Thursday, April 13, 2017
New Adobe CRITICAL Security Updates Acrobat Pro and Reader 11 0 03
New Adobe CRITICAL Security Updates Acrobat Pro and Reader 11 0 03
-
[Updated 2013-05-21 @8:38 AM: I removed the paragraphs and image regarding a low resolution icon for Adobe Reader. What I had witnessed was, I have discovered, yet another bug in Apples Finder application. Ive witnessed the exact same phenomenon with other newly installed apps. Refreshing or relaunching the Finder removes the problem. Not good Apple! Apologies to Adobe.]
On schedule, Adobe has posted critical security updates of both Acrobat Pro and Reader. The download links are below.
Thankfully, Adobe has (belatedly) provided an updated Security Bulletin as well, which is also linked below. The updates patch 27 security vulnerabilities.
Security Bulletin:
http://www.adobe.com/support/security/bulletins/apsb13-15.html
Adobe Reader XI (11.0.03):
http://get2.adobe.com/reader/
Adobe Acrobat Pro XI (11.0.03):
http://www.macupdate.com/download/1833/AcrobatUpd11003.dmg
Here are the security CVE vulnerabilities patched by these updates:
These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, CVE-2013-3341).
These updates resolve an integer underflow vulnerability that could lead to code execution (CVE-2013-2549).
These updates resolve a use-after-free vulnerability that could lead to a bypass of Adobe Readers sandbox protection (CVE-2013-2550).
These updates resolve an information leakage issue involving a Javascript API (CVE-2013-2737).
These updates resolve a stack overflow vulnerability that could lead to code execution (CVE-2013-2724).
These updates resolve buffer overflow vulnerabilities that could lead to code execution (CVE-2013-2730, CVE-2013-2733).
These updates resolve integer overflow vulnerabilities that could lead to code execution (CVE-2013-2727, CVE-2013-2729).
These updates resolve a flaw in the way Reader handles domains that have been blacklisted in the operating system (CVE-2013-3342).

--
Go to link Download
Saturday, March 25, 2017
NTFS Adobe Acrobat Reader Real Player Fedora Core 5
NTFS Adobe Acrobat Reader Real Player Fedora Core 5
1. Installing NTFS Support : -
1. Log in to linux in Super User mode or do so by typing "su" command at the console
2. Type "uname -rm" at the console to know the kernel version and processor type.
3. Go to the website "http://www.linux-ntfs.org/content/view/187/" and download the RPM package for NTFS driver relevant to your Linux kernel .
4. After downloading the driver go to the directory where you have downloaded the RPM directory and type "rpm -ivh kernel-module-ntfs-2.6.XX-XXXXXXXX.rpm" to install the driver.
5. Make a directory where you would like to have NTFS partition mounted Ex:- if you would like to have it mounted at /windows "mkdir /windows" .
6. type "/sbin/fdisk -l" to view available partitions and NTFS partion drive number
7. now edit /etc/fstab file using gedit and add line "/dev/hda1 /windows ntfs ro,defaults,umask=0222 0 0" at the end of the file replace /dev/hda1 with your ntfs partition as displayed by fdisk and /windows with your directory which you would like to mount ntfs volume onto.
8. Restart the linux to see change
2. Installing Real Player 10 and Adobe Acrobat Reader
1. Fedora Core 5 uses GCC 4.1 , Now many applications including Real player 10 and Adobe Acrobat 7.0 requires GCC 3.2 as they were compiled on these libraries hence for compatibility installation of this library is necessary.
GCC 3.2 Can be found on CD-3 of Fedora Core 5 , DVD or online
2. These Files are
compat-libstdc -33
compat-libstdc -296
3. To Install it using automatic yum package manager type" yum install compat-libstdc -33 compat-libstdc -296" after logging in Super User mode or after "su " at console
4. The library can also be downloaded as rpm from "http://rpmfind.net//linux/RPM/fedora/5/i386/compat-libstdc -33-3.2.3-55.fc5.i386.html" After downloading it can be installed as "rpm -ivh compatXXXXXX.rpm" after logging in super user mode.
5. After installing GCC 3.2 Library. Go to "http://www.real.com/linux" Download real player package and install it using "rpm -ivh RealXXXX.rpm" after logging inSuper User mode
6. Similarly install Adobe Acrobat Reader by downloading rpm package from "http://ardownload.adobe.com/pub/adobe/reader/unix/7x/7.0.8/enu/AdobeReader_enu-7.0.8-1.i386.rpm" and using rpm to install the package
Go to link Download
Sunday, December 18, 2016
Out of Band Adobe Flash Player Critical Security Update
Out of Band Adobe Flash Player Critical Security Update
Adobe has released security updates for Adobe Flash Player 16.0.0.257 and earlier versions for Windows and Macintosh and Adobe Flash Player 11.2.202.425 and earlier versions for Linux.
Correction: From Threatpost, Adobe Patches One Zero Day in Flash, Still Investigating Separate Vulnerability:
"The vulnerability that Adobe patched Thursday is under active attack, but Adobe officials said that this flaw is not the one that security researcher Kafeine said Wednesday was being used in the Angler attacks."The Threatpost article further indicated that there is no indication from Adobe officials that an update is in the works for the Angler zero-day vulnerability.
The update below has been released by Adobe to address the vulnerability. It is strongly advised that the update be applied as soon as possible.
Update Information:
Vulnerability identifier: APSB15-02
CVE number: CVE-2015-0310
Platform: All Platforms
- Users of the Adobe Flash Player desktop runtime for Windows and Macintosh should update to Adobe Flash Player 16.0.0.287.
- Users of the Adobe Flash Player Extended Support Release should update to Adobe Flash Player 13.0.0.262.
- Users of Adobe Flash Player for Linux should update to Adobe Flash Player 11.2.202.438.
- Adobe Flash Player installed with Google Chrome, as well as Internet Explorer on Windows 8.x, will automatically update to the current version.
Flash Player Update Instructions
Warning: Although Adobe suggests downloading the update from the Adobe Flash Player Download Center, that link includes a pre-checked option to install unnecessary extras, such as McAfee Scan Plus or Google Drive. If you use the download center, uncheck any unnecessary extras.It is recommended that you either use the auto-update mechanism within the product when prompted, or my preference, the direct download links.
- Non-IE Plugin (Opera, Firefox, Etc.): http://download.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_16_plugin.exe
- Flash Player For Internet Explorer, Windows 7 and earlier: http://download.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_16_active_x.exe
Internet Explorer, Windows 8 and above: Microsoft updated Security Advisory 2755801. If you do not have Automatic Updates enabled, the Flash Player update can be downloaded from Microsoft Security Advisory: Update for Vulnerabilities in Adobe Flash Player in Internet Explorer 10: July 9, 2013. - Flash Player Uninstaller: http://download.macromedia.com/get/flashplayer/current/support/uninstall_flash_player.exe
- Adobe AIR: http://get.adobe.com/air/
Notes:
- If you use the Adobe Flash Player Download Center, be careful to uncheck any optional downloads that you do not want. Any pre-checked option is not needed for the Flash Player update.
- Uncheck any toolbar offered with Adobe products if not wanted.
- If you use alternate browsers, it is necessary to install the update for both Internet Explorer as well as the update for alternate browsers.
- The separate 32-bit and 64-bit uninstallers have been replaced with a single uninstaller.
- Users of the Adobe Flash Player Extended Support Release should update to Adobe Flash Player 13.0.0.259.
The latest version for Adobe Flash Player for Android is available by downloading it from the Android Marketplace by browsing to it on a mobile phone.
Verify Installation
To verify the Adobe Flash Player version number installed on your computer, go to the About Flash Player page, or right-click on content running in Flash Player and select "About Adobe Flash Player" from the menu.Do this for each browser installed on your computer.
To verify the version of Adobe Flash Player for Android, go to Settings > Applications > Manage Applications > Adobe Flash Player x.x.
References
- Adobe Priority Ratings
- AIR Download Center
- Security Bulletin: APSB15-02
- Release Notes: Flash Player® 16 AIR® 16
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Go to link Download
Monday, December 12, 2016
On Vacation but Java updates from Oracle and Apple Be sure to have the UNmessed up Apple Java update!!! and Adobe Flash Update
On Vacation but Java updates from Oracle and Apple Be sure to have the UNmessed up Apple Java update!!! and Adobe Flash Update

Im on a break while I work on other things. But here is some quickie news. I expect, if youre a regular reader, you know how to dig up the URLs and CVE reports by now.
