Welcome to your place for tech questions! ( Log In or Join today ) Get answers from experts today. (it's 100% free) Virus removal forum
![]() ![]() |
Feb 27 2013, 06:18 AM
Post
#106
|
|
![]() AplusWebMaster ![]() ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 7,404 Joined: 30-December 03 From: USA Member No.: 1,643 Operating System: XP/SP3, Win7/SP1 |
Flash 11.6.602.171 released - https://www.adobe.com/support/security/bull.../apsb13-08.html Feb 26, 2013 CVE number: - https://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2013-0504 - 10.0 (HIGH) - https://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2013-0643 - 9.3 (HIGH) - https://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2013-0648 - 9.3 (HIGH) Platform: All platforms Adobe has released security updates for Adobe Flash Player 11.6.602.168 and earlier versions for Windows, Adobe Flash Player 11.6.602.167 and earlier versions for Macintosh, and Adobe Flash Player 11.2.202.270 and earlier versions for Linux. These updates address vulnerabilities that could cause a crash and potentially allow an attacker to take control of the affected system. Summary: Adobe is aware of reports that CVE-2013-0643 and CVE-2013-0648 are being exploited in the wild in targeted attacks designed to trick the user into clicking a link which directs to a website serving malicious Flash (SWF) content. The exploit for CVE-2013-0643 and CVE-2013-0648 is designed to target the Firefox browser. Adobe recommends users update their product installations to the latest versions: - Users of Adobe Flash Player 11.6.602.168 and earlier versions for Windows and Adobe Flash Player 11.6.602.167 and earlier versions for Macintosh should update to Adobe Flash Player 11.6.602.171. - Users of Adobe Flash Player 11.2.202.270 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.273. - Adobe Flash Player installed with Google Chrome will automatically be updated to the latest Google Chrome version, which will include Adobe Flash Player 11.6.602.171 for Windows, Macintosh and Linux. - Adobe Flash Player installed with Internet Explorer 10 for Windows 8 will automatically be updated to the latest version of Internet Explorer 10, which will include Adobe Flash Player 11.6.602.171 for Windows... Flash Download: > https://www.adobe.com/products/flashplayer/...tribution3.html Flash test site: http://helpx.adobe.com/flash-player/kb/fin...on_your_machine ___ MS Security Advisory (2755801) Update for Vulnerabilities in Adobe Flash Player in IE 10 - http://technet.microsoft.com/en-us/security/advisory/2755801 "... updates are available from... Windows Update..." Affected Software: Windows 8, Windows Server 2012, Windows RT V9.0 (February 26, 2013): Added KB2819372 to the Current Update section. ___ - https://secunia.com/advisories/52374/ Release Date: 2013-02-27 Criticality level: Extremely critical Impact: Security Bypass, System access Where: From remote... Solution: Update to a fixed version. Original Advisory: Adobe: http://www.adobe.com/support/security/bull.../apsb13-08.html ___ -Fake- Adobe Flash update page - https://www.symantec.com/connect/sites/defa...s/Figure1_6.png Feb 27, 2013 - http://www.symantec.com/connect/blogs/fake...rms-click-fraud Feb 27, 2013 - "... To ensure that you do not become a victim in the first place, please ensure that your antivirus definitions are constantly updated and that your software packages are also regularly updated. Do not download updates from third-party sites and always double check the URL of the download that is being offered." This post has been edited by AplusWebMaster: Mar 2 2013, 08:59 AM |
|
|
|
Mar 12 2013, 12:06 PM
Post
#107
|
|
![]() AplusWebMaster ![]() ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 7,404 Joined: 30-December 03 From: USA Member No.: 1,643 Operating System: XP/SP3, Win7/SP1 |
FYI...
Flash v11.6.602.180 released - https://www.adobe.com/support/security/bull.../apsb13-09.html March 12, 2013 CVE number: - https://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2013-0646 - 10.0 (HIGH) - https://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2013-0650 - 10.0 (HIGH) - https://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2013-1371 - 10.0 (HIGH) - https://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2013-1375 - 10.0 (HIGH) Platform: All Platforms Summary: Adobe has released security updates for Adobe Flash Player 11.6.602.171 and earlier versions for Windows and Macintosh, Adobe Flash Player 11.2.202.273 and earlier versions for Linux, Adobe Flash Player 11.1.115.47 and earlier versions for Android 4.x, and Adobe Flash Player 11.1.111.43 and earlier versions for Android 3.x and 2.x. These updates address vulnerabilities that could cause a crash and potentially allow an attacker to take control of the affected system. Adobe recommends users update their product installations to the latest versions: - Users of Adobe Flash Player 11.6.602.171 and earlier versions for Windows and Macintosh should update to Adobe Flash Player 11.6.602.180. - Users of Adobe Flash Player 11.2.202.273 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.275. - Adobe Flash Player 11.6.602.171 installed with Google Chrome will automatically be updated to the latest Google Chrome version, which will include Adobe Flash Player 11.6.602.180 for Windows, Macintosh and Linux. - Adobe Flash Player 11.6.602.171 installed with Internet Explorer 10 for Windows 8 will automatically be updated to the latest Internet Explorer 10 version, which will include Adobe Flash Player 11.6.602.180 for Windows. - Users of Adobe Flash Player 11.1.115.47 and earlier versions on Android 4.x devices should update to Adobe Flash Player 11.1.115.48. - Users of Adobe Flash Player 11.1.111.43 and earlier versions for Android 3.x and 2.x should update to Flash Player 11.1.111.44. - Users of Adobe AIR 3.6.0.597 and earlier versions for Windows, Macintosh and Android should update to Adobe AIR 3.6.0.6090. - Users of the Adobe AIR 3.6.0.597 SDK and earlier versions should update to the Adobe AIR 3.6.0.6090 SDK. - Users of the Adobe AIR 3.6.0.599 SDK & Compiler and earlier versions should update to the Adobe AIR 3.6.0.6090 SDK & Compiler. Flash Download: > https://www.adobe.com/products/flashplayer/...tribution3.html Flash test site: - http://helpx.adobe.com/flash-player/kb/fin...on_your_machine >> http://get.adobe.com/air/ This post has been edited by AplusWebMaster: Mar 16 2013, 11:29 PM |
|
|
|
Apr 9 2013, 01:12 PM
Post
#108
|
|
![]() AplusWebMaster ![]() ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 7,404 Joined: 30-December 03 From: USA Member No.: 1,643 Operating System: XP/SP3, Win7/SP1 |
FYI...
Flash v11.7.700.169 released - https://www.adobe.com/support/security/bull.../apsb13-11.html April 9, 2013 CVE number: - https://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2013-1378 - 7.5 (HIGH) - https://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2013-1379 - 7.5 (HIGH) - https://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2013-1380 - 7.5 (HIGH) - https://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2013-2555 - 10.0 (HIGH) Summary: Adobe has released security updates for Adobe Flash Player 11.6.602.180 and earlier versions for Windows and Macintosh, Adobe Flash Player 11.2.202.275 and earlier versions for Linux, Adobe Flash Player 11.1.115.48 and earlier versions for Android 4.x, and Adobe Flash Player 11.1.111.44 and earlier versions for Android 3.x and 2.x. These updates address vulnerabilities that could cause a crash and potentially allow an attacker to take control of the affected system. Adobe recommends users update their product installations to the latest versions: - Users of Adobe Flash Player 11.6.602.180 and earlier versions for Windows and Macintosh should update to Adobe Flash Player 11.7.700.169. - Users of Adobe Flash Player 11.2.202.275 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.280. - Adobe Flash Player 11.6.602.180 installed with Google Chrome will automatically be updated to the latest Google Chrome version, which will include Adobe Flash Player 11.7.700.179 for Windows and 11.7.700.169 for Macintosh and Linux. - Adobe Flash Player 11.6.602.180 installed with Internet Explorer 10 will automatically be updated to the latest Internet Explorer 10 version, which will include Adobe Flash Player 11.7.700.169 for Windows 8. - Users of Adobe Flash Player 11.1.115.48 and earlier versions on Android 4.x devices should update to Adobe Flash Player 11.1.115.54. - Users of Adobe Flash Player 11.1.111.44 and earlier versions for Android 3.x and 2.x should update to Flash Player 11.1.111.50. - Users of Adobe AIR 3.6.0.6090 and earlier versions for Windows, Macintosh and Android should update to Adobe AIR 3.7.0.1530. - Users of the Adobe AIR 3.6.0.6090 SDK & Compiler and earlier versions should update to the Adobe AIR 3.7.0.1530 SDK & Compiler... Flash Download: > https://www.adobe.com/products/flashplayer/...tribution3.html Flash test site: - http://helpx.adobe.com/flash-player/kb/fin...on_your_machine >> http://get.adobe.com/air/ - https://secunia.com/advisories/52931/ Release Date: 2013-04-09 Criticality level: Highly critical Impact: System access Where: From remote... Solution: Update to a fixed version. ___ Shockwave v12.0.2.122 released - https://www.adobe.com/support/security/bull.../apsb13-12.html April 9, 2013 CVE number: CVE-2013-1383, CVE-2013-1384, CVE-2013-1385, CVE-2013-1386 Summary: Adobe has released a security update for Adobe Shockwave Player 12.0.0.112 and earlier versions on the Windows and Macintosh operating systems. This update addresses vulnerabilities that could allow an attacker, who successfully exploits these vulnerabilities, to run malicious code on the affected system. Adobe recommends users of Adobe Shockwave Player 12.0.0.112 and earlier versions update to Adobe Shockwave Player 12.0.2.122 ... Solution: Adobe recommends users of Adobe Shockwave Player 12.0.0.112 and earlier versions update to the newest version 12.0.2.122, available here: http://get.adobe.com/shockwave/ - https://secunia.com/advisories/52981/ Release Date: 2013-04-10 Criticality level: Highly critical Impact: System access Where: From remote... Solution: Update to version 12.0.2.122 ___ ColdFusion hotfix - https://www.adobe.com/support/security/bull.../apsb13-10.html April 9, 2013 CVE number: CVE-2013-1387, CVE-2013-1388 Summary: Adobe has released a security hotfix for ColdFusion 10, 9.0.2, 9.0.1 and 9.0 for Windows, Macintosh and UNIX. Adobe recommends users update their product installation... Affected software versions: ColdFusion 10, 9.0.2, 9.0.1 and 9.0 for Windows, Macintosh and UNIX. Solution: Adobe recommends ColdFusion customers update their installation using the instructions provided in the technote: - http://helpx.adobe.com/coldfusion/kb/coldf...-apsb13-10.html - https://secunia.com/advisories/52995/ Release Date: 2013-04-10 Criticality level: Moderately critical Impact: Security Bypass, Spoofing Where: From remote... Solution: Apply hotfix. This post has been edited by AplusWebMaster: Apr 11 2013, 01:22 PM |
|
|
|
May 9 2013, 07:57 AM
Post
#109
|
|
![]() AplusWebMaster ![]() ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 7,404 Joined: 30-December 03 From: USA Member No.: 1,643 Operating System: XP/SP3, Win7/SP1 |
FYI...
