dslreports logo
Search similar:


uniqs
1808

chachazz
Premium Member
join:2003-12-14
kudos:10
·TELUS

2 edits

chachazz

Premium Member

Adobe Flash Player 16.0.0.287

Flash Player 16.0.0.287 is available.
DIgital Signature: January 18, 2015

Security Bulletin APSB 15-02

Release Notes (when posted): »helpx.adobe.com/flash-pl ··· tes.html

All downloads: »www.adobe.com/products/f ··· on3.html


GuruGuy
join:2002-12-16
Atlanta, GA

GuruGuy

Member

Are these coming out weekly now
--
GuruGuy
redwolfe_98
Premium Member
join:2001-06-11
kudos:3

redwolfe_98 to chachazz

Premium Member

to chachazz
thanks chachazz

adobe is great..

StuartMW
Who Is John Galt?
Premium Member
join:2000-08-06
Galt's Gulch
kudos:3

StuartMW to GuruGuy

Premium Member

to GuruGuy
said by GuruGuy:

Are these coming out weekly now

»Flash 0-Day Exploit Used by Angler Exploit Kit
--
Don't feed trolls--it only makes them grow!
StuartMW

StuartMW to chachazz

Premium Member

to chachazz
FYI the installers are digitally signed early Sun Jan 18th 2015. The flash executables are Sat Jan 17th 2015.
--
Don't feed trolls--it only makes them grow!

lordpuffer
RIP lil
Premium Member
join:2004-09-19
Albuquerque, NM
kudos:2

lordpuffer to chachazz

Premium Member

to chachazz
Thanks chachazz

WildByDesign
join:2014-09-05
Canada

WildByDesign to chachazz

Member

to chachazz
Sorry guys/gals, I gave the heads up on this 16.0.0.287 update yesterday but made the mistake of posting it in the previous thread for 16.0.0.257 when the right thing to do was to create a new thread for it. My first thought was to create a new thread, however, since Chrome 40 got the update first many hours before the official Flash download sites updated their information, I found it to be a bit mysterious at first. My apologies.

Anyways, it has now been confirmed that any version of Internet Explorer or any version of Firefox running Flash (prior to 16.0.0.287) was vulnerable on any version of Windows, including an up-to-date 8.1 as well. Chrome is the only one that was not vulnerable thus far. Not sure about Chromium though if it were to be running the NPAPI version as opposed to the PPAPI version of Flash.

StuartMW
Who Is John Galt?
Premium Member
join:2000-08-06
Galt's Gulch
kudos:3

StuartMW to chachazz

Premium Member

to chachazz
It seems 16.0.0.287 is still vulnerable

»Re: Flash 0-Day Exploit Used by Angler Exploit Kit
--
Don't feed trolls--it only makes them grow!

85160670
"If U know neither the enemy nor yoursel
Premium Member
join:2013-09-17
Edmonton, AB

85160670 to chachazz

Premium Member

to chachazz
THX & ACV ...... {{{ SMILE }}}

WildByDesign
join:2014-09-05
Canada

WildByDesign to StuartMW

Member

to StuartMW
said by StuartMW:

...

Thanks Stuart. That's where I was getting my information from as well. But I clearly misunderstood. I know that his English isn't the greatest, so I was trying to make sense of it. This is terrible if 16.0.0.287 is still vulnerable. Kafeine will continue to update is blog as he digs through it and tests some more, so we will have to keep an eye on his blog and see how it all plays out. Not good, that's for sure. Although I am glad that Chrome is not affected.

chachazz
Premium Member
join:2003-12-14
kudos:10
·TELUS

chachazz

Premium Member

Found mention of Security Bulletin APSB 15-02, however the link is not yet live.
--
Gladiator Security Forum

StuartMW
Who Is John Galt?
Premium Member
join:2000-08-06
Galt's Gulch
kudos:3

StuartMW to WildByDesign

Premium Member

to WildByDesign
said by WildByDesign:

I know that his English isn't the greatest, so I was trying to make sense of it.

Me too. I had to read it a few times. I saw the "included" so that nailed it for me.
--
Don't feed trolls--it only makes them grow!

chachazz
Premium Member
join:2003-12-14
kudos:10
·TELUS

chachazz

Premium Member

The Security Bulletin is live:
quote:
Adobe has released security updates for Adobe Flash Player for Windows, Macintosh and Linux. These updates address a vulnerability that could be used to circumvent memory randomization mitigations on the Windows platform.

Adobe is aware of reports that an exploit for CVE-2015-0310 exists in the wild, which is being used in attacks against older versions of Flash Player. Additionally, we are investigating reports that a separate exploit for Flash Player 16.0.0.287 and earlier also exists in the wild.

Adobe recommends users update their product installations to the latest versions:
• Users of the Adobe Flash Player desktop runtime for Windows and Macintosh should update to Adobe Flash Player 16.0.0.287.
• Users of the Adobe Flash Player Extended Support Release should update to Adobe Flash Player 13.0.0.262.
• Users of Adobe Flash Player for Linux should update to Adobe Flash Player 11.2.202.438.
• Adobe Flash Player installed with Google Chrome, as well as Internet Explorer on Windows 8.x, will automatically update to version 16.0.0.287.

These updates resolve a memory leak that could be used to circumvent memory address randomization on the Windows platform (CVE-2015-0310).
--
Gladiator Security Forum

Littlem129
Premium Member
join:2007-05-13
White Pine, TN

Littlem129 to chachazz

Premium Member

to chachazz
Got it...Thanks chachazz .

85160670
"If U know neither the enemy nor yoursel
Premium Member
join:2013-09-17
Edmonton, AB

85160670 to chachazz

Premium Member

to chachazz
Click for full size
Wow ..... what's this WARNING ¿ ¿

StuartMW
Who Is John Galt?
Premium Member
join:2000-08-06
Galt's Gulch
kudos:3

StuartMW

Premium Member

It means you should read your own threads

»New Adobe Flash Zero-Day found in the Wild
--
Don't feed trolls--it only makes them grow!

85160670
"If U know neither the enemy nor yoursel
Premium Member
join:2013-09-17
Edmonton, AB

85160670

Premium Member

{{{ SMILE }}} .... THX.

WildByDesign
join:2014-09-05
Canada

WildByDesign to chachazz

Member

to chachazz
Internet Explorer patch out now: »support.microsoft.com/kb/3033408
Advisory: »technet.microsoft.com/li ··· /2755801

Doesn't cover latest vuln though either.

Dustyn
Premium Member
join:2003-02-26
Ontario, CAN
kudos:13

Dustyn to chachazz

Premium Member

to chachazz
Got it thank you chachazz !
Mele20
Premium Member
join:2001-06-05
Hilo, HI
kudos:8

Mele20 to chachazz

Premium Member

to chachazz
Why has Microsoft not updated IE 11 on Win 10 Preview?

StuartMW
Who Is John Galt?
Premium Member
join:2000-08-06
Galt's Gulch
kudos:3

StuartMW to WildByDesign

Premium Member

to WildByDesign
said by WildByDesign:

Doesn't cover latest vuln though either.




quote:
Missed it by that much

Agent 86, Get Smart
--
Don't feed trolls--it only makes them grow!

WildByDesign
join:2014-09-05
Canada

WildByDesign to Mele20

Member

to Mele20
said by Mele20:

Why has Microsoft not updated IE 11 on Win 10 Preview?

Tech Preview is affected and is coming to WU soon.
Mele20
Premium Member
join:2001-06-05
Hilo, HI
kudos:8

Mele20

Premium Member

Microsoft's timing could be better. I installed the plugin version on 10 Preview (287...of course now we know it is vulnerable too) this morning about 2AM HST before I went to sleep. I installedthe IE version on IE 10 on the host Windows 8.0 Pro computer a few minutes ago. I suppose I could do that on 10 Preview also but since WU is mandatory on Win 10 Preview, I've been letting it install Flash Player updates, whereas, on Win 8 Pro I do it myself.

I installed Malwarebytes Anti Exploit yesterday on the host machine so I am ok there even if this latest version of Flash is vulnerable. I think I will install Malwarebytes Anti Exploit on 10 Preview also.
--
When governments fear people, there is liberty. When the people fear the government, there is tyranny. Thomas Jefferson

antdude
A Ninja Ant
VIP
join:2001-03-25
United State
kudos:5
·Time Warner Cable

antdude to StuartMW

VIP

to StuartMW
said by StuartMW:

said by WildByDesign:

Doesn't cover latest vuln though either.

quote:
Missed it by that much

Agent 86, Get Smart

Agent 99. ~
--
Ant @ AQFL.net and AntFarm.ma.cx.

StuartMW
Who Is John Galt?
Premium Member
join:2000-08-06
Galt's Gulch
kudos:3

StuartMW

Premium Member

said by antdude:

Agent 99.

Nope. Agent 86 (Maxwell Smart) was the one that said it. Agent 99 said "Oh Max...."
--
Don't feed trolls--it only makes them grow!

antdude
A Ninja Ant
VIP
join:2001-03-25
United State
kudos:5
·Time Warner Cable

antdude

VIP

said by StuartMW:

said by antdude:

Agent 99.

Nope. Agent 86 (Maxwell Smart) was the one that said it. Agent 99 said "Oh Max...."

No, I was drooling at Agent 99.
--
Ant @ AQFL.net and AntFarm.ma.cx.

StuartMW
Who Is John Galt?
Premium Member
join:2000-08-06
Galt's Gulch
kudos:3

StuartMW

Premium Member

Ahhh.. Barbara Feldon.

Not sure if she's still alive.
--
Don't feed trolls--it only makes them grow!
PX Eliezer
Premium Member
join:2013-03-10
Wakanda
kudos:10
·Optimum Voice
·callwithus
·Callcentric
·localphone.com

PX Eliezer

Premium Member

said by StuartMW:

Ahhh.. Barbara Feldon.

Not sure if she's still alive.

Yes, she is, the last surviving major character.

Bernie Kopell and David Ketchum also survive, they were in lesser roles.

M_
join:2010-05-01
Vancouver, BC

M_ to chachazz

Member

to chachazz
Click for full size
A 0-day exploit with a critical rating of 2!