011-2441, CVE-2011-2442
    "Critical vulnerabilities have been identified in Adobe Reader X (10.1) and earlier versions for Windows and Macintosh, Adobe Reader 9.4.2 and earlier versions for UNIX, and Adobe Acrobat X (10.1) and earlier versions for Windows and Macintosh. These vulnerabilities could cause the application to crash and potentially allow an attacker to take control of the affected system...
    ... Adobe recommends users of Adobe Reader X (10.1) and earlier versions for Windows and Macintosh update to Adobe Reader X (10.1.1). For users of Adobe Reader 9.4.5 and earlier versions for Windows and Macintosh, who cannot update to Adobe Reader X (10.1.1), Adobe has made available updates, Adobe Reader 9.4.6 and Adobe Reader 8.3.1...
    ... Adobe recommends users of Adobe Acrobat X (10.1) for Windows and Macintosh update to Adobe Acrobat X 10.1.1. Adobe recommends users of Adobe Acrobat 9.4.5 and earlier versions for Windows and Macintosh update to Adobe Acrobat 9.4.6, and users of Adobe Acrobat 8.3 and earlier versions for Windows and Macintosh update to Adobe Acrobat 8.3.1...
    Note: Support for Adobe Reader 8.x and Acrobat 8.x for Windows and Macintosh will end on November 3, 2011...

    Users can utilize the product's update mechanism. The default configuration is set to run automatic update checks on a regular schedule. Update checks can be manually activated by choosing Help > Check for Updates ..."
    ___

    - http://h-online.com/-1342490
    14 September 2011 - "... version 10.x offers an updated Adobe Approved Trust List (AATL) from which Adobe has removed all DigiNotar certificates. The 9.x versions don't yet dynamically update the AATL; this feature is planned to be included in future versions. Until then, users are advised to manually delete the certificates – Adobe has released instructions* on how to do so..."
    * http://blogs.adobe.com/security/2011...movalaatl.html
    ___

    - http://www.securitytracker.com/id/1026044
    Sep 13 2011
    Impact: Execution of arbitrary code via network, User access via local system, User access via network...
    Version(s): 8.x prior to 8.3.1, 9.x prior to 9.4.6, and 10.x prior to 10.1.1...

    - https://secunia.com/advisories/45978/
    Release Date: 2011-09-14
    Criticality level: Highly critical
    Impact: Security Bypass, Exposure of sensitive information, Privilege escalation,
    System access
    Where: From remote
    Solution Status: Vendor Patch...

    Last edited by AplusWebMaster; 2011-09-15 at 14:29.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  7. #97
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Flash Player v10.3.183.10 released

    FYI...

    Flash Player v10.3.183.10 released
    - https://www.adobe.com/support/securi...apsb11-26.html
    September 21, 2011
    CVE number: CVE-2011-2426, CVE-2011-2427, CVE-2011-2428, CVE-2011-2429, CVE-2011-2430, CVE-2011-2444
    Platform: All platforms
    Summary: Critical vulnerabilities have been identified inAdobe Flash Player 10.3.183.7 and earlier versions... being exploited in the wild in active targeted attacks... update to Adobe Flash Player 10.3.183.10... Flash Player for Android... update to Adobe Flash Player for Android 10.3.186.7...

    Direct download current version - executable Flash Player installer... to your Desktop, then double-click to install.
    - http://fpdownload.adobe.com/get/flas..._player_ax.exe
    For IE ...
    - http://fpdownload.adobe.com/get/flas...ash_player.exe
    For Firefox, other browsers, etc...

    Flash test site: http://www.adobe.com/software/flash/about/

    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2011-2426
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2011-2427
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2011-2428
    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2011-2430
    Last revised: 09/22/2011
    "... before 10.3.183.10..."
    CVSS v2 Base Score: 9.3 (HIGH)

    - https://secunia.com/advisories/46113/
    Release Date: 2011-09-22
    Criticality level: Highly critical
    Impact: Security Bypass, Cross Site Scripting, System access
    Where: From remote...
    Original Advisory: Adobe:
    http://www.adobe.com/support/securit...apsb11-26.html
    FortiGuard Labs:
    http://www.fortiguard.com/advisory/FGA-2011-32.html

    - http://www.securitytracker.com/id/1026084
    Sep 22 2011
    ___

    Adobe Reader and Acrobat updated... to 10.1.1, 9.4.6, 8.3.1
    - https://www.adobe.com/support/securi...apsb11-24.html
    Revised: September 21, 2011 - "... These updates also incorporate the Adobe Flash Player updates as noted in Security Bulletin APSB11-21 and Security Bulletin APSB11-26..."
    - https://www.adobe.com/support/securi...apsb11-21.html
    - https://www.adobe.com/support/securi...apsb11-26.html
    ___

    - https://www.us-cert.gov/current/#ado..._advisory_for3
    updated September 22, 2011

    Last edited by AplusWebMaster; 2011-09-23 at 14:43.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  8. #98
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Adobe Photoshop Security Advisory APSA11-03

    FYI...

