LandzDown Forum

Security => Security Alerts & Briefings => Topic started by: siljaline on December 08, 2015, 05:48:12 PM

Title: Adobe Flash Player and AIR December 2015 Critical Security Updates
Post by: siljaline on December 08, 2015, 05:48:12 PM
Adobe Flash Player 20.0.0.235 is now up. I'm assuming Corinne's links still work - if not these should be fine - note there is no changelog at the time of this writing.  http://www.neowin.net/news/adobe-flash-player-2000235 
Title: Re: Adobe Flash Player and AIR December 2015 Critical Security Updates
Post by: Corrine on December 08, 2015, 06:26:24 PM
Split to new topic to avoid confusion.  The download links have changed with the version update and only Flash Player and AIR were updated, not Reader.

Adobe has released Version two versions of Adobe Flash Player for Microsoft Windows and Macintosh, Version 20.0.0.228 for IE and Version 20.0.0.235 for plug-in based browsers.  The Extended Release Version was incremented to Version 18.0.0.268 with this update.  For those who use Adobe AIR, it has been updated to version  20.0.0.204.  The update is available here: https://get.adobe.com/air/

As illustrated in the incredibly long list of CVE's in the Security Bulletin, many vulnerabilities exist in unpatched versions of Flash Player.  It is recommended that date be installed as soon as possible.

    Non-IE Plugin (Opera, Firefox, Etc.):  http://download.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_20_plugin.exe
    Flash Player For Internet Explorer, Windows 7 and earlier:  http://download.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_20_active_x.exe

    Internet Explorer, Windows 8 and above: Microsoft updated Security Advisory 2755801.  If you do not have Automatic Updates enabled, the Flash Player update can be downloaded from Microsoft Security Advisory: Update for Vulnerabilities in Adobe Flash Player in Internet Explorer 10: July 9, 2013.

    Flash Player Uninstaller:  http://download.macromedia.com/get/flashplayer/current/support/uninstall_flash_player.exe
    Adobe AIR:  http://get.adobe.com/air/

Release Notes:  Flash Player® 20 AIR® 20 (https://helpx.adobe.com/flash-player/release-note/fp_20_air_20_release_notes.html)
Security Bulletin (https://helpx.adobe.com/flash-player/release-note/fp_20_air_20_release_notes.html)
Title: Re: Adobe Flash Player and AIR December 2015 Critical Security Updates
Post by: ky331 on December 28, 2015, 09:14:11 PM
Adobe Flash  has been updated to 20.0.0.267

In today's release, we've updated Flash Player and AIR with important bug fixes and security updates.

These updates address critical vulnerabilities that could potentially allow an attacker to take control of the affected system. 

------

Adobe AIR has been updated to   20.0.0.233
Title: Re: Adobe Flash Player and AIR December 2015 Critical Security Updates
Post by: ky331 on January 02, 2016, 11:10:23 AM
Adobe Flash --- ActiveX version for IE on Win 7 & earlier --- has been updated to 20.0.0.270

In today's release, we've updated Flash Player ActiveX for Windows XP, Windows Vista and Windows 7.  This release addresses a problem with Flash Player improperly loading in applicaitons that have it embedded. 

We are working with Microsoft to provide this update to Windows 8 and Windows 10 users as soon as possible.



https://helpx.adobe.com/flash-player/release-note/fp_20_air_20_release_notes.html

Remark:   The Plug-In version for other browsers remains at build 20.0.0.267.
Title: Re: Adobe Flash Player and AIR December 2015 Critical Security Updates
Post by: ky331 on January 06, 2016, 11:35:28 AM
Microsoft has announced that (the embedded) Flash for IE11/ActiveX & Edge on Win10 was finally updated to 20.0.0.272


https://technet.microsoft.com/library/security/2755801

https://support.microsoft.com/en-us/kb/3133431

Remark:   Based on the change in wording in the above document... as well as "confirmed" on my Win8.1 tablet... there has NOT (yet?) been a corresponding update for Win8.x.
(I do not currently have access to any Win10 system to check there.)
Title: Re: Adobe Flash Player and AIR December 2015 Critical Security Updates
Post by: plodr on January 06, 2016, 03:38:07 PM
If I understand this correctly:
plugins for browsers other than IE the current version is 20.0.0.267
IE activex for Win 7 and below the current version is 20.0.0.270
IE activex for Win 8 and above will be getting 20.0.0.272 directly from MS through the updates.
Title: Re: Adobe Flash Player and AIR December 2015 Critical Security Updates
Post by: ky331 on January 06, 2016, 03:43:32 PM
plugins for browsers other than IE the current version is 20.0.0.267
IE activex for Win 7 and below the current version is 20.0.0.270
IE 11 activex for Win 10 will be getting 20.0.0.272 directly from MS through the updates.

Not sure yet what exactly they're doing with IE 10/11 Win8.x...
Title: Re: Adobe Flash Player and AIR December 2015 Critical Security Updates
Post by: ky331 on January 12, 2016, 10:25:04 PM
(the embedded) Flash for IE11/ActiveX on Win 8.1 was finally updated to 20.0.0.272 today (1/12/16) [through Microsoft Updates]
Title: OT: Adobe Flash Player ESR
Post by: satrow on January 13, 2016, 01:36:31 PM
It looks like there might be an extension until June for public access to Flash ESR, not sure if the 'new' page will continue to be updated until then though:

Quote
https://www.adobe.com/products/flashplayer/distribution3.html will be decommissioned on March 1st, 2016.

https://www.adobe.com/products/flashplayer/distribution4.html will be decommissioned on June 15th, 2016.

Both of the pages will still be available after the decommissioning date, but will not contain any links to Flash Player downloads.  The pages will have detailed instructions on how to reach the new download page.
Title: Re: Adobe Flash Player and AIR December 2015 Critical Security Updates
Post by: Corrine on January 19, 2016, 06:47:48 PM
Adobe has released Version 20.0.0.286 of Adobe Flash Player for Microsoft Windows and Macintosh.  The update is to to address important functional issues impacting Flash Player users.

Google Chrome and Windows 8.x/10 Internet Explorer and Microsoft Edge will receive the update through the Google and Microsoft update mechanisms.  Direct down-load links for the plugin version and Windows 7 and below:

Non-IE Plugin (Opera, Firefox, Etc.):  http://download.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_20_plugin.exe
Flash Player For Internet Explorer, Windows 7 and earlier:  http://download.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_20_active_x.exe
Title: Re: Adobe Flash Player and AIR December 2015 Critical Security Updates
Post by: plodr on January 20, 2016, 01:47:28 AM
Thanks. Figures, I just imaged four computers!