<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Flash Player update available to address security vulnerabil in Security</title>
<link>http://www.dslreports.com/forum/r19655150</link>
<description></description>
<language>en</language>
<pubDate>Fri, 04 Dec 2009 14:15:07 EDT</pubDate>
<lastBuildDate>Fri, 04 Dec 2009 14:15:07 EDT</lastBuildDate>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19658803</link>
<description><![CDATA[<A HREF="/useremail/u/1395696"><b>Bubba17</b></A> : Well, I see some methods have been mentioned for determining your Flash version.<br><br>As for being in Add or Remove Programs, if you click on your Flash entry, it'll display, "Click here for support information", which then displays the version info along with a link to "Adobe Systems Incorporated", if clicked.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19658803</guid>
<pubDate>Thu, 20 Dec 2007 15:38:41 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19657735</link>
<description><![CDATA[<A HREF="/useremail/u/1502125"><b>Millenniumle</b></A> : For Windows IE ActiveX, go to: Windows>System32>Macromed>Flash.  There you will find a file named Flash<i>(x)</i>.ocx.  Right click the file and select "Properties," then select the version tab.<br><br>A bit of a manual way to go about it, but.... when you're done checking the verion you can send it to the recycle bin where Flash unfortunately belongs these days, annoying advertisement vehicle that it is and all. :D ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19657735</guid>
<pubDate>Thu, 20 Dec 2007 12:51:37 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19656715</link>
<description><![CDATA[<A HREF="/useremail/u/1079171"><b>lordpuffer</b></A> : Thanks....Sorry.....Missed that.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19656715</guid>
<pubDate>Thu, 20 Dec 2007 10:08:38 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19656677</link>
<description><![CDATA[<A HREF="/useremail/u/917630"><b>Cudni</b></A> : as referenced in 2nd post :)<br>&raquo;<A HREF="http://www.adobe.com/products/flash/about/" >www.adobe.com/products/flash/about/</A><br><br>also visit secunia site in case you have old version still lurking<br><br>Cudni<br><small>--<br>"Mercifully, he hit him with the soft end of the pistol." <br>Help yourself so God can help you.<br>MVP, Microsoft Windows Security 2006-2007</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19656677</guid>
<pubDate>Thu, 20 Dec 2007 10:02:00 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19656622</link>
<description><![CDATA[<A HREF="/useremail/u/1079171"><b>lordpuffer</b></A> : This may be a silly question, but how do I find the flash player to find out which version I have?  I found it under add/remove programs, and all it says is "Adobe Flash Player 9 Active X."  Thanks.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19656622</guid>
<pubDate>Thu, 20 Dec 2007 09:51:35 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19656007</link>
<description><![CDATA[<A HREF="/useremail/u/917630"><b>Cudni</b></A> : just delete the file referenced, it should give you the location it was found it.<br><br>Cudni]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19656007</guid>
<pubDate>Thu, 20 Dec 2007 06:29:09 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19656000</link>
<description><![CDATA[<A HREF="/useremail/u/1449681"><b>mouse</b></A> : I did a security check via secunia and noticed that I had two versions of flashplayer installed. Adobe Flash and Macromedia Flash - these were listed individually with the recommendation to upgrade as per advice in this thread. I looked for detailed instructions on the adobe site but did not find anything. I then uninstalled via add/remove the only apparent version of the Adobe flashplayer and reinstalled the latest version 9.0.115.0.<br>Redoing the secunia scan, this is now shown as secure/correct version but I am still shown the additional version of Macromedia Flash Player 6.084.0. How can I get rid of this? I tried the uninstall mentioned somewhere earlier in this thread but this only took care of the new version?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19656000</guid>
<pubDate>Thu, 20 Dec 2007 06:23:13 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19655902</link>
<description><![CDATA[<A HREF="/useremail/u/408621"><b>redwolfe_98</b></A> : thanks for posting the notice, nick, about the flash player security vulnerability.. i didn't install the new flash player, before, because there was no information saying that the update was needed and, also, i looked in the adobe forums and some people were having problems with the new update, so i passed on it.. however, when the update is necessary, in order to address security vulnerabilities, then i update.. :) ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19655902</guid>
<pubDate>Thu, 20 Dec 2007 05:01:24 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19655572</link>
<description><![CDATA[<A HREF="/useremail/u/1346679"><b>AB</b></A> : <div class="bquote"><small>said by  noway1 <A HREF="/useremail/u/1116435"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>. . Anyone heard of any way to substitute something for the Adobe Flash crapware?  (Sick of regular vulnerabilities requiring regular upgrades). </div>Microsoft Corp. now makes a competing crapware-- 'SilverLight' (or 'SilverNight', as Giorgio Maone, developer of the 'NoScript' extension for Firefox refers to it).<br>Whether or not it simply competes, or was designed as replacement crapware, I couldn't tell you off-hand.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19655572</guid>
<pubDate>Thu, 20 Dec 2007 01:38:38 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19655497</link>
<description><![CDATA[<A HREF="/useremail/u/461572"><b>MarkAW</b></A> : Yeah i guess your right.<br>Thanks. :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19655497</guid>
<pubDate>Thu, 20 Dec 2007 01:08:25 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19655489</link>
<description><![CDATA[<A HREF="/useremail/u/1346679"><b>AB</b></A> : <div class="bquote"><small>said by  MarkAW <A HREF="/useremail/u/461572"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>. . I guess what i am trying to say is why are they now posting this warning when people were asked to update to 9.0.115.0 15 days ago.</div>I think it's unlikely that the vast majority update their Flash player within two or three weeks of a new version coming out, don't you?  ;)<br><br>Half the computers in this world that have Flash probably still have a 6.x or 7.x version on them.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19655489</guid>
<pubDate>Thu, 20 Dec 2007 01:06:37 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19655451</link>
<description><![CDATA[<A HREF="/useremail/u/461572"><b>MarkAW</b></A> : AB thanks i saw your post and i was at the securia website earlier today using their scanner and wasn't warned about my Adobe Flash Player being out dated, plus i knew i had the latest version installed like i said since Dec 4th (15 days before this Adobe warning was posted). I guess what i am trying to say is why are they now posting this warning when people were asked to update to 9.0.115.0 15 days ago.<br>&raquo;<A HREF="/forum/r19559660-Update-Adobe-Flash-Player-901150">[Update] Adobe Flash Player 9.0.115.0</A><br><small>--<br>Advertising is legalized lying. - H.G. Wells<br>Pleasure in the job puts perfection in the work. - Aristotle</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19655451</guid>
<pubDate>Thu, 20 Dec 2007 00:55:47 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19655447</link>
<description><![CDATA[<A HREF="/useremail/u/1116435"><b>noway1</b></A> : Managed to get the Adobe Acrobat reader crapware off this computer by substituting PDF-XChange PDF Viewer.  Anyone heard of any way to substitute something for the Adobe Flash crapware?  (Sick of regular vulnerabilities requiring regular upgrades). ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19655447</guid>
<pubDate>Thu, 20 Dec 2007 00:53:58 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19655420</link>
<description><![CDATA[<A HREF="/useremail/u/1346679"><b>AB</b></A> : <div class="bquote"><small>said by  MarkAW <A HREF="/useremail/u/461572"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>. . are they trying to say that the 9.0.115.0 is vulnerable as well or what? :huh:</div>The Securia info I posted 2 posts above yours is dated the 19th of December, 2007, fwiw.<br><br>*Edit- Also, quoted from Nick's Original Post:<br><br>"Severity ratingAdobe categorizes this as a critical update and recommends affected users upgrade to version 9.0.115.0 (Win, Mac, Linux)."]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19655420</guid>
<pubDate>Thu, 20 Dec 2007 00:44:20 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19655347</link>
<description><![CDATA[<A HREF="/useremail/u/461572"><b>MarkAW</b></A> : <div class="bquote"><small>said by  tjack <A HREF="/useremail/u/886821"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>If I'm reading the info posted by Nick correctly these are the only versions affected:<br><br>Affected software versions: Adobe Flash Player 9.0.48.0 and earlier, 8.0.35.0 and earlier, and 7.0.70.0 and earlier.<br><br>If you updated on Dec 3rd to the latest version you don't need to add this.<br> </div>That's what i was thinking as well,because i have had this update since December 4th 2007. So what are they trying to say that the 9.0.115.0 is vulnerable as well or what? :huh:<br><small>--<br>Advertising is legalized lying. - H.G. Wells<br>Pleasure in the job puts perfection in the work. - Aristotle</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19655347</guid>
<pubDate>Thu, 20 Dec 2007 00:28:44 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19655150</link>
<description><![CDATA[<A HREF="/useremail/u/1393092"><b>Sindows 7</b></A> : Why dont they say all the darn versions are vulnerable?<br>Every version they ever had gets toasted, cant they get it right? :huh:]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19655150</guid>
<pubDate>Wed, 19 Dec 2007 23:44:32 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19655089</link>
<description><![CDATA[<A HREF="/useremail/u/1346679"><b>AB</b></A> : &raquo;<A HREF="http://secunia.com/advisories/28161/" >secunia.com/advisories/28161/</A><br><br>---------------------------<br>The vulnerabilities are reported in versions prior to 9.0.115.0.<br><br><b>Solution:</b><br>Update to version 9.0.115.0.<br>---------------------------]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19655089</guid>
<pubDate>Wed, 19 Dec 2007 23:35:55 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19650628</link>
<description><![CDATA[<A HREF="/useremail/u/886821"><b>tjack</b></A> : If I'm reading the info posted by Nick correctly these are the only versions affected:<br><br>Affected software versions: Adobe Flash Player 9.0.48.0 and earlier, 8.0.35.0 and earlier, and 7.0.70.0 and earlier.<br><br>If you updated on Dec 3rd to the latest version you don't need to add this.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19650628</guid>
<pubDate>Wed, 19 Dec 2007 11:41:14 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19650376</link>
<description><![CDATA[<A HREF="/useremail/u/1029026"><b>koma3504</b></A> : Thanks for the info.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19650376</guid>
<pubDate>Wed, 19 Dec 2007 11:02:26 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19650052</link>
<description><![CDATA[<A HREF="/useremail/u/634007"><b>SUMware</b></A> : Looks like this is the same version that was released on Dec. 3.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19650052</guid>
<pubDate>Wed, 19 Dec 2007 10:04:38 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19649822</link>
<description><![CDATA[<A HREF="/useremail/u/881809"><b>MagMan</b></A> : Thanks Guys got it. :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19649822</guid>
<pubDate>Wed, 19 Dec 2007 09:11:35 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19649660</link>
<description><![CDATA[<A HREF="/useremail/u/819609"><b>Grail Knight</b></A> : Thanks.<br><br>The Flash Player Uninstaller is available from here:<br><br>&raquo;<A HREF="http://www.adobe.com/shockwave/download/alternates/" >www.adobe.com/shockwave/download/alternates/</A><br><br>Users should also check their Flash Player Security settings after updating. <br><br><A HREF="http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager.html">Flash Player Security Panel</a><br><small>--<br>"It is a capital mistake to theorize before one has data. Insensibly one begins to twist facts to suit theories, instead of theories to suit facts." - Sherlock Holmes</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19649660</guid>
<pubDate>Wed, 19 Dec 2007 08:10:49 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19649544</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : The Linux update for Flash Player addresses a memory permissions issue that could lead to <b>privilege escalation</b>. (CVE-2007-6246)  :o<br>&raquo;<A HREF="http://www.adobe.com/support/security/bulletins/apsb07-20.html" >www.adobe.com/support/security/b&middot;&middot;&middot;-20.html</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19649544</guid>
<pubDate>Wed, 19 Dec 2007 07:25:14 EDT</pubDate>
</item>

<item>
<title>Re: Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19649534</link>
<description><![CDATA[<A HREF="/useremail/u/957998"><b>NICK ADSL UK</b></A> : With regards the above update please do make sure you are using the latest build. You can check that here. Also please note that this update was posted originally on the 3rd of December as to what has been updated remains unclear at this time as the build remains the same. None the less it is important to make sure you have this latest build <br>&raquo;<A HREF="http://www.adobe.com/products/flash/about/" >www.adobe.com/products/flash/about/</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19649534</guid>
<pubDate>Wed, 19 Dec 2007 07:21:29 EDT</pubDate>
</item>

<item>
<title>Flash Player update available to address security vulnerabil</title>
<link>http://www.dslreports.com/forum/remark,19649520</link>
<description><![CDATA[<A HREF="/useremail/u/957998"><b>NICK ADSL UK</b></A> : Flash Player update available to address security vulnerabilities<br>Release date: December 18, 2007<br><br>Vulnerability identifier: APSB07-20<br><br>CVE number: CVE-2007-6242, CVE-2007- 4768, CVE-2007-5275, CVE-2007- 6243, CVE-2007- 6244, CVE-2007- 6245, CVE-2007-4324, CVE-2007- 6246, CVE-2007-5476<br><br>Platform: All platforms<br><br>Affected software versions: Adobe Flash Player 9.0.48.0 and earlier, 8.0.35.0 and earlier, and 7.0.70.0 and earlier.<br><br>SummaryCritical vulnerabilities have been identified in Adobe Flash Player that could allow an attacker who successfully exploits these potential vulnerabilities to take control of the affected system. A malicious SWF must be loaded in Flash Player by the user for an attacker to exploit these potential vulnerabilities. Users are recommended to update to the most current version of Flash Player available for their platform.<br><br>Affected software versionsAdobe Flash Player 9.0.48.0 and earlier, 8.0.35.0 and earlier, and 7.0.70.0 and earlier. <br><br>To verify the Adobe Flash Player version number, access the About Flash Player page, or right-click on Flash content and select "About Adobe (or Macromedia) Flash Player" from the menu. If you use multiple browsers, perform the check for each browser you have installed on your system. <br><br>SolutionAdobe recommends all users of Adobe Flash Player 9.0.48.0 and earlier versions upgrade to the newest version 9.0.115.0 (Win, Mac, Linux), by downloading it from the Player Download Center, or by using the auto-update mechanism within the product when prompted.<br><br>Adobe will be providing an update to Adobe Flash Player 9.0.47.0 for Solaris at a later date. Customers can download and install the Flash Player public beta, which addresses these vulnerabilities, from the Adobe Labs site in the meantime.<br><br>For customers who cannot upgrade to Adobe Flash Player 9, Adobe has developed a patched version of Flash Player 7. Please refer to the Flash Player update TechNote.<br><br>Severity ratingAdobe categorizes this as a critical update and recommends affected users upgrade to version 9.0.115.0 (Win, Mac, Linux).<br><br>DetailsMultiple input validation errors have been identified in Flash Player 9.0.48.0 and earlier versions that could lead to the potential execution of arbitrary code. These vulnerabilities could be accessed through content delivered from a remote location via the user&#146;s web browser, email client, or other applications that include or reference the Flash Player. (CVE-2007- 4768, CVE-2007-6242)<br><br>This update introduces functionality to mitigate a potential issue could potentially aid an attacker in executing a DNS rebinding attack. For more information, see the following Adobe Developer Center article. (CVE-2007-5275)<br><br>This update introduces a new, stricter method for Flash Player to interpret cross-domain policy files. These changes could help prevent privilege escalation attacks against web servers hosting Flash content and cross-domain policy files. For more information, see the following Adobe Developer Center article. (CVE-2007- 6243)<br><br>This update restricts the unsupported asfunction: protocol to address potential cross-site scripting issues with some SWF files. This issue is specific to Flash Player 8 and Flash Player 9 and does not affect Flash Player 7. (CVE-2007-6244)<br><br>This update makes changes to the navigateToURL function to prevent potential Universal Cross-Site Scripting attacks. This issue is specific to the Flash Player ActiveX Control and the Internet Explorer Browser. (CVE-2007-6244)<br><br>This update resolves an issue that could allow remote attackers to modify HTTP headers of client requests and conduct HTTP Request Splitting attacks. (CVE-2007-6245)<br><br>This update introduces functionality to mitigate a potential port-scanning issue. For more information, see the following Knowledgebase Article. (CVE-2007-4324)<br><br>The Linux update for Flash Player addresses a memory permissions issue that could lead to privilege escalation. (CVE-2007-6246)<br><br>The Mac update for Flash Player addresses the issue with Flash Player originally reported by Opera and described in Security Advisory APSA07-05. (CVE-2007-5476)<br><br>&raquo;<A HREF="http://www.adobe.com/support/security/bulletins/apsb07-20.html" >www.adobe.com/support/security/b&middot;&middot;&middot;-20.html</A><br><br>download<br>&raquo;<A HREF="http://www.adobe.com/shockwave/download/download.cgi?P1_Prod_Version=ShockwaveFlash" >www.adobe.com/shockwave/download&middot;&middot;&middot;aveFlash</A><br><small>--<br><A HREF="http://www.wilderssecurity.com/index.php">Wilders Security Forum Admin<br>Microsoft MVP-Windows Security<br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19649520</guid>
<pubDate>Wed, 19 Dec 2007 07:14:15 EDT</pubDate>
</item>

</channel>
</rss>