    Adobe Photoshop Security Advisory APSA11-03
    - https://www.adobe.com/support/securi...apsa11-03.html
    September 30, 2011
    Platform: Windows
    "... Critical vulnerabilities exist in Adobe Photoshop Elements 8.0 and earlier versions. These two buffer overflow vulnerabilities (CVE-2011-2443) could cause a crash and potentially allow an attacker to take control of the affected system... Adobe is not aware of any attacks exploiting these vulnerabilities against Adobe Photoshop Elements to date. Photoshop Elements 10 and Photoshop Elements 9 are not vulnerable to this issue. Because Adobe Photoshop 8 and earlier versions are no longer supported, Adobe recommends users upgrade to Photoshop Elements 10 or Photoshop Elements 9..."

    - http://web.nvd.nist.gov/view/vuln/de...=CVE-2011-2443
    Last revised: 10/05/2011
    CVSS v2 Base Score: 9.3 (HIGH)
    "... Adobe Photoshop Elements 8.0 and earlier..."

    > http://www.adobe.com/cfusion/tdrc/in...ents&loc=en_us

    > https://www.adobe.com/products/photo...splayTab3.html
    ___

    - https://secunia.com/advisories/46277/
    Release Date: 2011-10-03
    Criticality level: Highly critical
    Impact: System access
    Where: From remote ...
    Solution: Upgrade to version 10.

    Last edited by AplusWebMaster; 2011-10-11 at 19:13.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  9. #99
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Flash Player v11.0.1.152 released

    FYI...

    Flash Player v11.0.1.152 released
    - http://kb2.adobe.com/cps/919/cpsid_91932.html
    October 4, 2011 - "... This release includes new features as well as enhancements and bug fixes related to security, stability, performance and device compatibility..."

    New Features in Flash Player 11 and AIR 3
    - http://kb2.adobe.com/cps/919/cpsid_9...n_new_features

    Known Issues
    - http://kb2.adobe.com/cps/919/cpsid_9...n_known_issues

    System Requirements - Flash Player 11
    - https://www.adobe.com/products/flash...ech-specs.html
    • Internet Explorer 7.0 and above, Mozilla Firefox 4.0 and above, Google Chrome, Safari 5.0 and above, Opera 11...
    [Apparently -not- compatible with Firefox v3.6.23, possibly others.]
    ___

    Downloads: https://www.adobe.com/special/produc...ribution3.html
    Flash Player 11 (64 bit)
    IE: http://fpdownload.macromedia.com/pub...ve_x_64bit.exe
    Flash Player 11 (32 bit)
    IE: http://fpdownload.macromedia.com/pub...ve_x_32bit.exe
    Firefox, other Plugin-based browsers: http://fpdownload.macromedia.com/pub...ugin_32bit.exe

    Flash test site: http://www.adobe.com/software/flash/about/
    ___

    - http://nakedsecurity.sophos.com/2011...th-brad-arkin/
    October 6, 2011 - "... Flash applications will now be able to use SSL socket connections to securely communicate over the network. Flash Player will now provide access to your operating system's cryptography APIs... This enables the use of a proper pseudo-random number generator for instances where greater security is required.
    Flash is now available in a 64 bit binary as well, and will take advantage of 64 bit ASLR (Address Space Layout Randomization) where available..."

    - http://blogs.adobe.com/asset/2011/09...y-updates.html
    ___

    - https://isc.sans.edu/diary.html?storyid=11731
    Oct 04 2011

    Last edited by AplusWebMaster; 2011-10-07 at 20:52.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  10. #100
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Flash click-jacking exploit...

    FYI...

    Flash click-jacking exploit...
    - https://isc.sans.edu/diary.html?storyid=11857
    Last Updated: 2011-10-21 - "... a blog post about a vulnerability in Flash that allows for a click jacking attack to turn on the clients camera and microphone. The attack is conceptually similar to the original click jacking attack presented in 2008. Back then Flash adjusted the control panel. The original attack "framed" the entire Flash control page. To prevent the attack, Adobe added frame busting code to the settings page. Feross' attack doesn't frame the entire page, but instead includes just the SWF file used to adjust the settings, bypassing the frame busting javascript in the process.

    Update: Adobe fixed the problem. The fix does not require any patches for client side code. Instead, adobe modified the control page and applet that users load from Adobe's servers. Details from Adobe:
    - http://blogs.adobe.com/psirt/2011/10...s-manager.html
    "... We have resolved the issue with a change to the Flash Player Settings Manager SWF file hosted on the Adobe website..."
    > http://www.macromedia.com/support/do...manager06.html
    ___

    - http://blogs.adobe.com/psirt/2011/10...d-acrobat.html
    October 21, 2011 - "The next quarterly security update for Adobe Reader and Acrobat has been rescheduled for January 10, 2012."

    Last edited by AplusWebMaster; 2011-10-24 at 00:00.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •