This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Flash Player update released

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.techweb.com/article/printableAr…_section=700027
June 28, 2006
"Adobe on Wednesday released Flash Player 9, an update to its popular Web media player that boasts a 10x performance boost. The new player gets its new-found speed by using ActionScript 3.0 – an object-oriented language that's ECMAScript-compliant – and a new ActionScript Virtual Machine (AVM) which features a Just In Time (JIT) compiler. That compiler "translates ActionScript code to native machine code for maximum execution speed" Adobe said in a statement…"

:huh:
FYI…

- http://secunia.com/advisories/20971/
Release Date: 2006-07-10
Critical: Highly critical
Impact: DoS, System access
Where: From remote
Solution Status: Vendor Patch
Software: Macromedia Flash Player 8.x
…The vulnerability has been reported in version 8.0.24. Prior versions may also be affected.
Solution:
Upgrade to version 9.0* …"
* http://www.adobe.com/shockwave/download/do…=ShockwaveFlash

Test version installed:
- http://www.macromedia.com/software/flash/about/

Get Flash Player 9
> http://www.adobe.com/products/flashplayer/

:ph34r:
FYI…

Flash v9.0.28.0 released
Download:
- http://www.adobe.com/shockwave/download/do…=ShockwaveFlash
Version: 9,0,28,0
Browser: Firefox, Mozilla, Netscape, Opera, and Internet Explorer
Date Posted: 11/14/2006

Security bulletins and advisories
- http://www.adobe.com/support/security/

Test version installed:
- http://www.macromedia.com/software/flash/about/

EDIT/ADD:
- http://isc.sans.org/diary.php?compare=1&storyid=1859
Last Updated: 2006-11-14 23:58:33 UTC
"…Affected versions include 9.x, 8.x and 7.x . If after reading the adobe announcement you are left wondering what modified HTTP headers of client requests can do to cause HTTP Request Splitting attacks, or what those are to start with, take a look at e.g.: http://en.wikipedia.org/wiki/HTTP_Response_splitting …"
FYI…

Flash v9.0.45.0 released
- http://www.adobe.com/shockwave/download/do…=ShockwaveFlash
Version: 9,0,45,0
Browser: Firefox, Mozilla, Netscape, and Opera
Date Posted: 4/12/2007 …

For IE - you may want to start here:
- http://www.adobe.com/products/flashplayer/
(Uncheck the "Google Toolbar" unless you want the "piggyback" install…)

Post install test here:
- http://www.adobe.com/shockwave/welcome/
-or-
- http://www.macromedia.com/software/flash/about/

.
FYI…

Flash player vuln - update available
- http://www.adobe.com/support/security/bull…/apsb07-12.html
Release date: July 10, 2007
"…Summary:
Critical vulnerabilities have been identified in Adobe Flash Player that could allow an attacker who successfully exploits these potential vulnerabilities to take control of the affected system. A malicious SWF must be loaded in Flash Player by the user for an attacker to exploit these potential vulnerabilities. Users are recommended to update to the most current version of Flash Player available for their platform.

Affected software versions:
Adobe Flash Player 9.0.45.0 and earlier, 8.0.34.0 and earlier, and 7.0.69.0 and earlier…

Download
- http://www.adobe.com/shockwave/download/do…=ShockwaveFlash
Version: 9,0,47,0
Browser: Firefox, Mozilla, Netscape, and Opera
Date Posted: 7/10/2007

For IE - you may want to start here:
- http://www.adobe.com/products/flashplayer/
(Uncheck the "Google Toolbar" unless you want the "piggyback" install…)

Post install test here:
- http://www.adobe.com/shockwave/welcome/
-or-
- http://www.macromedia.com/software/flash/about/

> http://secunia.com/advisories/26027/
Release Date: 2007-07-11
Critical: Highly critical

> http://www.us-cert.gov/current/#adobe_flas…_arbitrary_code

.
FYI…

Flash Player v9,0,115,0 released
- http://www.adobe.com/shockwave/download/do…=ShockwaveFlash
File size: 1,457 K
Version: 9,0,115,0
Browser: Firefox, Mozilla, Netscape, and Opera
Date Posted: 12/3/2007 -?-
Language: English

Version test for Adobe Flash Player
- http://www.adobe.com/products/flash/about/

Settings Manager
- http://www.macromedia.com/support/document…gs_manager.html

Flash Player Support
- http://www.adobe.com/support/flashplayer/
—————————

> http://www.adobe.com/support/security/bull…/apsb07-20.html
December 18, 2007 - "Summary: Critical vulnerabilities have been identified in Adobe Flash Player that could allow an attacker who successfully exploits these potential vulnerabilities to take control of the affected system. A malicious SWF must be loaded in Flash Player by the user for an attacker to exploit these potential vulnerabilities. Users are recommended to update to the most current version of Flash Player available for their platform.
Affected software versions: Adobe Flash Player 9.0.48.0 and earlier, [removed] and earlier, and [removed] and earlier…
Solution: Adobe recommends all users of Adobe Flash Player 9.0.48.0 and earlier versions upgrade to the newest version 9.0.115.0…"

:huh:
FYI…

Flash Player version 9.0.124.0 released
- http://www.adobe.com/shockwave/download/do…=ShockwaveFlash

APSB08-11 Flash Player update available to address security vulnerabilities
- http://www.adobe.com/support/security/bull…/apsb08-11.html
04/08/2008 - "Critical vulnerabilities have been identified in Adobe Flash Player that could allow an attacker who successfully exploits these potential vulnerabilities to take control of the affected system. A malicious SWF must be loaded in Flash Player by the user for an attacker to exploit these potential vulnerabilities. It is recommended users update to the most current version of Flash Player available for their operating system…
Affected software versions:
Adobe Flash Player [removed] and earlier, and [removed] and earlier…"
Severity rating:
Adobe categorizes this as a -critical- update and recommends affected users upgrade to version 9.0.124.0…"

- http://secunia.com/advisories/28083/
Release Date: 2008-04-09
Critical: Highly critical
Impact: Security Bypass, Cross Site Scripting, System access
Where: From remote
Solution Status: Vendor Patch
Software: Adobe Flash Player 9.x …
…The vulnerabilities are reported in versions prior to 9.0.124.0…

CVE reference:
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-0071
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5275

http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6019
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6243
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6637

http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1654
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1655 …

:ph34r: