INTERACT FORUM

More => Old Versions => Media Center 12 (Development Ended) => Topic started by: JimH on June 03, 2008, 06:41:59 am

Title: XP Service Pack 3 has old, vulnerable Flash Player
Post by: JimH on June 03, 2008, 06:41:59 am
From Computerworld:

Quote
Microsoft Corp.'s Windows XP Service Pack 3 (SP3) ships with an out-of-date version of Adobe's Flash Player that's vulnerable to recently-spotted attacks, according to Microsoft's support documentation.

Windows XP SP3 includes Flash Player 9.0.115.0, a version released by Adobe Systems Inc. in December 2007. That version of Flash Player, however, was superseded by version 9.0.124.0 on April 8, nearly two weeks before Microsoft decided SP3 was done by giving it a Release To Manufacturing (RTM) label and sending it out for distribution.

The older version that shipped with XP SP3, however, harbors a bug that hackers have been exploiting since last week; that's when security researchers, including those at Symantec Corp., reported what they at first thought was a zero-day vulnerability in the most current edition of Flash, 9.0.124.0. A few days later, however, Symantec retracted that claim, and said that only the older 9.0.115.0 was at risk.
Full article:
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9092218&intsrc=news_ts_head
Title: Re: XP Service Pack 3 has old, vulnerable Flash Player
Post by: Mastiff on June 03, 2008, 09:39:27 am
Could this be a good enough reason to nuke Flash out of existence on the Net? ;) Seriously, it's the most annoying thing there is! Every time my browser locks up it's because of a Flash ad!
Title: Re: XP Service Pack 3 has old, vulnerable Flash Player
Post by: rjm on June 03, 2008, 12:06:23 pm
Last week's Security Now podcast reported first hand experience with a serious SP3 problem (start menu lockup). I am waiting for a service pack for the service pack.
Title: Re: XP Service Pack 3 has old, vulnerable Flash Player
Post by: Eccles on June 03, 2008, 06:24:45 pm
Could this be a good enough reason to nuke Flash out of existence on the Net? ;) Seriously, it's the most annoying thing there is! Every time my browser locks up it's because of a Flash ad!
I recently found the best flash site I've ever seen: zombo.com (http://www.zombo.com/)  More useful than 99.9% of the flash sites out there.
Title: Re: XP Service Pack 3 has old, vulnerable Flash Player
Post by: KingSparta on June 03, 2008, 06:38:49 pm
Funny...
Title: Re: XP Service Pack 3 has old, vulnerable Flash Player
Post by: Frobozz on June 04, 2008, 06:54:38 am
A true zero-day exploit involving Flash would be a disaster.  It could spread rapidly to many many web sites through SQL injection and other attacks.  The only defense would be to disable Flash till there was a fix from Adobe (or surf the web and YouTube inside a virtual machine running Linux).

But even with the current attacks being against the old version of Flash, it may as well be a zero-day (http://blogs.zdnet.com/security/?p=1236) because very few people are actually updated to the current version of Flash.

There is no good update mechanism for Flash in the Windows world.  The only hope for a widespread update of Flash would be for Microsoft to include it in the Windows Update.

The best way to make sure you have Flash up to date (and several other programs) is to run the Secunia Online Scan (http://secunia.com/software_inspector/) or the Secunia Personal Software Inspector (https://psi.secunia.com/).  Or the FileHippo Update Checker (http://www.filehippo.com/updatechecker/), but it's not as comprehensive and isn't aimed at security vulnerable updates.