0-day ColdFusion critical vulnerability - https://isc.sans.edu/diary.html?storyid=15770 - https://www.adobe.com/support/security/advi.../apsa13-03.html May 8, 2013 CVE number: https://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2013-3336 Summary: Adobe has identified a critical vulnerability affecting ColdFusion 10, 9.0.2, 9.0.1 and 9.0 and earlier versions for Windows, Macintosh and UNIX. This vulnerability (CVE-2013-3336) could permit an unauthorized user to remotely retrieve files stored on the server. There are reports that an exploit for this vulnerability is publicly available. ColdFusion customers who have restricted public access to the CFIDE/administrator, CFIDE/adminapi and CFIDE/gettingstarted directories (as outlined in the ColdFusion 9 Lockdown Guide* and ColdFusion 10 Lockdown Guide**) are already mitigated against this issue. Customers who have not already applied these steps can protect themselves from CVE-2013-3336 by implementing the following configuration settings: - Restrict public access to the CFIDE/administrator, CFIDE/adminapi and CFIDE/gettingstarted directories by following the hardening guidance in the ColdFusion 9 Lockdown Guide and ColdFusion 10 Lockdown Guide** We are in the process of finalizing a fix for this issue and expect a hotfix for ColdFusion 10, 9.0.2, 9.0.1 and 9.0 for Windows, Macintosh and UNIX to be available on May 14, 2013... * http://wwwimages.adobe.com/www.adobe.com/c...guide-wp-ue.pdf ** http://wwwimages.adobe.com/www.adobe.com/c...own%20Guide.pdf Revisions - May 9, 2013: Revised to clarify the CFIDE/gettingstarted directory is only applicable to ColdFusion version 8.x and earlier. - http://atlas.arbor.net/briefs/index#366717635 Severity: High Severity May 09, 2013 17:23 "... being exploited in the wild..." ___ Prenotification Security Advisory for Adobe Reader and Acrobat - https://www.adobe.com/support/security/bull.../apsb13-15.html May 9, 2013 - "Summary: Adobe is planning to release security updates on Tuesday, May 14, 2013 for Adobe Reader and Acrobat..." This post has been edited by AplusWebMaster: May 10 2013, 04:46 AM |
|
|
|
May 14 2013, 10:45 AM
Post
#110
|
|
![]() AplusWebMaster ![]() ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 7,404 Joined: 30-December 03 From: USA Member No.: 1,643 Operating System: XP/SP3, Win7/SP1 |
FYI...
Flash v11.7.700.202 released - https://www.adobe.com/support/security/bull.../apsb13-14.html May 14, 2013 CVE number: CVE-2013-2728, CVE-2013-3324, CVE-2013-3325, CVE-2013-3326, CVE-2013-3327, CVE-2013-3328, CVE-2013-3329, CVE-2013-3330, CVE-2013-3331, CVE-2013-3332, CVE-2013-3333, CVE-2013-3334, CVE-2013-3335 Platform: All platforms Summary: Adobe has released security updates for Adobe Flash Player 11.7.700.169 and earlier versions for Windows and Macintosh, Adobe Flash Player 11.2.202.280 and earlier versions for Linux, Adobe Flash Player 11.1.115.54 and earlier versions for Android 4.x, and Adobe Flash Player 11.1.111.50 and earlier versions for Android 3.x and 2.x. These updates address vulnerabilities that could cause a crash and potentially allow an attacker to take control of the affected system. Adobe recommends users update their product installations to the latest versions: - Users of Adobe Flash Player 11.7.700.169 and earlier versions for Windows and Macintosh should update to Adobe Flash Player 11.7.700.202. - Users of Adobe Flash Player 11.2.202.280 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.285. - Adobe Flash Player 11.7.700.169 installed with Google Chrome (and version 11.7.700.179 on the Windows platform) will automatically be updated to the latest Google Chrome version, which will include Adobe Flash Player 11.7.700.202 for Windows, Macintosh and Linux. - Adobe Flash Player 11.7.700.169 installed with Internet Explorer 10 will automatically be updated to the latest Internet Explorer 10 version, which will include Adobe Flash Player 11.7.700.202 for Windows 8. - Users of Adobe Flash Player 11.1.115.54 and earlier versions on Android 4.x devices should update to Adobe Flash Player 11.1.115.58. - Users of Adobe Flash Player 11.1.111.50 and earlier versions for Android 3.x and 2.x should update to Flash Player 11.1.111.54. - Users of Adobe