Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - No Geek, no glory.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews



IObit Black Friday Sale

spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Mozilla Firefox
4. Smart Defrag
5. MusicBee
6. Microsoft Visual C++ 2015-2022 Redistributable Package
7. Sergei Strelec's WinPE
8. Visual C++ Redistributable Runtimes AIO Repack
9. Dolby AC-3/AC-4 Installer
10. McAfee Removal Tool (MCPR)
More >>

top reads

Star Lossless vs Lossy: When FLAC, APE, and ALAC Beat MP3 and When They Don't

Star Google Search Tricks You'll Actually Use in 2025 and Beyond

Star Fresh PC Checklist: First 12 Things to Do On a New Windows 11 Machine

Star Running AI Models Locally: What They Are, Where to Find Them, and How to Get Started

Star Deciding Between Idle State, Sleep Mode, and Shutdown: What's Best for Your PC?

Star How to Fix VMware Workstation "The Update Server Could Not Be Resolved" Error Installing VMware Tools

Star How to Remove Google Gemini from Your Phone (and Your Life)

Star Windows Bloat Removal Guide: Debloat Safely and Keep What You Need

Star Windows 11 Repair Playbook: SFC, DISM, CHKDSK Without Breaking Stuff

Star Gmail Using Your Emails and Attachments for AI Training: Here's How To Opt Out


MajorGeeks.Com » News » February 2013 » Emergency Flash update blocks exploit targeted at Firefox

Emergency Flash update blocks exploit targeted at Firefox


Contributed by: Email on 02/27/2013 04:17 PM [ comments Comments ]


Flash patched again.

The last update of Flash Player was just two weeks ago and now it's being updated again – this time to block exploits that target the Firefox browser. The new advisory points to three fixes in the update, two involved in blocking the Firefox exploit and one correcting a generally applicable, serious flaw. The problems affect Flash Player on Windows, Mac OS X and Linux, but do not appear to affect Flash on Android.

One of the corrected problems is a permissions problem with the Flash Player Firefox sandbox (CVE-2013-0643). This vulnerability has been being exploited in the wild with another, now fixed, hole in the ExternalInterface ActionScript feature of Flash, which allowed for the execution of arbitrary code (CVE-2013-0648). As is usual with Flash Player exploits, a victim would have to open a page with malicious SWF content in it to be exposed to attacks; Adobe notes the vulnerabilities are being used in a targeted attack which tries to trick the user into clicking a link that sends the user's browser to such a page. A third buffer overflow vulnerability (CVE-2013-0504), discovered by IBM X-Force in the Flash Player broker service, could also be made to execute malicious code.

On 8 February, Adobe released emergency updates to Flash Player, taking its version number, on Windows and Mac, up to 11.5.502.149. Then further patches were released on 12 February as part of the regularly scheduled Patch Tuesday, bringing the version number up to 11.6.602.168. In the latest update the version number rises to 11.6.602.171 for Windows and Mac OS X versions; the updates can be downloaded from Adobe. Internet Explorer 10 users on Windows 8 should be automatically updated. Google Chrome users on all platforms should also be automatically updated to Chrome version 25.0.1364.97 which includes the fixed Flash. Linux users can download the latest version for Linux, 11.2.202.273.

Windows users who update manually from the Adobe web site should remember to deselect the option to download the additional McAfee Security Scan Plus application.






« Swimmer mauled to death by Great White Shark in front of hundreds of tourists on New Zealand beach as armed police opened fire on the animal at least 20 times · Emergency Flash update blocks exploit targeted at Firefox · Google says it's effectively blocking hackers and spammers »




Comments
comments powered by Disqus

MajorGeeks.Com » News » February 2013 » Emergency Flash update blocks exploit targeted at Firefox

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition