May 30, 2008 10:32 AM PDT

Exploited bug doesn't exist in latest version of Flash

Old versions of Adobe Flash Player, perhaps the most widely used software in the world, contain known bugs that are being actively exploited online. If you are using any version of Flash Player, other than the latest, you should update to version 9.0.124.0 as soon as possible.

Early reports from Symantec said the bug being exploited was a new one. Turns out this is not the case. On Thursday, Adobe said

"Despite various reports that have been circulating, the Flash Player Standalone 9.0.124.0 and Linux Player 9.0.124.0 are NOT vulnerable to the exploits discussed in conjunction with the previously disclosed vulnerability Symantec posted on 5/27/08. Symantec originally believed this to be a zero-day, unpatched vulnerability, but as their latest update on their Threatcon page indicates, they have now confirmed this issue does not affect any versions of Flash Player 9.0.124.0."

You can see which version of Flash Player is being used by your Web browser at the Adobe Flash tester page. You need to check every Web browser installed on your computer.

For instructions on updating Flash Player, see Time to update the Flash Player. Here's how. If you use the portable version of Firefox, see Portable Firefox and the Flash Player for instructions on updating Flash Player.

See a summary of all my Defensive Computing postings.

Recent posts from Defensive Computing
The main problem with Windows Vista
Foxit PDF reader v2.3 updated with bug fixes
Cringely's iPhone Gripes
A warning about IE8 and Windows XP SP3
Be safer than NASA: Disable autorun
Add a Comment (Log in or register) 7 comments
by Lerianis May 31, 2008 9:08 PM PDT
Well, you should ALWAYS keep up to date with the latest versions of the software on your computer...... some things, like the Flash Player, should have an 'automatic update' thing where it runs on the start of your computer or when you first open a Flash file, searches for an update, and pops up a message if there is one.
Reply to this comment
by hnielsenatcbs June 1, 2008 1:31 PM PDT
Agree - Flash Player should have an auto update feature, just like Firefox and many others.
But there are alternatives - programs that watch your installed software for updates. CNET's VersionTracker is fine, but not free. FileHippo (www.filehippo.com) has a free alternative. Not as comprehensive as VersionTracker, but it does check your Flash, both the ActiveX and the "normal" (Firefox) version, and offer direct download links to the new versions. And it's easy to set it to start at boot-time.
Reply to this comment View reply
by dbjohnson2 June 1, 2008 2:29 PM PDT
I recommend the Secunia.com website.

You can run the online scanner which checks to see whether the typical suspect programs are up-to-date. One nice feature is it tells you where to obtain the update and where the obsolete version is installed on your PC.

But the feature I probably like best is that you can sign up to receive an email alert whenever there is a security update to the typical programs. This enables you to turn off many programs which run in the background on your PC checking for updates. Less non-required stuff running the better in my opinion.

And, no, I have no financial interest in Secunia.

Doug
Reply to this comment View reply
by i_made_this June 2, 2008 10:12 AM PDT
Agreed, the on-line Secunia Software Inspector is excellent. It actually proved something subtle to me about Adobe Flash - it doesn't matter if you keep up with extremely critical Flash patches / updates, so long as you continue using certain Instant Messengers and gaming programs that refuse to update Flash on their servers. The corrupt and outdated Flash code these providers insist on inflicting on your system doesn't mean you should stop being timely about your Flash updates. It just means that you should pause to consider why certain Instant Messengers in particular would choose not to be timely. What benefit do they gain by feeding your client with their servers' extremely critical and corrupt code? The answer is more than a little frightening.
Reply to this comment View reply
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
What you need in business class email.
Mailtrust

Click Here!
Never worry about email again. From mobility and shared calendaring to virus and spam protection starting at only $3 per mailbox. more>

Rackspace Mailtrust
Total Email Relief

We'll take care of your email so you can take care of your business.

14 Day Free Trial

With expert support 24x7x365 we guarentee 100% uptime. Try us for free for 14 days. Never worry about your email again.

Just $3 per mailbox

Choose the plan that is right for your company and only pay for what you need.

About Defensive Computing

Michael Horowitz is an independent computer consultant and the author of several classes on Defensive Computing. He views Defensive Computing as taking steps, when things are running well, to avoid or minimize the inevitable problems down the road. It's about educating yourself to the level where you can make your own intelligent decisions about keeping your computers and data happy and healthy. If you depend on computers, yet are on your own, without an IT department or nearby nerd, this blog's for you. His personal web site is michaelhorowitz.com.

He is a member of the CNET Blog Network and is not an employee of CNET.

Disclosure.

Add this feed to your online news reader

Defensive Computing topics

Featured blogs

advertisement

Inside CNET News

Scroll Left Scroll Right
  • Nanotech: The Circuits Blog

    Intel ships low-power chips for servers

    New server chips from processor giant draw as little as 12.5 watts per core.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • Webware

    Google upgrades Gmail for IE 6 users

    The online e-mail application is faster for those using the 7-year-old browser and gets features already available to more modern browsers, Google said.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Webware

    DemoFall preview: 10 to watch

    If you can only watch 10 pitches from DemoFall, these would be good ones.

  • Green Tech

    TI does energy efficiency on a chip

    Its line of Piccolo microcontrollers can reduce power consumption significantly of home appliances, hybrid cars, LED lighting, and even solar panels.