AIR 3.7.0.1530 and earlier versions for Windows and Macintosh should update to Adobe AIR 3.7.0.1860. - Users of Adobe AIR 3.7.0.1660 and earlier versions for Android should update to Adobe AIR 3.7.0.1860. - Users of the Adobe AIR 3.7.0.1530 SDK & Compiler and earlier versions should update to the Adobe AIR 3.7.0.1860 SDK & Compiler... Flash Download: > https://www.adobe.com/products/flashplayer/...tribution3.html Flash test site: - http://helpx.adobe.com/flash-player/kb/fin...on_your_machine >> http://get.adobe.com/air/ ___ Adobe Reader/Acrobat v11.0.03 released - https://www.adobe.com/support/security/bull.../apsb13-15.html May 14, 2013 CVE number: CVE-2013-2549, CVE-2013-2550, CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2724, CVE-2013-2725, CVE-2013-2726, CVE-2013-2727, CVE-2013-2729, CVE-2013-2730, CVE-2013-2731, CVE-2013-2732, CVE-2013-2733, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-2737, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, CVE-2013-3341, CVE-2013-3342 Platform: All Summary: Adobe has released security updates for Adobe Reader and Acrobat XI (11.0.02) and earlier versions for Windows and Macintosh, and Adobe Reader 9.5.4 and earlier 9.x versions for Linux. These updates address vulnerabilities that could cause a crash and potentially allow an attacker to take control of the affected system. Adobe recommends users update their product installations to the latest versions: - Users of Adobe Reader XI (11.0.02) for Windows and Macintosh should update to Adobe Reader XI (11.0.03). - For users of Adobe Reader X (10.1.6) and earlier versions for Windows and Macintosh, who cannot update to Adobe Reader XI (11.0.03), Adobe has made available the update Adobe Reader X (10.1.7). - For users of Adobe Reader 9.5.4 and earlier versions for Windows and Macintosh, who cannot update to Adobe Reader XI (11.0.03), Adobe has made available the update Adobe Reader 9.5.5. - Users of Adobe Reader 9.5.4 and earlier versions for Linux should update to Adobe Reader 9.5.5. - Users of Adobe Acrobat XI (11.0.02) for Windows and Macintosh should update to Adobe Acrobat XI (11.0.03). - For users of Adobe Acrobat X (10.1.6) and earlier versions for Windows and Macintosh, who cannot update to Adobe Acrobat XI (11.0.03), Adobe has made available the update Adobe Acrobat X (10.1.7). - For users of Adobe Acrobat 9.5.4 and earlier versions for Windows and Macintosh, who cannot update to Adobe Acrobat XI (11.0.03), Adobe has made available the update Adobe Acrobat 9.5.5... ___ ColdFusion hotfix available - https://www.adobe.com/support/security/bull.../apsb13-13.html May 14, 2013 CVE number: CVE-2013-1389, CVE-2013-3336 Platform: All Summary: Adobe has released a security hotfix for ColdFusion 10, 9.0.2, 9.0.1 and 9.0 for Windows, Macintosh and UNIX. This hotfix addresses a vulnerability (CVE-2013-1389) that could allow remote arbitrary code execution on a system running ColdFusion, and a vulnerability (CVE-2013-3336) that could permit an unauthorized user to remotely retrieve files stored on the server. Adobe is aware of reports that CVE-2013-3336 (referenced in Security Advisory APSA13-03) is being exploited in the wild against ColdFusion customers. Adobe recommends users update their product installation using the instructions provided in the "Solution" ... Solution: Adobe recommends ColdFusion customers update their installation using the instructions provided in the technote located here: - http://helpx.adobe.com/coldfusion/kb/coldf...-apsb13-13.html Customers should also apply the security configuration settings as outlined on the ColdFusion Security page, as well as review the ColdFusion 9 Lockdown Guide and ColdFusion 10 Lockdown Guide. |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
1 | pitchermark | 1,583 | 21st April 2006 - 11:52 AM Last post by: Doug |
|||
![]() |
9 | Biker-T | 3,663 | 19th March 2005 - 04:31 PM Last post by: HM2K |
|||
![]() |
0 | janet reap | 1,850 | 27th June 2005 - 02:03 PM Last post by: janet reap |
|||
![]() |
4 | vinylman | 1,183 | 4th August 2005 - 05:40 PM Last post by: university_guy |
|||
![]() |
2 | danszczerba | 1,030 | 14th June 2005 - 09:38 PM Last post by: danszczerba |
|||
|
Time is now: 25th May 2013 - 11:04 PM |