Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

NEW Adobe Flash Zero-day Vulnerability / Exploit - Uninstall Flash Today From All Computers
(vanity, multiple sources) ^ | Oct 15, 2015 | (vanity, multiple sources)

Posted on 10/15/2015 11:34:56 AM PDT by dayglored

click here to read article


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-64 next last
To: dayglored

ping


41 posted on 10/15/2015 1:33:21 PM PDT by VA Voter
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
New zero-day exploit hits fully patched Adobe Flash [Updated]

This article says:
Note that Adobe released version 19.0.0.209 since.
42 posted on 10/15/2015 2:06:16 PM PDT by TomGuy
[ Post Reply | Private Reply | To 1 | View Replies]

To: TomGuy
> Note that Adobe released version 19.0.0.209 since.

I just now visited Adobe's site: https://get.adobe.com/flashplayer/ with my Windows 7 and Firefox, and they are offering only the vulnerable 19.0.0.207 version.

Pray tell, where did they release .209 to, if not their own website? What OS and browser are you running, to see .209?

43 posted on 10/15/2015 2:27:54 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 42 | View Replies]

To: dayglored

The .209 download is on the Adobe Labs Downloads site.

Arrow down to the Flash Player 19 Beta and select the appropriate version(s).

http://labs.adobe.com/downloads/flashplayer.html


44 posted on 10/15/2015 2:41:25 PM PDT by TomGuy
[ Post Reply | Private Reply | To 43 | View Replies]

To: TomGuy
Re: The Adobe Labs Downloads site. Beta software releases of Flash Player... They say this at the top...
Announcement: We are moving to a rapid beta release cycle using "Background Update". We encourage you to subscribe so you can get the latest and the greatest Flash Player without a single mouse click.
Like I or any other sane user are going to allow Adobe to silently install beta versions of Flash Player into my computer without my approval and explicit authorization each time?

Seriously? I mean no offense to -you- of course, just sayin', Adobe does not have the complete trust of any sane person at present.

In any case, I don't think I can in good conscience tell my fellow FReepers to download quick-turn beta-grade software from Adobe. I'll stick with "uninstall Flash until further notice" and wait for Adobe to make a formal release on their regular page.

Nobody I know needs Flash that bad that they'd run a beta version today.

45 posted on 10/15/2015 2:54:03 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 44 | View Replies]

To: TomGuy
BTW, I do, of course, recognize the need of Flash application developers to have the latest and greatest beta-level pre-release versions of tools. Been there, done that.

And I note Adobe has the usual disclaimer about not using betas on anything that actually matters (production or other mission critical systems). Most folks on FR are using their only computer, so it is sort of their "production" system. Hence my caution.

I also find it slightly annoying that they discontinued Linux work back at version 11.2 since I prefer using Linux for browsing to sites that might contain Windows-specific malware. Oh well.

46 posted on 10/15/2015 3:04:10 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 44 | View Replies]

To: dayglored

To be completely candid, I don’t know if I’d run a Beta version right now from ANYBODY without a ton of crosschecking and consideration.

....and Adobe????

Don’t make me laugh. I’m not real certain that bunch could even spell “security” correctly more than once every six or seven stabs at the deal.


47 posted on 10/15/2015 3:11:40 PM PDT by Unrepentant VN Vet (God gives us rights; Governments take them away....if we let them.)
[ Post Reply | Private Reply | To 45 | View Replies]

To: dayglored

Rapid release has killed a lot of Firefox.

Many developers of extensions/add-ons quit updating because it was too much.

Rapid release must have something to do with job security, because such releases cause more problems than they resolve. Firefox comes out with a new release. Within a week or so, they come out with .1 update. Then, .2 update. Then a new release.


48 posted on 10/15/2015 3:28:01 PM PDT by TomGuy
[ Post Reply | Private Reply | To 45 | View Replies]

To: TomGuy
> Rapid release has killed a lot of Firefox. Many developers of extensions/add-ons quit updating because it was too much.

Yep, and I don't blame them.

> Rapid release must have something to do with job security,...

I'd bet it has to do with the increasing pressure from the malware/exploit community and malicious state-sponsored actors who crave to use vulnerabilities for financial or espionage purposes. This latest Flash vuln has been used for espionage against our own government.

So in that kind of environment, rapid release of patches makes sense -- fix every flaw as it appears because time is of the essence.

But it doesn't IMO require new major version numbering. That's nuts, and my god, Firefox is at version 40-something now? WTF.

I kind of hope that MS Win10's Edge sets a precedent with regard to "No Plugins". It'll kill off a lot of developers, which saddens me, but it'll hopefully improve stability and security enough to compensate for the loss of add-on functionality.

49 posted on 10/15/2015 3:40:57 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 48 | View Replies]

To: dayglored; ~Kim4VRWC's~; 1234; Abundy; Action-America; acoulterfan; AFreeBird; Airwinger; Aliska; ..
SIGH. . . Another day, another FLASH ZERO DAY Exploit! Remove FLASH from all your computers and devices and don't look back. Thanks to dayglored for posting!— PING!


JUST SAY "NO!" TO FLASH
Ping!

The Latest Apple/Mac/iOS Pings can be found by searching Keyword “ApplePingList” on Freerepublic’s Search.

If you want on or off the Mac Ping List, Freepmail me.

50 posted on 10/15/2015 5:18:10 PM PDT by Swordmaker ( This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

I’m using chrome on Linux Mint.

From google’s support page, it instructs you to do this:
Turn specific plugins on and off
You can turn certain plugins on and off at any time.

