siljalineI'm lovin' that double wide Premium Member join:2002-10-12 Montreal, QC kudos:18 ·Bell Fibe Internet
|
Security Advisory for Adobe Acrobat and Reader APSB15-24quote: Adobe is planning to release security updates on Tuesday, October 13, 2015 for Adobe Acrobat and Reader for Windows and Macintosh.
Advisory - » helpx.adobe.com/security ··· -24.htmlFor those socially inclined - » twitter.com/AdobeSecurit ··· 08389632 |
|
jap Premium Member join:2003-08-10 038xx |
jap
Premium Member
2015-Oct-10 2:41 pm
Translation: uninstall until patch arrives.
Thanks for the heads-up, siljaline. |
|
antdudeA Ninja Ant VIP join:2001-03-25 United State kudos:5 |
to siljaline
I am also predicting a Flash update too. :P |
|
siljalineI'm lovin' that double wide Premium Member join:2002-10-12 Montreal, QC kudos:18 |
The update should be available sometime later today. |
|
antdudeA Ninja Ant VIP join:2001-03-25 United State kudos:5 |
said by siljaline:The update should be available sometime later today. I wonder when. Good mawning. :P |
|
siljalineI'm lovin' that double wide Premium Member join:2002-10-12 Montreal, QC kudos:18 ·Bell Fibe Internet
|
 |  via Internal Update | |
said by antdude:I wonder when. Good mawning. :P Success |
|
DrStrangeTechnically feasible Premium Member join:2001-07-23 West Hartford, CT kudos:1 |
Flash Player 19.0.0.207, Acro Reader 11.0.13 or DC 15.009.20069 [stole this version number from graphic above  ] are now available on Adobe's site. |
|
siljalineI'm lovin' that double wide Premium Member join:2002-10-12 Montreal, QC kudos:18 |
Shop until you drop Adobe download landing page - » www.adobe.com/support/do ··· =Windows |
|
jap Premium Member join:2003-08-10 038xx |
to siljaline
Flash off-line installers Win & Mac = 19.0.0.207 Linux = 11.2.202.535 https://www.adobe.com/products/flashplayer/distribution3.html |
|
andyross MVM join:2003-05-04 Schaumburg, IL |
to siljaline
Looks like there may be another update very soon: quote: New zero-day exploit hits fully patched Adobe Flash Attacks used to hijack end users' computers when they visit booby-trapped sites.
» arstechnica.com/security ··· e-flash/ |
|
antdudeA Ninja Ant VIP join:2001-03-25 United State kudos:5 ·Time Warner Cable
|
to jap
Flash? This thread is about Acrobat and Reader. :P |
|
| antdude |
to andyross
said by andyross:Looks like there may be another update very soon: quote: New zero-day exploit hits fully patched Adobe Flash Attacks used to hijack end users' computers when they visit booby-trapped sites.
» arstechnica.com/security ··· e-flash/ That explains » www.free-codecs.com/down ··· ayer.htm mentioning a newer build. |
|
jap Premium Member join:2003-08-10 038xx |
to antdude
said by antdude:Flash? This thread is about Acrobat and Reader. :P Oops. Right pile of shit, wrong kernel. Sorry. |
|
siljalineI'm lovin' that double wide Premium Member join:2002-10-12 Montreal, QC kudos:18 |
siljaline
Premium Member
2015-Oct-13 10:18 pm
|
|
| siljaline |
to andyross
Disable Flash again until Adobe releases something to fix the newly found Zero-day is patched. |
|
| |
I recommend uninstalling Flash if at all possible. Or for the advanced users, uninstall it anyway, and then use a virtual machine for those rare situations where you need that piece of programming Swiss cheese.
As for the Reader... yeah, you might toss that too, especially now that browsers and even Windows itself offer quite a decent PDF reading environment. |
|
siljalineI'm lovin' that double wide Premium Member join:2002-10-12 Montreal, QC kudos:18 ·Bell Fibe Internet
|
Many are suggesting disabling or removing Flash while Adobe fiddles for four days or so to release the zero-day patch. Kill Flash: Adobe says patch to fix under-attack hole still days away - Via @ theregister.com » www.theregister.co.uk/20 ··· sh_flaw/ |
|
| |
to siljaline
I have set FireFox to ask to use. I can only find one site I go that requires it. I doubt if a weather site would be on a hackers list. ALTHOUGH |
|
camperjust visiting this planet Premium Member join:2010-03-21 Bethel, CT kudos:1 |
camper
Premium Member
2015-Oct-15 12:09 pm
 
I also have Firefox set to 'ask to use' for Flash. Lots of sites trigger the "ask", but very, very few sites actually need it for the content I want to view. |
|
siljalineI'm lovin' that double wide Premium Member join:2002-10-12 Montreal, QC kudos:18 |
to Ken1943
Irrespective of your Browser platform - having Flash installed is an open door for attacks since it's currently (your installed version) is, zero-day. There's been jokes floating around about staying away from certain sites but we won't go there. |
|
| |
to siljaline
Another update for Acrobat Reader (2015.009.20071). |
|
Frodo join:2006-05-05 kudos:1 ·magicJack
|
to siljaline
There is a nifty feature in EMET, the ASR feature that allows certain modules to be blocked for certain processes. One process I like to restrict whenever possible is Winhttp.dll, since it can be used to deposit malware. 
I've noticed this popup ever since I updated to the latest version, which represents a change in how that process works on my machine. So far, the only files I have accessed are files already on the machine, not a file that may need internet access. 
I get the popup on the startup of the reader, even if no PDF file is loaded. The reader still works right, so it is not critical that it accesses Winhttp.dll
|
|
siljalineI'm lovin' that double wide Premium Member join:2002-10-12 Montreal, QC kudos:18 ·Bell Fibe Internet
|
to bluepoint
 Reader DC current version |
My software seems to have auto-majically updated as well but I don't know how as I've got everything possible that would phone home disabled - yet here I am at the current version. |
|
| |
said by siljaline :My software seems to have auto-majically updated as well but I don't know how as I've got everything possible that would phone home disabled - yet here I am at the current version. You are running Adobe Acrobat Reader DC which, like Windows 10, is designed to update automatically. It's possible to modify this behavior by running the Adobe Customization Wizard DC or by editing the registry manually? Did you do that? If not, see the following links: Adobe Customization Wizard DC » www.adobe.com/support/do ··· pID=5892Updater (basic settings) » www.adobe.com/devnet-doc ··· _1_20396In the second summary table, you can see the default setting for update mode for the DC products is 3: Automatically download and install updates. If you do this manually, you want to set it to 1: Do not download or install updates automatically. If you haven't already, you might also want to disable the Adobe Acrobat Update Service and any related scheduled tasks. Here's a thread on Adobe Communities which discusses the issue and reader reactions to it: » forums.adobe.com/thread/ ··· tstart=0Sadly, more and more control is being taken away from the user. Pfft!  This is one of the reasons I still use Adobe Reader X and XI. |
|
siljalineI'm lovin' that double wide Premium Member join:2002-10-12 Montreal, QC kudos:18 ·Bell Fibe Internet
|
siljaline
Premium Member
2015-Oct-19 12:43 pm
 Adobe Update Service |
Could have sworn I had disabled the Adobe Update Service - (you might not want to do this at home unless you are comfortable disabling Services) - |
|
planet join:2001-11-05 Oz kudos:1 ·Cox HSI
|
to bluepoint
said by bluepoint:Another update for Acrobat Reader (2015.009.20071). Is this limited to DC only or is Acrobat Reader 11.0.13 due another update? I checked yesterday via internal updater and it said 11.0.13 was current. |
|
| |
Don't know just reporting what I see. If there was an update for reader 11, it would have been out already. |
|
siljalineI'm lovin' that double wide Premium Member join:2002-10-12 Montreal, QC kudos:18 |
Update checks can be manually activated by choosing Help > Check for Updates > usually does it and doesn't require a download landing page to fetch your newer version from. |
|
| |
to planet
said by planet :Is this limited to DC only or is Acrobat Reader 11.0.13 due another update? I checked yesterday via internal updater and it said 11.0.13 was current. Adobe Acrobat Reader DC 15.009.20071 was an out-of-cycle patch released on October 14, 2015 to fix a bug introduced in the earlier 15.009.20069 continuous update. 4069884: Windows taskbar is visible in Full Screen mode if RHP is collapsed. The following link has the version numbers, release dates, notes and type for the various versions of Adobe Reader: » helpx.adobe.com/acrobat/ ··· der.htmlIt still shows 11.0.13 as the latest release for Adobe Reader XI, so either this bug didn't affect that version or Adobe didn't get around to fixing it yet. |
|