Tuesday, November 13, 2018

Adobe Flash Player Security Updates Released


Adobe Flashplayer

Adobe has released Version 31.0.0.148 of Adobe Flash Player and AIR for Windows, macOS, Linux and Chrome OS. These updates address an important vulnerability in Adobe Flash Player 31.0.0.122 and earlier versions.  Successful exploitation could lead to information disclosure.

Release date:  November 13, 2018
Vulnerability identifier: APSB18-39
Platform:  Windows, Macintosh, Linux and Chrome OS

Fixed Issues

Flash Player
  • IE quits unexpectedly on opening multiple tabs with Flash Content (FP-4198903)
  • Assorted security and functional fixes

Vulnerability details

Vulnerability Category Vulnerability Impact Severity CVE Number
Out-of-bounds Read Information Disclosure Important CVE-2018-15978

Update:

*Important Note:  Downloading the update from the Adobe Flash Player Download Center link includes a pre-checked option to install unnecessary extras, such as McAfee Scan Plus or Google Drive.  If you use the download center, uncheck any unnecessary extras that you do not want.  They are not needed for the Flash Player update.

    Verify Installation

    To verify the Adobe Flash Player version number installed on your computer, go to the About Flash Player page, or right-click on content running in Flash Player and select "About Adobe Flash Player" from the menu. 

    Do this for each browser installed on your computer.

    To verify the version of Adobe Flash Player for Android, go to Settings > Applications > Manage Applications > Adobe Flash Player x.x.

    References



    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...









    Adobe Acrobat DC and Reader DC Security Updates Released

    Adobe

    Adobe has released security updates for Adobe Acrobat and Reader for Windows to resolve an important vulnerability.  Successful exploitation could lead to an inadvertent leak of the user’s hashed NTLM password.  Proof-of-concept code for CVE-2018-15979 is publicly available. 


    Release date:  November 13, 2018
    Vulnerability identifier: APSB18-40
    Platform: Windows

    Update or Complete Download

    Reader DC and Acrobat DC were updated to version 2019.008.20081. Update checks can be manually activated by choosing Help & Check for Updates. 
    Note: UNcheck any pre-checked additional options presented with the update. They are not part of the software update and are completely optional.


    References





    Home
    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...



    Pale Moon Version 28.2.0 Released with Security Updates


    Pale Moon
    Pale Moon has been updated to version 28.2.0, a major development release addressing performance, web compatibility, bugfixes, regressions and security vulnerabilities.  In particular, security fixes have been implemented for CVE-2018-12381, CVE-2017-7797, a better fix for CVE-2018-12386 (DiD), CVE-2018-12401 (DiD), CVE-2018-12398, CVE-2018-12392, several Skia bugs, and several crashes and memory safety hazards that do not have a CVE number.

    From the Release Notes:

    Changes/fixes:
    • Fixed a major performance issue with web workers.
    • Fixed a rare crash on local networks with HTTP basic auth and unsupported cipher suites.
    • Fixed a performance/timer issue when leaving the browser idle.
    • Fixed an issue causing an empty dialog when launching executable files from the browser.
    • Fixed an issue preventing making entries to disallow sites to store data for off-line use.
    • Removed code to prevent extensions with binary components.
    • Fixed an issue with common dialogs being sized incorrectly for their content.
    • Fixed an issue with event handling on the tab bar that would cause frustrating behavior when trying to open/close tabs in rapid succession.
    • Switched default behavior for scrolling when a context or pop-up menu is open to allow scrolling, like in v27. This also affects scrolling in very long menus, e.g. bookmarks.
    • Added experimental Asynchronous Panning and Zooming (APZ) for desktop use.
    • Re-enabled the use and parsing of ICC v4 color profiles.
    • Removed telemetry code from the caching subsystem.
    • Improved full-screen detection for suppressing status messages.
    • Made all arguments passed to Init*Event() optional except the first for parity with other browsers.
    • Cleaned up some internal installer code.
    • Fixed making caret width configurable when dealing with CJK characters (regression).
    • Fixed drawing of table borders consistently when zooming a page (regression).
    • Exposed the "Save download location per site" pref in about:config.
    • Improved media handling (ongoing).
    • Added experimental support for AV1 in WebM videos (disabled by default).
      Note: this is for WebM only for now, so MP4 and MSE AV1 streams (e.g. YouTube) will not (yet) play.
    • Removed the (defunct and incomplete) in-browser translation code.
    • Fixed an issue with CSS Grid layouts unnecessarily shrinking element blocks.
    • Fixed notification settings menu entry (opes about:permissions with relevant data now).
    • Fixed the launching of an undesirable background content process for capturing page thumbnails.
    • Fixed a focus issue in the bookmark properties dialog.
    • Changed the setting for reporting CSS errors to the console to false by default, to prevent unnecessary performance loss for recording this data.
    • Added control mechanisms for Opportunistic Encryption (both for alternative services and upgrade-insecure-requests) in preferences, and disabled this by default due to potential security and privacy issues with this transitional technology.
    • Updated the default reported Firefox version in Firefox Compatibility Mode to prevent "too old Firefox" complaints on websites.
    • Updated libnestegg, ffvpx, reader view components and several other modules from upstream.
    • Implemented security fixes for CVE-2018-12381, CVE-2017-7797, a better fix for CVE-2018-12386 (DiD), CVE-2018-12401 (DiD), CVE-2018-12398, CVE-2018-12392, several Skia bugs, and several crashes and memory safety hazards that do not have a CVE number.
      Download:

      Update

      To get the update now, select "Help" from the Pale Moon menu at the upper left of the browser window.  Select About Pale Moon > Check for Updates.




      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...