警報解除 2/3 : Adobe Flash Player
Posted in security on 7 月 31st, 2009 by gnome
Adobe Flash Player
永らくFlashを見るのを自粛していた方、お待ちどう様でした。
昨日ニコニコ生中継を見てたクセに!
また、関連して Adobe AIRを使用中の方もアップデートしてください
Security updates available for Adobe Flash Player
| Flash Player 10.x | → | 10.0.32.18 |
| Flash Player 9.x | → | 9.0.246.0 |
| Adobe AIR 1.5.1 | → | 1.5.2 |
注意:
バージョンチェックのページの最新版表記が更新されました。尚、IEの場合一度ブラウザを再起動しないと正確な表示ができません。複数のブラウザを使用中の方は、必ず各ブラウザ上でバージョンチェックを行い、10.0.32.18 (もしくは 9.0.246.0)になっていることを確認してください。
※基本的にはIEだけ別コンポネンツのはずですが・・・
----------
Security Bulletin Posted for Adobe Flash PlayerCVE:
CVE-2009-1862Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009.
CVE-2009-0901The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not prevent VariantClear calls on an uninitialized VARIANT, which allows remote attackers to execute arbitrary code via a malformed stream to an ATL (1) component or (2) control, related to ATL headers and error handling, aka "ATL Uninitialized Object Vulnerability."
CVE-2009-2395SQL injection vulnerability in the K2 (com_k2) component 1.0.1 Beta and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter in an itemlist action to index.php.
CVE-2009-2493The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka "ATL COM Initialization Vulnerability."
以下はreserved (非公開脆弱性)
CVE-2009-1863
CVE-2009-1864
CVE-2009-1865
CVE-2009-1866
CVE-2009-1867
CVE-2009-1868
CVE-2009-1869
CVE-2009-1870----------
セキュ各社報道:
6:30(JST)ではまだ無かった・・・
----------
シス管の方へ
コレでもカジリながらインストールしてください(笑)
ちなみに、まだ Adobe (Acrobat) Reader も残っています
(明日パッチ予定:月曜ですね・・)
Ciscoのルータを導入している方には更に楽しい(?)日になりそうです・・・
システム管理者の日
Happy patching day
CentOS-announce
A Security Vulnerability in Solaris BIND named(1M) Due to Insufficient Input Validation of Dynamic Update Requests Can Lead to Denial of Service (DoS)
[SECURITY] Fedora 11 Update: bind-9.6.1-4.P1.fc11
[SECURITY] [DSA 1847-1] New bind9 packages fix denial of service
USN-808-1: Bind vulnerability -- Ubuntu
Cisco Security Advisory: Cisco IOS Software Border Gateway Protocol 4-Byte Autonomous System Number Vulnerabilities
BlackHat USA+2009
Null Character Hack Allows SSL Spoofing
exact same way to fake being a popular website
Black Hat DC 09 Moxie Marlinspike Interview
Busy day at Black Hat
Vegas Baby!
URL bar spoofing vulnerability

KILL Acrobat JavaScript
Apple QuickTime 7.5.6
Firefox 3.6.3
Chrome 4.1.249.1045
Opera 10.51
Thunderbird 3.0.4
O
OOo 3.2
RealPlayer SP1.1.2(12.0.0.641)
Skype 4.2.0.155
Pidgin 2.6.6
Wordpress 2.9.2
WireShark 1.2.7




Secunia PSI
MyJVN VerChk

BEFORE BURNER