I) MASSIVE CRITICAL Java update from both Oracle and Apple, including 40 (FORTY) security patches. Apples update is for Java version 1.6 only, the part of Java included in OS X. The update is for OS X 10.6 - 10.8.
II) Apple MESSED-UP their original Java update release, which was labeled "JavaForOSX2013-003". This mess KILLED Java and must be updated with what replaced it: "JavaForOSX2013-004". From my experience, Software Update did NOT provide me with the updated version. I had to grab oo4 myself and apply it myself. You may have to do so as well.
Here is an article to help you sort out whether you got STUNG by Apples mess or not, and how to clean it up. Thank you to 9to5Mac.com:


Go to link Download
Sunday, November 27, 2016
Out of Band Critical Adobe Flash Player and AIR Update
Out of Band Critical Adobe Flash Player and AIR Update
Adobe has released Version 18.0.0.203 of Adobe Flash Player for Windows and Macintosh and Version 18.0.0.180 of Adobe AIR. Version information for Linux and the Extended Release is available below.
This update addresses critical vulnerabilities that could potentially allow an attacker to take control of the affected system. Because an exploit targeting CVE-2015-5119 has been published publicly, updating to the latest version as soon as possible is advised.
Details of the vulnerabilities are included in the below-referenced Security Bulletin. At the time of this posting, the Release Notes have not yet been released but will be available later in the reference below.
Release date: July 8, 2015
Vulnerability identifier: APSB15-16
CVE number: CVE number: CVE-2014-0578, CVE-2015-3097, CVE-2015-3114, CVE-2015-3115, CVE-2015-3116, CVE-2015-3117, CVE-2015-3118, CVE-2015-3119, CVE-2015-3120, CVE-2015-3121, CVE-2015-3122, CVE-2015-3123, CVE-2015-3124, CVE-2015-3125, CVE-2015-3126, CVE-2015-3127, CVE-2015-3128, CVE-2015-3129, CVE-2015-3130, CVE-2015-3131, CVE-2015-3132, CVE-2015-3133, CVE-2015-3134, CVE-2015-3135, CVE-2015-3136, CVE-2015-3137, CVE-2015-4428, CVE-2015-4429, CVE-2015-4430, CVE-2015-4431, CVE-2015-4432, CVE-2015-4433, CVE-2015-5116, CVE-2015-5117, CVE-2015-5118, CVE-2015-5119
Platform: All Platforms
- Users of the Adobe Flash Player desktop runtime for Windows and Macintosh should update to Adobe Flash Player 18.0.0.203. The current version of Adobe AIR is 18.0.0.180.
- Users of the Adobe Flash Player Extended Support Release should update to Adobe Flash Player 13.0.0.302.
- Users of Adobe Flash Player for Linux should update to Adobe Flash Player 11.2.202.481.
- Adobe Flash Player installed with Google Chrome, as well as Internet Explorer on Windows 8.x, will automatically update to the current version.
- The latest version of Adobe AIR for Android is 18.0.0.180 and earlier versions, available by downloading it from the Android Marketplace by browsing to it on a mobile phone.
Flash Player Update Instructions
It is recommended that you either use the auto-update mechanism within the product when prompted or the direct download links. The problem with the auto-update mechanism is that it can take a few days to finally provide the update and up to a week if using the "Notify me to install updates" setting.Flash Player Auto-Update
The update settings for Flash Player versions 10.3 and above can found in the Advanced tab of the Flash Player Settings Manager. The locations are as follows:
- Windows: click Start > Settings > Control Panel > Flash Player
- Macintosh: System Preferences (under Other) click Flash Player
- Linux Gnome: System > Preferences > Adobe Flash Player
- Linux KDE: System Settings > Adobe Flash Player
Flash Player Direct Download Links
Warning: Although Adobe suggests downloading the update from the Adobe Flash Player Download Center, that link includes a pre-checked option to install unnecessary extras, such as McAfee Scan Plus or Google Drive. If you use the download center, uncheck any unnecessary extras.
- Non-IE Plugin (Opera, Firefox, Etc.): http://download.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_18_plugin.exe
- Flash Player For Internet Explorer, Windows 7 and earlier: http://download.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_18_active_x.exe
Internet Explorer, Windows 8 and above: Microsoft updated Security Advisory 2755801. If you do not have Automatic Updates enabled, the Flash Player update can be downloaded from Microsoft Security Advisory: Update for Vulnerabilities in Adobe Flash Player in Internet Explorer 10: July 9, 2013. - Flash Player Uninstaller: http://download.macromedia.com/get/flashplayer/current/support/uninstall_flash_player.exe
- Adobe AIR: http://get.adobe.com/air/
Notes:
- If you use the Adobe Flash Player Download Center, be careful to uncheck any optional downloads that you do not want. Any pre-checked option is not needed for the Flash Player update.
- Uncheck any toolbar offered with Adobe products if not wanted.
- If you use alternate browsers, it is necessary to install the update for both Internet Explorer as well as the update for alternate browsers.
- The separate 32-bit and 64-bit uninstallers have been replaced with a single uninstaller.
Verify Installation
To verify the Adobe Flash Player version number installed on your computer, go to the About Flash Player page, or right-click on content running in Flash Player and select "About Adobe Flash Player" from the menu.Do this for each browser installed on your computer.
To verify the version of Adobe Flash Player for Android, go to Settings > Applications > Manage Applications > Adobe Flash Player x.x.
References
- Adobe Priority Ratings
- AIR Download Center
- Security Bulletin: Security Bulletin
- Release Notes: Flash Player® 18 AIR® 18
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Go to link Download
Sunday, October 30, 2016
New Adobe Flash Exploits In The Wild New Critical Adobe Flash Update v11 6 602 171
New Adobe Flash Exploits In The Wild New Critical Adobe Flash Update v11 6 602 171

Where to download the latest version of Flash, in this case v11.6.602.171:
http://get.adobe.com/flashplayer/
Adobes related security reports:
Today, a Security Bulletin (APSB13-08) has been posted to address security issues in Adobe Flash Player 11.6.602.168 and earlier versions for Windows, Adobe Flash Player 11.6.602.167 and earlier versions for Macintosh, and Adobe Flash Player 11.2.202.270 and earlier versions for Linux.
Adobe is aware of reports that CVE-2013-0643 and CVE-2013-0648 are being exploited in the wild in targeted attacks designed to trick the user into clicking a link which directs to a website serving malicious Flash (SWF) content. The exploit for CVE-2013-0643 and CVE-2013-0648 is designed to target Flash Player in Firefox.
Adobe recommends users apply the updates for their product installations.
Security Bulletin (APSB13-08)
- Users of Adobe Flash Player 11.6.602.168 and earlier versions for Windows and Adobe Flash Player 11.6.602.167 and earlier versions for Macintosh should update to Adobe Flash Player 11.6.602.171.
- Users of Adobe Flash Player 11.2.202.270 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.273.
- Adobe Flash Player installed with Google Chrome will automatically be updated to the latest Google Chrome version, which will include Adobe Flash Player 11.6.602.171 for Windows, Macintosh and Linux.
- Adobe Flash Player installed with Internet Explorer 10 for Windows 8 will automatically be updated to the latest version of Internet Explorer 10, which will include Adobe Flash Player 11.6.602.171 for Windows.
This update resolves a permissions issue with the Flash Player Firefox sandbox (CVE-2013-0643).
This update resolves a vulnerability in the ExternalInterface ActionScript feature, which can be exploited to execute malicious code (CVE-2013-0648).
This update resolves a buffer overflow vulnerability in a Flash Player broker service, which can be used to execute malicious code (CVE-2013-0504).
Stop Adobe Flash In Your Web Browser!
Because of drive-by infections via malicious Flash files, I HIGHLY recommend stopping Flash files dead in your web browsers until YOU approve them running. I have updated my list of web browser Flash blocking add-ons/extensions:
Safari: ClickToFlash, Plugin Customs
Firefox: Flashblock, NoScript
Chromium: Flashblock, FlashControl, SafeScript (ScriptNo)
Opera: Use the Preferences:Advanced:Content:"Enable plug-ins only on demand" checkbox. Also sort of useful is NotScripts. (Note: NotScripts is kind of a PITA to setup, but works once you have your JavaScript cache set, as prescribed, to 5000K).
:-Derek


Go to link Download
Monday, October 17, 2016
New Adobe Reader
New Adobe Reader
Adobe has released updates to their Adobe Reader application which should fix security vulnerabilities which affecting Adobe Reader 9.5.3, 10.1.5 and 11.0.1. Their PSIRT team has confirmed this bug and they acted fast by releasing new version which hopefully fixed this problem.
You can get the Windows version here and Linux version here
Go to link Download
Friday, September 30, 2016
Out of Band Critical Adobe Flash Player Update
Out of Band Critical Adobe Flash Player Update
Adobe has released Version 18.0.0.194 of Adobe Flash Player for Windows and Macintosh to address a critical vulnerability that is being exploited in limited, targeted attacks.
Version information for Linux and the Extended Release is available in the Release Notes.
Vulnerability identifier: APSB15-14
Priority: See table below
CVE number: CVE-2015-3113
Platform: Windows, Macintosh and Linux
Users of the Adobe Flash Player desktop runtime for Windows and Macintosh should update to Adobe Flash Player 18.0.0.194.
- Users of the Adobe Flash Player Extended Support Release should update to Adobe Flash Player 13.0.0.296.
- Users of Adobe Flash Player for Linux should update to Adobe Flash Player 11.2.202.486.
- Adobe Flash Player installed with Google Chrome, as well as Internet Explorer on Windows 8.x and Windows 10 TP, will automatically update to the current version.
Flash Player Update Instructions
It is recommended that you either use the auto-update mechanism within the product when prompted or the direct download links. The problem with the auto-update mechanism is that it can take a few days to finally provide the update and up to a week if using the "Notify me to install updates" setting.Flash Player Auto-Update
The update settings for Flash Player versions 10.3 and above can found in the Advanced tab of the Flash Player Settings Manager. The locations are as follows:
- Windows: click Start > Settings > Control Panel > Flash Player
- Macintosh: System Preferences (under Other) click Flash Player
- Linux Gnome: System > Preferences > Adobe Flash Player
- Linux KDE: System Settings > Adobe Flash Player
Flash Player Direct Download Links
Warning: Although Adobe suggests downloading the update from the Adobe Flash Player Download Center, that link includes a pre-checked option to install unnecessary extras, such as McAfee Scan Plus or Google Drive. If you use the download center, uncheck any unnecessary extras.
- Non-IE Plugin (Opera, Firefox, Etc.): http://download.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_18_plugin.exe
- Flash Player For Internet Explorer, Windows 7 and earlier: http://download.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_18_active_x.exe
Internet Explorer, Windows 8 and above: Microsoft updated Security Advisory 2755801. If you do not have Automatic Updates enabled, the Flash Player update can be downloaded from Microsoft Security Advisory: Update for Vulnerabilities in Adobe Flash Player in Internet Explorer 10: July 9, 2013. - Flash Player Uninstaller: http://download.macromedia.com/get/flashplayer/current/support/uninstall_flash_player.exe
- Adobe AIR: http://get.adobe.com/air/
Notes:
- If you use the Adobe Flash Player Download Center, be careful to uncheck any optional downloads that you do not want. Any pre-checked option is not needed for the Flash Player update.
- Uncheck any toolbar offered with Adobe products if not wanted.
- If you use alternate browsers, it is necessary to install the update for both Internet Explorer as well as the update for alternate browsers.
- The separate 32-bit and 64-bit uninstallers have been replaced with a single uninstaller.
Verify Installation
To verify the Adobe Flash Player version number installed on your computer, go to the About Flash Player page, or right-click on content running in Flash Player and select "About Adobe Flash Player" from the menu.Do this for each browser installed on your computer.
To verify the version of Adobe Flash Player for Android, go to Settings > Applications > Manage Applications > Adobe Flash Player x.x.
References
- Adobe Priority Ratings
- AIR Download Center
- Security Bulletin: Security Bulletin
- Release Notes: Flash Player® 18 AIR® 18
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Computer security news & information, help, tips, tutorials, and more.
©2006 - 2016 "Security Garden" By Corrine
Go to link Download