Update: Adobe has released an update to counter the zero-day exploit

Ketchup

Elite Member
Sep 1, 2002
14,546
238
106
Last edited:

Chiefcrowe

Diamond Member
Sep 15, 2008
5,049
182
116
Just checked my plugins via FF and it reported that it is "vulnerable
16.0.0.296" when that is the latest version out right now, so I am not sure why that is.
 

Ketchup

Elite Member
Sep 1, 2002
14,546
238
106
image isn't showing up.

I am not sure why it isn't showing up for you. I just tried it on two different computers with two different browsers (which aren't signed into the forums) and it comes up just fine.

Anyone else having issues?
 

Red Squirrel

No Lifer
May 24, 2003
67,905
12,375
126
www.anyf.ca
Been getting this for a while in Linux, and if I try to update it, it just points me to Flash's site, and it fails if I try to do it there. Have not bothered yet to try to do it manually. The current one I have is installed via package manager so I hate to try to do things manually and possibly end up with two versions or some kind of conflict.

In Mint 17.1 it's "vulnerable" out of the box and the popup is very annoying. I don't see what the point of this warning is, flash is ALWAYS vulnerable, but unfortunately lot of sites still use it so you still need it to work.
 

ninaholic37

Golden Member
Apr 13, 2012
1,883
31
91
This was happening to me about two days ago in Linux. I had 11.2.202.425 so I upgraded to 11.2.202.440 and that got rid of the annoying warnings.
 

lxskllr

No Lifer
Nov 30, 2004
57,659
7,893
126
I am not sure why it isn't showing up for you. I just tried it on two different computers with two different browsers (which aren't signed into the forums) and it comes up just fine.

Anyone else having issues?

Not showing up for me. PrivacyBadger is marking s22.postimg.org as a tracker, and blocking it.

My version in Debian is marked vulnerable, but I'm not especially concerned. I keep it blocked 99.9% of the time, and am || close to just uninstalling it.

 

ninaholic37

Golden Member
Apr 13, 2012
1,883
31
91
I don't see what the point of this warning is, flash is ALWAYS vulnerable, but unfortunately lot of sites still use it so you still need it to work.
I agree. I only turned it on because I wanted to play Guitar Flash on Facebook. I wonder if downgrading to version 10 or 9 will stop the warnings. :hmm:
 

Ketchup

Elite Member
Sep 1, 2002
14,546
238
106
Thanks lxskllr. The image is from postimage.org. Ghostery blocked the first image, but didn't block the it once I brought up the full image.
 

ninaholic37

Golden Member
Apr 13, 2012
1,883
31
91
I wonder if downgrading to version 10 or 9 will stop the warnings. :hmm:
Success! I removed 11.2.202.440 and installed 10.3.183.90 (June 11, 2013) and it gives no warnings! If the v10 series lasted over 1.5 years without warnings and still works for everything you want to do, perhaps it's better to stick to that version.
 

ninaholic37

Golden Member
Apr 13, 2012
1,883
31
91
Interestingly, 11.2.202.228 (April 5, 2012) doesn't give me a warning either, but I heard that 11.2.202.335 will (January 14, 2014), so it seems that the v11 series (and all the others above it) was only contaminated with this "need to upgrade to work" bug some time after June 2013 and before 2014, as far as I can tell...
 

Ketchup

Elite Member
Sep 1, 2002
14,546
238
106
It is odd. I cannot Google anything from Mozilla about this version being vulnerable. Maybe it's just a bug.
 

John Connor

Lifer
Nov 30, 2012
22,840
617
121
I'm surprised no one mentions why VLC is always showing vulnerable. It seems Mozilla and VLC point fingers at each other on why the version is showing vulnerable.

I'm referring to the web-based plugin.
 

corkyg

Elite Member | Peripherals
Super Moderator
Mar 4, 2000
27,370
239
106
A few days ago, I got an email from Malwarebytes that may shed some light on the specific FLASH problem.

"Recently Kafeine, a keen malware hunter and friend of Malwarebytes, discovered a new (zero-day) exploit that attacks Adobe Flash Player. Distributed through the Angler Exploit Kit, the zero-day delivers malware that takes control of your computer to commit click fraud."
 

ninaholic37

Golden Member
Apr 13, 2012
1,883
31
91
I'm surprised no one mentions why VLC is always showing vulnerable. It seems Mozilla and VLC point fingers at each other on why the version is showing vulnerable.

I'm referring to the web-based plugin.
What does the VLC web plugin actually do? I thought it was to play Youtube videos but that doesn't seem to work, Youtube ignores it and always goes to Flash or HTML5.
 

mikeymikec

Lifer
May 19, 2011
18,042
10,224
136
I'm running the latest version of FF and Flash, no warnings here (Win7 64).

I've never bothered to install the VLC web plug-in; I generally regard plug-ins to be a great way to introduce extra vulnerabilities to one's set-up. I'll tolerate Flash because it's pretty much a requirement for a lot of sites to work, but I have it set to 'ask to activate' in FF.

My wife had the "Flash vulnerable" message earlier today on YT. It was really odd as her version of FF was so out of date that it had to update twice. It still complained after updating FF (which didn't surprise me at the time). I didn't bother to check the Flash version before she updated it immediately afterwards. No more warning.
 

John Connor

Lifer
Nov 30, 2012
22,840
617
121
What does the VLC web plugin actually do? I thought it was to play Youtube videos but that doesn't seem to work, Youtube ignores it and always goes to Flash or HTML5.


Specific applications like MP4 or MP3. If you are using Firefox, Pale Moon or Cyberfox you can see what VLC defaults to under Tools | Options | Applications.
 
Last edited:

John Connor

Lifer
Nov 30, 2012
22,840
617
121
I've never bothered to install the VLC web plug-in; I generally regard plug-ins to be a great way to introduce extra vulnerabilities to one's set-up. I'll tolerate Flash because it's pretty much a requirement for a lot of sites to work, but I have it set to 'ask to activate' in FF.


Crap, I would bet VLC is more secure than flash. It seem there is a vulnerability for Flash once a month.
 

Red Squirrel

No Lifer
May 24, 2003
67,905
12,375
126
www.anyf.ca
What I don't get about how insecure flash is, is why does the flash application even have code that allows those things to happen? Flash is basically a client to display information. It should not actually be able to DO things that change your computer. It should only be able to display you content.

Another one that always gets me even more is PDFs. Those are basically glorified images that require an overcomplicated viewer. Why is there so many exploits in those products?
 

Bock

Senior member
Mar 28, 2013
319
0
0
Too fix it, go to adobes flash website, download and install. works from that point on
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |