Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: Adobe Flash Player Security Update - Internet Security | DShield SANS ISC InfoSec Forums


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Adobe Flash Player Security Update

Adobe today released bulletin with details regarding two new vulnerabilities in Adobe Flash Player [1]. The vulnerabilities can lead to arbitrary code execution and affects all platforms (don't forget Android and Google Chrome patches!).

There is no indication at this point that the vulnerability has been exploited yet. However, I believe this is an unannounced out-of cycle release. 

Also note that twitter is littered with links to various "adobe updates" with suspect destinations. Only download adobe updates using Adobe's own update tools or use the Adobe site itself.

Thanks all the readers who alerted us about this issue. It took a little bit long to publish this diary in part as I first needed to verify that the update is valid. The security bulletin below isn't link yet from Adobes bulletin overview page.

http://www.adobe.com/support/security/bulletins/apsb12-05.html

------
Johannes B. Ullrich, Ph.D.
SANS Technology Institute
Twitter

I will be teaching next: Defending Web Applications Security Essentials - SANS Munich July 2019

Johannes

3555 Posts
ISC Handler
Note that at least some of the redistribution packages for corporate deployment have yet to be updated and still reflect the 11.1.102.62 content released on Feb 15th, so be sure to double check the version numbers on files you download! 20 days between updates! Woohoo!
Anonymous
If you download the msi installers for distributing flash within your organization, be sure to check the version within the msi file using Orca or a similar tool. As of 3/5/2012 4:00 EST, the download page lists the new version (11.1.102.63), but the files themselves are still the old version (11.1.102.62). Unfortunately, Adobe doesn't include the version in the filename so this is not as obvious as it probably should be.
James

12 Posts
... and still the distribution downloads are the .62 version at 6th March 10:50 GMT. Hopefully someone will wake up soon and realise what they've (not) done?
Anonymous
You can currently get the .63 version on their archived version download page. http://kb2.adobe.com/cps/142/tn_14266.html

The single file for Flash Player 11.1.102.63 (174 MB) contains the released and debug versions for both 32 and 64 bit.

James

12 Posts
Apparently, they have now updated the normal distribution site to the latest versions:
- https://www.adobe.com/products/flashplayer/distribution3.html
.
Jack

160 Posts

Sign Up for Free or Log In to start participating in the conversation!