Author Topic: Flexnet Publisher insecure Re: Secunia scan - confused  (Read 2492 times)

0 Members and 1 Guest are viewing this topic.

Offline pastywhitegurl

  • Hero Member
  • *****
  • Posts: 538
  • advanced techno feeb
    • View Profile
Flexnet Publisher insecure Re: Secunia scan - confused
« on: March 29, 2012, 11:59:56 PM »
Secunia flagged this program as insecure:

Flexnet Publisher

Quote
This program was detected as Insecure, it is strongly recommended that you apply the latest security patch from the vendor of the program.

The version detected of FlexNet Publisher 11.x was 11.10.0.2 while the latest version including one or more security fixes is 11.10.1.0.

I did download the solution, but the installer says i already have an instanced in the default folder. ive not encountered this sort of update problem before so i aborted the install so i could ask for help here.

here is the log of what happened that appeared on my desktop
------------------------------------------------------------------------------------------------------
Thu Mar 29 19:37:37 CDT 2012

Free Memory: 2104 kB
Total Memory: 15872 kB

java.class.path:
    C:\Documents and Settings\Helena\Local Settings\Temp\I1333067742\InstallerData\IAClasses.zip
    C:\Documents and Settings\Helena\Local Settings\Temp\I1333067742\InstallerData\Execute.zip
    C:\Documents and Settings\Helena\Local Settings\Temp\I1333067742\Windows\InstallerData\Execute.zip
    C:\Documents and Settings\Helena\Local Settings\Temp\I1333067742\InstallerData\Resource1.zip
    C:\Documents and Settings\Helena\Local Settings\Temp\I1333067742\Windows\InstallerData\Resource1.zip
    C:\Documents and Settings\Helena\Local Settings\Temp\I1333067742\InstallerData
    C:\Documents and Settings\Helena\Local Settings\Temp\I1333067742\Windows\InstallerData

ZGUtil.CLASS_PATH:
    C:\Documents and Settings\Helena\Local Settings\Temp\I1333067742\InstallerData\IAClasses.zip
    C:\Documents and Settings\Helena\Local Settings\Temp\I1333067742\InstallerData\Execute.zip
    C:\Documents and Settings\Helena\Local Settings\Temp\I1333067742\InstallerData

sun.boot.class.path:
    C:\Program Files\Java\jre6\lib\resources.jar
    C:\Program Files\Java\jre6\lib\rt.jar
    C:\Program Files\Java\jre6\lib\sunrsasign.jar
    C:\Program Files\Java\jre6\lib\jsse.jar
    C:\Program Files\Java\jre6\lib\jce.jar
    C:\Program Files\Java\jre6\lib\charsets.jar
    C:\Program Files\Java\jre6\lib\modules\jdk.boot.jar
    C:\Program Files\Java\jre6\classes

java.ext.dirs:
    C:\Program Files\Java\jre6\lib\ext
    C:\WINDOWS\Sun\Java\lib\ext

java.version                  == 1.6.0_31 (Java 1)
java.vm.name                  == Java HotSpot(TM) Client VM
java.vm.vendor                == Sun Microsystems Inc.
java.vm.version               == 20.6-b01
java.vm.specification.name    == Java Virtual Machine Specification
java.vm.specification.vendor  == Sun Microsystems Inc.
java.vm.specification.version == 1.0
java.specification.name       == Java Platform API Specification
java.specification.vendor     == Sun Microsystems Inc.
java.specification.version    == 1.6
java.vendor                   == Sun Microsystems Inc.
java.vendor.url               == http://java.sun.com/
java.class.version            == 50.0
java.compiler                 == null
java.home                     == C:\Program Files\Java\jre6
java.io.tmpdir                == C:\DOCUME~1\Helena\LOCALS~1\Temp\
os.name                       == Windows XP
os.arch                       == x86
os.version                    == 5.1
path.separator                == ;
file.separator                == \
file.encoding                 == Cp1252
user.name                     == Helena
user.home                     == C:\Documents and Settings\Helena
user.dir                      == C:\Documents and Settings\Helena\Local Settings\Temp\I1333067742\Windows
user.language                 == en
user.region                   == null
__________________________________________________________________________

Installed Feature(s) Server of FlexNet Publisher License Server Manager

Install Begin: MARCH 29, 2012 7:35:59 PM CDT
Install End: MARCH 29, 2012 7:37:05 PM CDT

Installed by InstallAnywhere 12.5 Enterprise Build 4181

INSTALLATION WAS CANCELLED BY USER DURING PRE-INSTALLATION

User Interactions
-----------------


#Choose Install Folder
#---------------------
USER_INSTALL_DIR=C:\\Program Files\\FlexNet Publisher License Server Manager

Summary
-------

Installation:  Cancelled during pre-install.

2 Successes
0 Warnings
0 NonFatalErrors
0 FatalErrors

Action Notes:

None

Install Log Detail:

Check Disk Space:         C:\Program Files\FlexNet Publisher License Server Manager
                          Status: SUCCESSFUL
                          Additional Notes: NOTE - Required Disk Space: 28,806,326; Free Disk Space: 249,287,946,240

Custom Action:            com.zerog.ia.customcode.rules.IsAdminAction
                          Status: SUCCESSFUL

INSTALLATION WAS CANCELLED BY USER DURING PRE-INSTALLATION

-----------------------------------------------------------------------------------------
the program wants me to create a new folder....so thats what stopped me


This related thread from the secunia site just royally confused me:
http://secunia.com/community/forum/thread/show/11356/unnable_to_aply_the_patch

so what do i do?

Offline MikeW

  • LzD Friends
  • Full Member
  • *****
  • Posts: 158
    • View Profile
Re: Flexnet Publisher insecure Re: Secunia scan - confused
« Reply #1 on: March 30, 2012, 07:08:03 AM »
From what I can make out it's just the Secunia updater that is causing the problem. Just go direct to the Fexnet publisher site and download your update from there. Hope this helps you
Win 7 Home Premium  IE10 MSE Mbam Pro

Offline pastywhitegurl

  • Hero Member
  • *****
  • Posts: 538
  • advanced techno feeb
    • View Profile
Re: Flexnet Publisher insecure Re: Secunia scan - confused
« Reply #2 on: March 31, 2012, 01:33:15 AM »
Thank you. I'll do just that.  The download I got from Secunia just didn't seem like anything normal.

Offline MikeW

  • LzD Friends
  • Full Member
  • *****
  • Posts: 158
    • View Profile
Re: Flexnet Publisher insecure Re: Secunia scan - confused
« Reply #3 on: March 31, 2012, 07:02:39 AM »
Thank you. I'll do just that.  The download I got from Secunia just didn't seem like anything normal.

Thats probably to do with their new installer see info here

https://www.networkworld.com/news/2012/022812-secunia-we-dont-know-how-256739.html
Win 7 Home Premium  IE10 MSE Mbam Pro

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 12797
  • "Stronger than the past, united in our goal."
    • View Profile
    • Security Garden
Re: Flexnet Publisher insecure Re: Secunia scan - confused
« Reply #4 on: March 31, 2012, 12:59:22 PM »
Because of the change to Secunia PSI, some people have switched to the FileHippo.com Update Checker.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline pastywhitegurl

  • Hero Member
  • *****
  • Posts: 538
  • advanced techno feeb
    • View Profile
Re: Flexnet Publisher insecure Re: Secunia scan - confused
« Reply #5 on: June 23, 2012, 02:44:57 PM »
Update:

I have started using the FileHippo update checker, but I think I might keep Secunia as well just for spotlighting things.  FileHippo only alerts to updates on programs that they have downloads for, but I found they also alert to things Secunia doesn't.  So having both, but using the FH downloads is probably a good way to go.

I'm still struggling with how to update the FlexNet application.  The simplest thing seems to be what is suggested by some users in this Secunia forum thread: http://secunia.com/community/forum/thread/show/11356/unnable_to_aply_the_patch

Which is to run the Adobe License Repair Tool.   There is a differentiation made between the .exe files  for FlexNet service.exe and Flexnet server.exe.  Mine is the server.exe application, which might explain why the update is so complicated and so huge.     

My question now is...is there any reason not to run the Licence Repair Tool?  All my Adobe programs (notably CS3 which I do not want to blow up) are functioning now.  If this program doesn' t need to be run to fix something that doesn't need fixing, will it harm anything to run it?

I've downloaded it, but I'd like some advice before I actually run it.

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 12797
  • "Stronger than the past, united in our goal."
    • View Profile
    • Security Garden
Re: Flexnet Publisher insecure Re: Secunia scan - confused
« Reply #6 on: June 23, 2012, 06:10:53 PM »
Re:  FileHippo vs. Secunia

Secunia only provides information regarding security updates.  It does not include program updates.

Re:  Secunia forum thread

What makes me a bit uncomfortable about the Secunia forum thread is that it is from last year   One thing that Maurice Joyce said in that thread:

Quote
Adobe Premier Elements 8 & 9 certainly work without FlexNet Publisher being installed. Tried & tested.

Reading further, there was apparently a problem with the initial Secunia solution of pointing to the page for vendors using InstallShield.

According to Secunia rep, M.Hansen,

Quote
This Hot Fix must be applied to lmadmin version 11.10. If you are using an older version of lmadmin, you must replace it with version 11.10, and then apply this hotfix.

It also must be Run as Admin.  Some people had success, other didn't.


Do you have the latest version of Flexnet Publisher installed?  Is that the only issue you have?  I note the initial post in this thread points to a user directory in temp: 

user.dir                      == C:\Documents and Settings\Helena\Local Settings\Temp\I1333067742\Windows

It also references an old Java release (although Java has been updated since your initial post).
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline pastywhitegurl

  • Hero Member
  • *****
  • Posts: 538
  • advanced techno feeb
    • View Profile
Re: Flexnet Publisher insecure Re: Secunia scan - confused
« Reply #7 on: June 23, 2012, 07:27:21 PM »
This screenshot is the result of my Secunia scan today:

http://img18.imageshack.us/img18/4549/7b7e9733a911439aac410b8.png

also from the details page of that scan:
"The version detected of FlexNet Publisher 11.x was 11.10.0.2 while the latest version including one or more security fixes is 11.10.1.0."

My Java is now updated.

I guess my other issue is is the lmadmin-i86_n3-11_10_1_0.exe  really supposed to be for updating my client-side licensing program?  It seems that from what I read on the forum thread, that it is for developer applications.  I'm kind of afraid to run it, becuase when I started to install it last time, it was asking me to pick a place to install it since there was something in the default folder already.

Also, I was thinking I should probably uninstall Adobe bridge since it's end of life and I don't have any of the other programs in the creative suite anyway.  Is there any reason to keep it along with my CS3  (which I do not plan to pay to update)

Offline pastywhitegurl

  • Hero Member
  • *****
  • Posts: 538
  • advanced techno feeb
    • View Profile
Re: Flexnet Publisher insecure Re: Secunia scan - confused
« Reply #8 on: June 23, 2012, 09:37:53 PM »
Quote
My Java is now updated.

Ack. I installed the wrong update. I went to the download link at the end of this update notice:
http://www.landzdown.com/general-software-news-updates-discussions/sun-java-runtime-news/msg153907/#msg153907

and didn't notice that it was Java7 instead of Java 6, which is what I had. So i installed jre-7u4-windows i586.exe   

How do I fix this?  I'm assuming I can uninstall it and then add the Java 6 update? but  I can't find a link to download the update for Java 6 Ok, found it.    Why is this updating process so complicated?
 *asks rhetorically while tearing out hair*.

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 12797
  • "Stronger than the past, united in our goal."
    • View Profile
    • Security Garden
Re: Flexnet Publisher insecure Re: Secunia scan - confused
« Reply #9 on: June 23, 2012, 11:41:48 PM »
I don't understand why you don't download the latest update from the website:  FlexNet Publisher

Quote
Welcome to the FlexNet Publisher product download pages. These downloads are available for our FlexNet Publisher customers that have a current maintenance or evaluation agreement. 
Since it appears to require a valid maintenance or evaluation agreement, then support is available at Support for InstallShield, AdminStudio, All Products-Flexera Software.

I wouldn't recommend following 3rd party recommendations for a software program that appears integral to your business.

Re:  Java

I'm not sure why you didn't just update to version 7 of Java.  The "end of life" date for Java SE 6 has been extended from July 2012 to November 2012 so plan on updating to version 7 in the future.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline pastywhitegurl

  • Hero Member
  • *****
  • Posts: 538
  • advanced techno feeb
    • View Profile
Re: Flexnet Publisher insecure Re: Secunia scan - confused
« Reply #10 on: June 23, 2012, 11:59:38 PM »
:O   I don't remember seeing  that page before.  :(   I must seem like an idiot to y'all.

  That certainly looks more like a normal update installer.  But I'm still confused.  Is the Tier 1 the  the right download?

And about Java...I thought Java7 was a beta.  So it is a main version?  If so, then I do want to switch to Java 7.   I installed the Java7 update, and it said..installing Java.  So does that mean by installing it, I also changed to Java7? or do I have to download something else?  Should I uninstall everything, or just use the JavaRa when I'm done?


Offline pastywhitegurl

  • Hero Member
  • *****
  • Posts: 538
  • advanced techno feeb
    • View Profile
Re: Flexnet Publisher insecure Re: Secunia scan - confused
« Reply #11 on: June 24, 2012, 12:05:32 AM »
Apparently Tier 1 is  not the right one..it's asking me for sign-in credentials.   ???

The Java test page says this:
http://img88.imageshack.us/img88/4909/8ebc0a389acf4302bf6a215.png
That means I have Java7 now, correct? and I should run JavaRa?

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 12797
  • "Stronger than the past, united in our goal."
    • View Profile
    • Security Garden
Re: Flexnet Publisher insecure Re: Secunia scan - confused
« Reply #12 on: June 24, 2012, 01:23:35 PM »
Version 7 of Java was released a few updates ago, although, as indicated above, version 6 is still supported.  Check add/remove programs to ensure that version 6 was removed. 

As to Flexnet Publisher, I really don't know what to tell you.  From the pages I read, it is licensed software.  From what I saw in the Secunia thread and I gather from your posts, it is somehow related to the Adobe software you use.  Yet, as I quoted above:

Quote
Adobe Premier Elements 8 & 9 certainly work without FlexNet Publisher being installed. Tried & tested.

Do you use FlexNet Publisher?  Do you have or need a license for it?  Did it come as part of the Adobe software?
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline pastywhitegurl

  • Hero Member
  • *****
  • Posts: 538
  • advanced techno feeb
    • View Profile
Re: Flexnet Publisher insecure Re: Secunia scan - confused
« Reply #13 on: June 24, 2012, 04:58:44 PM »
Thanks, Corrine.  I'll get the rest of the Java mess cleaned up now.  :) I'm glad to be in the current version, even if I got there accidentally.  :tongue:

I have no idea if I use FlexNet Publisher or not.  I'm assuming that it came with the Adobe CS3 suite, but the first I ever heard of it was when it appeared in the Secunia scan.

I suppose that if it is important to CS3 and I delete it, I could re-install CS3 again and get it back.

And with Adobe Bridge, I've used it a couple times, but it takes so many resources that it slows down the PS functions so I stopped using it.

Offline pastywhitegurl

  • Hero Member
  • *****
  • Posts: 538
  • advanced techno feeb
    • View Profile
Re: Flexnet Publisher insecure Re: Secunia scan - confused
« Reply #14 on: June 25, 2012, 01:33:43 AM »
Ran into an issue when I tried to remove Java 6 update from my control programs:

http://z3.ifrm.com/2/81/0/p451700/screenAddRemove.png

How should I get rid of it?

I ran JavaRa and it says it removed the Java 7 - 4  update, but it's still showing in my control panel.
http://z3.ifrm.com/2/81/0/p451701/JavaRaLog.txt

Did I corrupt something?