Exploited bug doesn't exist in latest version of Flash
Old versions of Adobe Flash Player, perhaps the most widely used software in the world, contain known bugs that are being actively exploited online. If you are using any version of Flash Player, other than the latest, you should update to version 9.0.124.0 as soon as possible.
Early reports from Symantec said the bug being exploited was a new one. Turns out this is not the case. On Thursday, Adobe said
"Despite various reports that have been circulating, the Flash Player Standalone 9.0.124.0 and Linux Player 9.0.124.0 are NOT vulnerable to the exploits discussed in conjunction with the previously disclosed vulnerability Symantec posted on 5/27/08. Symantec originally believed this to be a zero-day, unpatched vulnerability, but as their latest update on their Threatcon page indicates, they have now confirmed this issue does not affect any versions of Flash Player 9.0.124.0."
You can see which version of Flash Player is being used by your Web browser at the Adobe Flash tester page. You need to check every Web browser installed on your computer.
For instructions on updating Flash Player, see Time to update the Flash Player. Here's how. If you use the portable version of Firefox, see Portable Firefox and the Flash Player for instructions on updating Flash Player.
See a summary of all my Defensive Computing postings.



But there are alternatives - programs that watch your installed software for updates. CNET's VersionTracker is fine, but not free. FileHippo (www.filehippo.com) has a free alternative. Not as comprehensive as VersionTracker, but it does check your Flash, both the ActiveX and the "normal" (Firefox) version, and offer direct download links to the new versions. And it's easy to set it to start at boot-time.
You can run the online scanner which checks to see whether the typical suspect programs are up-to-date. One nice feature is it tells you where to obtain the update and where the obsolete version is installed on your PC.
But the feature I probably like best is that you can sign up to receive an email alert whenever there is a security update to the typical programs. This enables you to turn off many programs which run in the background on your PC checking for updates. Less non-required stuff running the better in my opinion.
And, no, I have no financial interest in Secunia.
Doug