General :  K-Meleon Web Browser Forum
General discussion about K-Meleon 
Zero day exploit now in Flash too
Posted by: Fred
Date: September 14, 2010 05:02PM

After the vulnerability in Adobe Reader and Acrobat,
now also Flash for Windows, Linux, Mac and for the
first time also Google's Android are vulnerable to
an extremely critical zero day exploit, which for Windows
is already in the wild.

http://www.h-online.com/open/news/item/Attackers-exploit-additional-zero-day-vulnerability-in-Adobe-Flash-and-Reader-1078297.html

http://secunia.com/advisories/41434

As it is not yet known, if turning off Javascript
would stop an attack, it seems to be advisable
to rename the Flash plugin temporarily, in order
to stop it from working, until the bug will be fixed
on September 27th, as it has been announced.

Fred

Options: ReplyQuote
Re: Zero day exploit now in Flash too
Posted by: Matt
Date: September 18, 2010 04:59PM

Updated Flash Player version for Windows, Mac OS, Linux, Solaris and Android should be released on Monady, September 20.

http://www.heise.de/security/meldung/Adobe-zieht-Flash-Update-vor-1081650.html

Options: ReplyQuote
Re: Zero day exploit now in Flash too
Posted by: 4td8s
Date: September 20, 2010 07:36PM

New Flash Players to resolve zero day security flaw released today Sept. 20:
http://www.adobe.com/support/security/bulletins/apsb10-22.html

Options: ReplyQuote
Re: Zero day exploit now in Flash too
Posted by: 4td8s
Date: September 20, 2010 07:39PM

Quote
Matt
Updated Flash Player version for Windows, Mac OS, Linux, Solaris and Android should be released on Monady, September 20.

http://www.heise.de/security/meldung/Adobe-zieht-Flash-Update-vor-1081650.html

yup, with the exception of Google Chrome, which they released Chrome v6.0.472.62 last Friday to include embedded Flash Player 10.1.85.3.

Google was a few days ahead of schedule than Adobe.

Options: ReplyQuote
Re: Zero day exploit now in Flash too
Posted by: ndebord
Date: September 21, 2010 01:58PM

4td8s,

That was quick... already a new update, just a day later. Version 10.1.85.3.

N

Options: ReplyQuote
Re: Zero day exploit now in Flash too
Posted by: Matt
Date: September 21, 2010 04:23PM

For those who prefer NOT to install Flash Player here is standalone NPSWF32.dll v10.1.85.3. Unzip the archive to /plugins in your K-Meleon root folder.

http://www.adobe.com/software/flash/about/ Flash Player version check

Options: ReplyQuote
Re: Zero day exploit now in Flash too
Posted by: disrupted
Date: September 22, 2010 01:12PM

thanks matt, hexed version is now available on kmext and updated flash switcher

Options: ReplyQuote
Re: Zero day exploit now in Flash too
Posted by: JohnHell
Date: September 22, 2010 08:50PM

Thanks for your work again smiling smiley

Options: ReplyQuote


K-Meleon forum is powered by Phorum.