On your computer, open Chrome.
In the address bar at the top, type chrome://plugins/ and press Enter.
Next to the plugin you’d like to use or turn off, click Enable or Disable.
Note: When you visit a page with a plugin that’s turned off, you’ll see a message that says the plugin has been disabled instead of seeing the video or audio that’s on the page.

Easy as pie, the built in support for flash is disabled.

It remains to be seen how many pages complain about it being disabled.


51 posted on 10/15/2015 6:38:24 PM PDT by Nacho Bidnith (Leftists can see racism everywhere except the mirror)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Thanks- complying immediately!


52 posted on 10/15/2015 7:15:27 PM PDT by matthew fuller (BHO strategy: anti-American, anti-Western, pro-Islamic, pro-Iranian, and pro-Muslim Brotherhood.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
"Microsoft developed SilverLight as a "Flash killer" some years ago; it had about as much success killing Flash as their Zune did at killing the iPod. SL is still available but nothing is written in it and MS is desupporting it. "

So I can uninstall Silverlite also, with no repercussions?

53 posted on 10/15/2015 7:32:12 PM PDT by matthew fuller (BHO strategy: anti-American, anti-Western, pro-Islamic, pro-Iranian, and pro-Muslim Brotherhood.)
[ Post Reply | Private Reply | To 32 | View Replies]

To: matthew fuller
> So I can uninstall Silverlite also, with no repercussions?

Yes. Unless you've got a mission critical application that requires it, you can uninstall it and not look back. According to its Wikipedia page:

Microsoft announced the end of life of Silverlight 5 [the most current version] in 2012. In 2013, Microsoft announced that they had ceased development of Silverlight except for patches and bugfixes. Silverlight is no longer supported in Chrome on OS X, while support for Silverlight in Chrome on all other operating systems was disabled by default in April 2015 and was removed completely in September 2015. Microsoft has set the support end date for Silverlight 5 to be October 2021. In 2015, Microsoft announced that since support for ActiveX was discontinued with Microsoft Edge, Silverlight will not be supported in that browser.
I'd say you're safe. Not only has there been no reason for developers to write for it for many years, the fact that Windows 10 Edge does not support it is the death knell.
54 posted on 10/15/2015 7:40:40 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 53 | View Replies]

To: dayglored
Yuk!! I haven't had flash on my systems for years, and just today, paid to take an online "defensive driving" course that our auto insurer said will significantly reduce our premiums. But, after signing up (paying) for the course, I found that it requires Flash to run the chintzy Flash CG movies that constitute much of the content.

So, I downloaded Flash and am halfway thru the course. Guess I'll hurry up and finish (and surf nowhere else but FR). Then I'll decide if it is worth the risk of having the wife take the same course --before I again purge FlashCrap from my system... :-(

55 posted on 10/15/2015 7:42:58 PM PDT by TXnMA ("Allah": Satan's current alias... "Barack": Allah's current ally...)
[ Post Reply | Private Reply | To 2 | View Replies]

To: dayglored

Thanks, it will be uninstalled ASAP.


56 posted on 10/15/2015 7:45:13 PM PDT by matthew fuller (BHO strategy: anti-American, anti-Western, pro-Islamic, pro-Iranian, and pro-Muslim Brotherhood.)
[ Post Reply | Private Reply | To 54 | View Replies]

To: HiTech RedNeck; dayglored
Here you go!

http://arstechnica.com/security/2015/10/new-zero-day-exploit-hits-fully-patched-adobe-flash/

57 posted on 10/15/2015 7:49:11 PM PDT by Chgogal (Obama "hung the SEALs out to dry, basically exposed them like a set of dog balls..." CMH)
[ Post Reply | Private Reply | To 27 | View Replies]

To: dayglored
Jacqie Lawson cards requires Flash.

Dang it!

58 posted on 10/15/2015 7:50:57 PM PDT by Chgogal (Obama "hung the SEALs out to dry, basically exposed them like a set of dog balls..." CMH)
[ Post Reply | Private Reply | To 54 | View Replies]

To: dayglored

Adobe Security Bulletin
Security Advisory for Adobe Flash Player

Release date: October 14, 2015

Last updated: October 15, 2015

Vulnerability identifier: APSA15-05

CVE number: CVE-2015-7645

Platforms: Windows, Macintosh and Linux
Summary

A critical vulnerability (CVE-2015-7645) has been identified in Adobe Flash Player 19.0.0.207 and earlier versions for Windows, Macintosh and Linux. Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system.

Adobe is aware of a report that an exploit for this vulnerability is being used in limited, targeted attacks.

UPDATE: Adobe expects updates to be available as early as October 16.
Affected software versions

Adobe Flash Player 19.0.0.207 and earlier versions for Windows and Macintosh
Adobe Flash Player Extended Support Release version 18.0.0.252 and earlier 18.x versions
Adobe Flash Player 11.2.202.535 and earlier 11.x versions for Linux

To verify the version of Adobe Flash Player installed on your system, access the About Flash Player page, or right-click on content running in Flash Player and select “About Adobe (or Macromedia) Flash Player” from the menu. If you use multiple browsers, perform the check for each browser you have installed on your system.
Severity ratings

Adobe categorizes this as a critical vulnerability.


59 posted on 10/15/2015 7:53:51 PM PDT by JoeProBono (SOME IMAGES MAY BE DISTURBING VIEWER DISCRETION IS ADVISED;-{)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Chgogal
> Jacqie Lawson cards requires Flash. Dang it!

Oh dear. Yeah, E-card animations and games are the last holdouts of Flash, other than obnoxious ads.

Well, perhaps you can convince yourself away from the cards with this charming (not!) Facebook page:

https://www.facebook.com/IHateJacquieLawson
(Slight rude language caution)
60 posted on 10/15/2015 8:34:09 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 58 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-64 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson