The latest version of Chrome includes a few minor fixes and a very important security update for the embedded Flash player. The official announcement for version 39.0.2171.71 has additional details.
Category Archives: Flash
Flash 15.0.0.239 strengthens protection against CVE-2014-8439
Security vulnerability CVE-2014-8439 was addressed in the October updates for Flash, but recent attacks made it clear that more work was required. Flash 15.0.0.239 provides additional protection against attacks based on CVE-2014-8439.
Anyone who uses Flash is advised to install the new version as soon as possible. Google Chrome and Internet Explorer 10/11 in Windows 8.x will be updated automatically.
Note that if you use Flash in Internet Explorer as well as in other web browsers, you may need to install the new version twice: once using IE and once using another browser.
Chrome 38.0.2125.122 released
A new version of Google’s web browser was announced yesterday. Version 38.0.2125.122 fixes some bugs, and updates the embedded Flash to the latest version. Apparently there are no security fixes in this version, although the updated Flash does include security fixes.
Patch Tuesday for November 2014
Yesterday Microsoft released fourteen updates, addressing 33 CVEs in Windows, Internet Explorer, Office, .NET, Internet Information Services, Remote Desktop Protocol, Active Directory Federation Services, Input Method Editor, and Kernel Mode Driver. Four of the updates are flagged as Critical. You can find all the details in the main bulletin.
Two of the expected sixteen updates (MS14-068 and MS14-075) were held back by Microsoft, with release dates for those updates now being shown as ‘Release date to be determined’.
In keeping with its new monthly update policy, Adobe released a new version of Flash yesterday. Flash 15.0.0.223 addresses several security vulnerabilities in previous versions.
Brian Krebs has additional analysis of these updates.
Update 2014Nov15: One of the updates in this batch addresses a serious vulnerability that exists on all versions of Windows. MS14-066 fixes a bug in the way secure connections are handled by the Microsoft secure channel (schannel) security component. Most of the focus has been on Windows servers, especially those running Microsoft’s web server software, Internet Information Services (IIS). However, according to some sources, any Windows computer that is configured to accept secure network connections is potentially vulnerable. Recommendation: if you’re running any Internet-facing service on a Windows computer, install this patch ASAP. Ars Technica has additional details.
Update 2014Nov15: Another of this month’s patches (MS14-064) addresses problems with a previous patch (MS14-060). McAfee has a detailed breakdown of the problems with MS14-060.
Update 2014Nov19: MS14-068 was released.
Update 2014Nov26: Apparently the MS14-066 update caused problems for some Windows servers. Microsoft added a workaround to the update bulletin that should resolve one of the problems, but has yet to acknowledge the performance problems reported in SQL Server and IIS. InfoWorld has additional details.
Patch Tuesday for October 2014
Yesterday saw eight security bulletins and associated patches from Microsoft, as well as two new versions of Java from Oracle, and a new version of Adobe Flash.
The Microsoft updates include three flagged Critical. The updates address twenty-four CVEs in Windows, Office, .NET Framework, .ASP.NET, and Internet Explorer. A post on the MSRC blog provides a good overview.
Two new versions of Java from Oracle address as many as 25 security vulnerabilities in Java 7 and 8. If you’re using a web browser with Java enabled, you should install Java SE 8 Update 25 and/or Java SE 7 Update 72 as soon as possible. Unfortunately, Oracle has made things a bit confusing by saying that you should install SE 7 Update 72 only if you are being affected by the issues fixed in that version, and otherwise to install Update 71. Our recommendation is to install Update 72.
The new version of Flash is 15.0.0.189, and it includes fixes for at least three security vulnerabilities. If you’re like most people and use a browser with Flash enabled, you should update to the new version as soon as possible.
Flash version 15.0.0.167 for Internet Explorer
Yesterday Adobe released Flash 15.0.0.167 for Internet Explorer on Windows. No other platforms are affected. The new version fixes one specific bug that caused video failures in certain cases.
This is not a security-related update.
Chrome 37.0.2062.120 released
Chrome 37.0.2062.120 was announced yesterday. The new version includes the latest Adobe Flash, and fixes several security vulnerabilities.
Patch Tuesday for September 2014
This month’s crop of updates from Microsoft includes four security bulletins, addressing 42 CVEs in Microsoft Windows, Internet Explorer, .NET Framework, and Lync Server. The update for Internet Explorer is Critical, and should be installed ASAP.
From Adobe, we get another new version of Flash, 15.0.0.152. The new version addresses memory leakage vulnerabilities that could be used to bypass memory address randomization (CVE-2014-0557), a security bypass vulnerability (CVE-2014-0554), a use-after-free vulnerability that could lead to code execution (CVE-2014-0553), memory corruption vulnerabilities that could lead to code execution (CVE-2014-0547, CVE-2014-0549, CVE-2014-0550, CVE-2014-0551, CVE-2014-0552, CVE-2014-0555), a vulnerability that could be used to bypass the same origin policy (CVE-2014-0548), and a heap buffer overflow vulnerability that could lead to code execution (CVE-2014-0556, CVE-2014-0559). Anyone still using Flash, especially within a web browser, should update immediately.
Google Chrome and Internet Explorer on Windows 8.x will be updated automatically to include the new version of Flash.
Chrome 36.0.1985.143: security fixes and new Flash
Another new version of Chrome was released on August 12. Version 36.0.1985.143 closes twelve security holes and includes a new version of Flash.
August Patch Tuesday for Adobe software
Adobe’s monthly updates continue to coincide with Microsoft’s. This month there are updates for Adobe Acrobat/Reader and Flash.
The new version of Flash is 14.0.0.176, unless you’re using Flash in a browser other than Internet Explorer, in which case it’s 14.0.0.179. Regardless, the new version includes several bug and security fixes, and adds some new features that are mainly of interest to developers.
The latest version of Adobe Reader is 11.0.0.8. This version fixes a specific vulnerability that allows attackers to circumvent security protections. According to Adobe, attacks based on this vulnerability have been seen in the wild.