dslreports logo
 
    All Forums Hot Topics Gallery
spc
Search similar:


uniqs
9544

WildByDesign
join:2014-09-05
Canada

1 edit

4 recommendations

WildByDesign

Member

Adobe Flash Player 16.0.0.296

»blogs.adobe.com/psirt/?p=1160
quote:
UPDATED: Security Advisory for Adobe Flash Player (APSA15-01)

A Security Advisory (APSA15-01) has been published regarding a critical vulnerability (CVE-2015-0311) in Adobe Flash Player 16.0.0.287 and earlier versions for Windows, Macintosh and Linux. We are aware of reports that this vulnerability is being actively exploited in the wild via drive-by-download attacks against systems running Internet Explorer and Firefox on Windows 8 Windows 8.1 and below.

UPDATE (January 24): users who have enabled auto-update for the Flash Player desktop runtime will be receiving version 16.0.0.296 beginning on January 24. This version includes a fix for CVE-2015-0311. Adobe expects to have an update available for manual download during the week of January 26, and we are working with our distribution partners to make the update available in Google Chrome and Internet Explorer 10 and 11. For more information on updating Flash Player, please refer to this post. We will continue to provide updates on this issue via the Adobe PSIRT blog.

WildByDesign

WildByDesign

Member

My PPAPI version had already updated before I knew about it, apparently. Kudos to Adobe for pushing this out fast (on a Saturday of all days). Waiting on IE and Chrome now.
Mele20
Premium Member
join:2001-06-05
Hilo, HI

Mele20 to WildByDesign

Premium Member

to WildByDesign
But the manual update (and probably IE for Windows 8 and Preview 10) is not available until next week.

StuartMW
Premium Member
join:2000-08-06

StuartMW

Premium Member

No doubt one of the big download sites (e.g MajorGeeks) will post it soon.

I guess Adobe figures manual downloaders are mostly IT people who work Mon-Fri.

WildByDesign
join:2014-09-05
Canada

WildByDesign to Mele20

Member

to Mele20
Go to Task Scheduler and manually run Adobe Flash Player Updater for those who haven't been automatically updated yet.

jap
Premium Member
join:2003-08-10
038xx

1 recommendation

jap to WildByDesign

Premium Member

to WildByDesign
Yay. I can re-enable FP now.
But I have to say, two hours on YouTube (~27 vids) didn't hit a single video which didn't play smooth like silk in HTML5 with OpenH254 plugin.
»www.openh264.org/

Thanks for the heads-up, WBD.
Mele20
Premium Member
join:2001-06-05
Hilo, HI

Mele20 to WildByDesign

Premium Member

to WildByDesign
You can't get it that way. I went to Flash Player Advanced tab and reset it to check for updates. Then I clicked "check for updates" and I was sent to the IT download page first and then finally got to the consumer page. BOTH offer ONLY .287.

jap
Premium Member
join:2003-08-10
038xx

1 recommendation

jap

Premium Member

Similar waste of time here.
1. Manual launched (via run-as-admin)
C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe
which threw up a window, paused, disappeared (so I assume it wanted me to launch from somewhere else?)
2. Visited distribution3 page = .287build (expected)
3. Went to Adobe 'Check Flash' page which told me I needed to update my .287build and sent me to consumer d'load page
4. Downloaded & ran the f'ing stub installer which proceeded to install a parallel instance of .287 to the one which already existed.
5. Cursed and removed all three instances of Flash and deleted associated dirs and reg entries.
Guess: WildByDesign's mention of launch-from-Task-Scheduler works because Adobe is trying to protect us from ourselves by only allowing user=system to launch their fricken updater.

You so insistently suck, Adobe.
Frodo
join:2006-05-05

1 recommendation

Frodo

Member

I tried the task scheduler thing and got no where. So I went to services and started Adobe Flash Player Update Service, got a firewall prompt, temporarily allowed it, and the active x versions updated. Then I started the service again, and the plugin versions updated. All versions are 16_0_0_296 now, according to the file name.

Now, I'll update EMET to point to the new file names.

jap
Premium Member
join:2003-08-10
038xx

jap

Premium Member

That makes sense. Not as much sense as giving us an update button like ever other app on the planet but...

Congrats on your patch. I feel stupid for even trying since I do not need Flash anytime soon. A lesson to let the inimitable Adobe Way get there at it's own speed.
________________________

Daddy? Is this how terrorists are made?

Dustyn
Premium Member
join:2003-02-26
Ontario, CAN
·Carry Telecom
·TekSavvy Cable
Asus GT-AX11000
Technicolor TC4400

1 edit

4 recommendations

Dustyn to WildByDesign

Premium Member

to WildByDesign
Get it here: »www.adobe.com/products/f ··· on3.html
daveinpoway
Premium Member
join:2006-07-03
Poway, CA

daveinpoway to WildByDesign

Premium Member

to WildByDesign
I just checked my Mac- the 16.0.0.296 version was automatically installed.

I normally want control over what gets installed, but, given that keeping up with Flash updates is so important, I have selected the option to allow Adobe to update Flash automatically.
Mele20
Premium Member
join:2001-06-05
Hilo, HI

Mele20 to Frodo

Premium Member

to Frodo
Click for full size
said by Frodo:

So I went to services and started Adobe Flash Player Update Service

What OS? I don't have that service on Windows 8.0Pro.

I do have Mozilla making a no-no and telling me Flash is up to date.

Even if I could get it before Monday, I have to wait for Microsoft to issue an update for IE 10 and 11. But right now, I would settle for fixing Flash on Mozilla based browsers since my default browser is Pale Moon and I also use Fx 35 Portable and Fx 31.4 ESR and SeaMonkey a lot.

jap
Premium Member
join:2003-08-10
038xx

3 recommendations

jap to WildByDesign

Premium Member

to WildByDesign
offline installers of ver, 16.0.0.296 are now available on the distribution3 page.

»www.adobe.com/products/f ··· on3.html
Mele20
Premium Member
join:2001-06-05
Hilo, HI

Mele20

Premium Member

Thank you. Got it for Windows 8.0 Pro and then called up the virtual machine running Win 10 Preview to find it had crashed again (very unstable build). Got it installed there also.

Still have to wait for Microsoft to issue an update for IE 10 and 11.

v6movement
@pppoe.ca

v6movement to WildByDesign

Anon

to WildByDesign
said by WildByDesign:

My PPAPI version had already updated before I knew about it, apparently. Kudos to Adobe for pushing this out fast (on a Saturday of all days). Waiting on IE and Chrome now.

Comment doesn't make sense. PPAPI is the API used by Chrome. You probably mean NPAPI.

WildByDesign
join:2014-09-05
Canada

WildByDesign to jap

Member

to jap
said by jap:

offline installers of ver, 16.0.0.296 are now available on the distribution3 page.

»www.adobe.com/products/f ··· on3.html

Thank you for the heads up on the updated offline installers, much appreciated. That is always the preferred method of most, for sure. Glad they have updated that page quicker than expected as well since they were initially looking at the start of next week. I guess Adobe kept some guys/gals working overtime on the weekend.
said by v6movement :

Comment doesn't make sense. PPAPI is the API used by Chrome. You probably mean NPAPI.

Sorry that I wasn't more specific on that comment as I was in a hurry to watch the fights last night. This is referring to the PPAPI which shows in the Advanced tab of the Flash Player Settings and is specific to Chromium (and possibly Opera). The binaries are identical to those used by Chrome as well but installed to SysWOW64/System32 just the same as the plugin version of Flash. As a matter of fact, I have used this method to replace (manually) the PPAPI Flash used within Chrome until Google releases an update for Chrome. Although there isn't much worry since Chrome hasn't been targeted with this yet.
said by Mele20:

You can't get it that way. I went to Flash Player Advanced tab and reset it to check for updates. Then I clicked "check for updates" and I was sent to the IT download page first and then finally got to the consumer page. BOTH offer ONLY .287.

My apologies, I am not sure why the Task Scheduler method did not work for you. It could be that Adobe is rolling it out by Region or some sort of method to get it out gracefully without overloading their servers. It seems that in most cases they have pushed the update out already which is good. I manually installed the plugin version (.287) just to test. Checked Advanced tab to confirm. Then ran the scheduled task manually. Waited about 2-3 minutes. Then checked Advanced tab again and it was at (.296). So it worked in my case, but could be rolling out by region or something. Either way, the offline installers are out so it's all good now. Cheers!

StuartMW
Premium Member
join:2000-08-06

StuartMW to jap

Premium Member

to jap
Thanks. Just got and installed them. I wasn't expecting them for a few a few more days.

BTW I don't allow the phone home aka update service to run and actually delete the .exe for it right after installation.

carpetshark3
Premium Member
join:2004-02-12
Idledale, CO

carpetshark3 to WildByDesign

Premium Member

to WildByDesign
What's the story on the 13.0.0.264 release? I don't see it mentioned.

StuartMW
Premium Member
join:2000-08-06

StuartMW

Premium Member

Is that an extended service release (ESR)?
redwolfe_98
Premium Member
join:2001-06-11

redwolfe_98 to carpetshark3

Premium Member

to carpetshark3
said by carpetshark3:

What's the story on the 13.0.0.264 release? I don't see it mentioned.

if you are using the ESR version, you need to install the update.. the update can be downloaded from here:

»www.adobe.com/products/f ··· on3.html
85160670 (banned)
"If U know neither the enemy nor yoursel
join:2013-09-17
Edmonton, AB

85160670 (banned) to jap

Member

to jap
Click for full size
Just open your LINK & ...... voila " April - April " ¿ ¿
redwolfe_98
Premium Member
join:2001-06-11

redwolfe_98

Premium Member

said by 85160670:

Just open your LINK &....

you must have opened a cached webpage..
85160670 (banned)
"If U know neither the enemy nor yoursel
join:2013-09-17
Edmonton, AB

85160670 (banned)

Member

Click for full size
Click for full size
THX & ACK ..... redwolfe_98 .The TRUTH lies on browser rendering engine, with IE-11 got the right one as shown above *_* .Just why QUALYS would NOT run TEST my IE-11 after this update ¿ ¿

hayc59
Your a Daisy
Premium Member
join:2001-02-26

hayc59 to WildByDesign

Premium Member

to WildByDesign
I cannot get this to work in FireFox, I keep getting the version before this
any help please

siljaline
I'm lovin' that double wide
Premium Member
join:2002-10-12
Montreal, QC

siljaline to WildByDesign

Premium Member

to WildByDesign
Click for full size
Adobe ActiveX
Click for full size
Adobe NAPI
My ActiveX and NAPI versions are now current.
85160670 (banned)
"If U know neither the enemy nor yoursel
join:2013-09-17
Edmonton, AB

85160670 (banned)

Member

Click for full size
Choose your right browser download @ the download bottom this page :"Adobe Flash Player 16.0.0.296"......[ »www.neowin.net/news/adob ··· -1600296 ]

WildByDesign
join:2014-09-05
Canada

WildByDesign

Member

Click for full size
Qualys shows that my Flash Player in Chrome is secure and Up To Date, yet Chrome itself is Pre-release. That seems weird, maybe they haven't updated their database for Chrome. I haven't used Qualys Browser Check before so I am not very familiar with it.
WildByDesign

WildByDesign

Member

Click for full size
Does anybody know why 16.0.0.296 is reported by Qualys to be insecure running under Firefox, yet secure running under Chrome? Qualys states that this version still includes vulnerabilities.

Also, does anyone know why Chrome doesn't get a button to 'Install Plugin'?

Thanks!
PX Eliezer1
Premium Member
join:2013-03-10
Zubrowka USA

PX Eliezer1

Premium Member

said by WildByDesign:

Also, does anyone know why Chrome doesn't get a button to 'Install Plugin'?

Chrome has their own internal version of Flash (called pepper).