Results 1 to 14 of 14

Thread: New Flash     submit to reddit submit to twitter

  1. #1
    Fake Numbers
    Join Date
    Sep 2006
    Posts
    94
    BG Level
    2
    FFXI Server
    Ifrit

    New Flash

    The patch, rated “critical” by Adobe, affects Flash Player 9.0.124.0 on all platforms. Adobe is recommending that users upgrade immediately to Flash Player 10.

    Check your Flash Version Here:
    Version test for Adobe Flash Player

    Adobe updates Flash Player 9 to fix six security holes | Zero Day | ZDNet.com
    Quote Originally Posted by ZDnet.com
    Adobe updates Flash Player 9 to fix six security holes
    Adobe has slapped another band-aid on its ever-present Flash Player to cover at least six documented security vulnerabilities that could expose users to a wide range of hacker attacks.

    The patch, rated “critical” by Adobe, affects Flash Player 9.0.124.0 on all platforms. Adobe is recommending that users upgrade immediately to Flash Player 10.

    The skinny on the latest Flash Player vulnerabilities:


    CVE-2008-4818: This update includes a change to the way Flash Player interprets HTTP response headers to prevent a potential cross-site scripting attack.
    CVE-2008-4819: This update introduces a change to mitigate a potential issue that could aid an attacker in executing a DNS rebinding attack.
    CVE-2008-4823: This update introduces stricter interpretation of an ActionScipt attribute to prevent a potential HTML injection issue.
    CVE-2008-4822: This update prevents an issue with policy file interpretation that could potentially lead to bypass of a non-root domain policy.
    CVE-2008-4821: This update prevents an issue with the Flash Player interpretation of jar: protocol on Mozilla browsers that could potentially lead to information disclosure.
    CVE-2008-4820: This update prevents a potential Windows-only information disclosure issue in the Flash Player ActiveX control.
    Adobe provides this page to held end users determine which version of Flash Player is installed on a system. Keep in mind that any version below Flash Player 9.0.151.0 will be vulnerable to these attack scenarios.

    Separately, Adobe released Security Bulletin ASPB08-21 to resolve a potential privilege escalation issue that is particularly applicable to ColdFusion servers in a shared hosting environment:

    A vulnerability in ColdFusion could allow a lower-privileged user to bypass sandbox security and access sensitive information, and could potentially lead to a privilege escalation attack. This issue is particularly applicable to ColdFusion servers in a shared hosting environment. This issue is not remotely exploitable.
    Affected software versions are ColdFusion 8, ColdFusion 8.0.1 and ColdFusion MX 7.0.2 Solution.

    I urge everyone to update their Flash if you version prior than 10.

    Any site that is running Flash ads could exploit these, and its important to stay up to date on your software. Running Firefox 3 with NoScript add-on is recommended.

    If you previously had one of the latest versions of Flash, its very possible you have already auto-updated. Adobe recently pushed a Flash 10 update.

  2. #2
    Campaign
    Join Date
    Mar 2006
    Posts
    6,192
    BG Level
    8

    There's actually a huge notice at the top of the forum about Flash, it's been there a while too, and it links to the latest version.

  3. #3
    Cerberus
    Join Date
    Sep 2006
    Posts
    412
    BG Level
    4

    Yeah, I thought there was yet another new version out that we really needed to download for a second there.

  4. #4
    Relic Shield
    Join Date
    Nov 2006
    Posts
    1,778
    BG Level
    6

    This new version of flash causes sound delays on my ubuntu 8.10 install. Anyone have the same problem?

  5. #5
    I Am, Who I Am.
    Join Date
    Nov 2005
    Posts
    15,656
    BG Level
    9
    FFXIV Character
    Trixi Sephyuyx
    FFXIV Server
    Excalibur
    FFXI Server
    Ragnarok

    New version of flash also causes some flash not to load, and some websites to crash on exit.

  6. #6
    Ridill
    Join Date
    Aug 2004
    Posts
    12,275
    BG Level
    9
    FFXIV Character
    Septimus Atumre
    FFXIV Server
    Gilgamesh
    FFXI Server
    Bahamut

    Adobe has really dropped the ball frequently with flash since they took over. It is fairly depressing.

  7. #7
    Relic Shield
    Join Date
    Nov 2006
    Posts
    1,778
    BG Level
    6

    So its flash and not my lappy or ubuntu install *wipes away sweat*

  8. #8
    The Mizzle Fizzle of Nikkei's Haremizzle

    Join Date
    Feb 2006
    Posts
    22,049
    BG Level
    10
    FFXI Server
    Bismarck

    Quote Originally Posted by Septimus View Post
    Adobe has really dropped the ball frequently with flash since they took over. It is fairly depressing.
    Yeah they have, they need to get their shit together.

  9. #9
    blax n gunz
    Join Date
    May 2005
    Posts
    11,141
    BG Level
    9

    Quote Originally Posted by Septimus View Post
    Adobe has really dropped the ball frequently with flash since they took over. It is fairly depressing.
    Arguably Flash has been a fucking disaster since its inception and all Adobe is doing is exploiting the inertia of web technologies to fix only those security holes with a modicum of public exposure.

  10. #10
    I Am, Who I Am.
    Join Date
    Nov 2005
    Posts
    15,656
    BG Level
    9
    FFXIV Character
    Trixi Sephyuyx
    FFXIV Server
    Excalibur
    FFXI Server
    Ragnarok

    Im wondering when everyone will switch to MS Silverlight.

  11. #11
    Sandworm Swallows
    Join Date
    Mar 2005
    Posts
    6,989
    BG Level
    8

    MS Silver what now?

  12. #12
    Cerberus
    Join Date
    Sep 2006
    Posts
    412
    BG Level
    4

    I got that to watch the olympics online. It was kind of neat.

  13. #13
    Ridill
    Join Date
    Aug 2004
    Posts
    12,275
    BG Level
    9
    FFXIV Character
    Septimus Atumre
    FFXIV Server
    Gilgamesh
    FFXI Server
    Bahamut

    Quote Originally Posted by Correction View Post
    Arguably Flash has been a fucking disaster since its inception and all Adobe is doing is exploiting the inertia of web technologies to fix only those security holes with a modicum of public exposure.
    There were not nearly as many screw-ups when Macromedia was developing it. Maybe the problems are just more visible now, but they didn't seem to be quite as horrible before Adobe took over.

  14. #14
    Relic Shield
    Join Date
    Nov 2006
    Posts
    1,778
    BG Level
    6

    I still don't have flash installed on my Ubuntu laptop because of some shitty ass sound delay something is causing and I fucking know its not my laptop because previous versions of flash ran perfect on 8.04 and before. I'm quite sick of this bullshit! First I had to manually fix streaming on firefox on ubuntu for flash now I get a fucking sound delay. What the fuck is next hardcoding rm -rf into the .deb package or apt? Fuck you adobe fix this bullshit! Seriously sick of it!

Similar Threads

  1. New Equipment
    By Yummy in forum General Discussion
    Replies: 39
    Last Post: 2004-09-18, 16:08
  2. New Sig!!!
    By Sadler in forum General Discussion
    Replies: 12
    Last Post: 2004-08-18, 23:42