INTERACT FORUM

Please login or register.

Login with username, password and session length
Advanced search  
Pages: [1]   Go Down

Author Topic: XP Service Pack 3 has old, vulnerable Flash Player  (Read 1648 times)

JimH

  • Administrator
  • Citizen of the Universe
  • *****
  • Posts: 71529
  • Where did I put my teeth?
XP Service Pack 3 has old, vulnerable Flash Player
« on: June 03, 2008, 06:41:59 am »

From Computerworld:

Quote
Microsoft Corp.'s Windows XP Service Pack 3 (SP3) ships with an out-of-date version of Adobe's Flash Player that's vulnerable to recently-spotted attacks, according to Microsoft's support documentation.

Windows XP SP3 includes Flash Player 9.0.115.0, a version released by Adobe Systems Inc. in December 2007. That version of Flash Player, however, was superseded by version 9.0.124.0 on April 8, nearly two weeks before Microsoft decided SP3 was done by giving it a Release To Manufacturing (RTM) label and sending it out for distribution.

The older version that shipped with XP SP3, however, harbors a bug that hackers have been exploiting since last week; that's when security researchers, including those at Symantec Corp., reported what they at first thought was a zero-day vulnerability in the most current edition of Flash, 9.0.124.0. A few days later, however, Symantec retracted that claim, and said that only the older 9.0.115.0 was at risk.
Full article:
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9092218&intsrc=news_ts_head
Logged

Mastiff

  • MC Beta Team
  • Citizen of the Universe
  • *****
  • Posts: 1977
  • The Multi-Zone Tzar
Re: XP Service Pack 3 has old, vulnerable Flash Player
« Reply #1 on: June 03, 2008, 09:39:27 am »

Could this be a good enough reason to nuke Flash out of existence on the Net? ;) Seriously, it's the most annoying thing there is! Every time my browser locks up it's because of a Flash ad!
Logged
Tor with the Cinema Inferno & Multi-Zone Audio system

rjm

  • Regular Member
  • Citizen of the Universe
  • *****
  • Posts: 2699
Re: XP Service Pack 3 has old, vulnerable Flash Player
« Reply #2 on: June 03, 2008, 12:06:23 pm »

Last week's Security Now podcast reported first hand experience with a serious SP3 problem (start menu lockup). I am waiting for a service pack for the service pack.
Logged

Eccles

  • Regular Member
  • Junior Woodchuck
  • **
  • Posts: 99
  • Mostly harmless.
Re: XP Service Pack 3 has old, vulnerable Flash Player
« Reply #3 on: June 03, 2008, 06:24:45 pm »

Could this be a good enough reason to nuke Flash out of existence on the Net? ;) Seriously, it's the most annoying thing there is! Every time my browser locks up it's because of a Flash ad!
I recently found the best flash site I've ever seen: zombo.com  More useful than 99.9% of the flash sites out there.
Logged

KingSparta

  • MC Beta Team
  • Citizen of the Universe
  • *****
  • Posts: 20049
Re: XP Service Pack 3 has old, vulnerable Flash Player
« Reply #4 on: June 03, 2008, 06:38:49 pm »

Funny...
Logged
Retired Military, Airborne, Air Assault, And Flight Wings.
Model Trains, Internet, Ham Radio
https://MyAAGrapevines.com
https://centercitybbs.com
Fayetteville, NC, USA

Frobozz

  • Citizen of the Universe
  • *****
  • Posts: 637
  • There is a small mailbox here.
Re: XP Service Pack 3 has old, vulnerable Flash Player
« Reply #5 on: June 04, 2008, 06:54:38 am »

A true zero-day exploit involving Flash would be a disaster.  It could spread rapidly to many many web sites through SQL injection and other attacks.  The only defense would be to disable Flash till there was a fix from Adobe (or surf the web and YouTube inside a virtual machine running Linux).

But even with the current attacks being against the old version of Flash, it may as well be a zero-day because very few people are actually updated to the current version of Flash.

There is no good update mechanism for Flash in the Windows world.  The only hope for a widespread update of Flash would be for Microsoft to include it in the Windows Update.

The best way to make sure you have Flash up to date (and several other programs) is to run the Secunia Online Scan or the Secunia Personal Software Inspector.  Or the FileHippo Update Checker, but it's not as comprehensive and isn't aimed at security vulnerable updates.
Logged
Pages: [1]   Go Up