Guru3D.com
  • HOME
  • NEWS
    • Channels
    • Archive
  • DOWNLOADS
    • New Downloads
    • Categories
    • Archive
  • GAME REVIEWS
  • ARTICLES
    • Rig of the Month
    • Join ROTM
    • PC Buyers Guide
    • Guru3D VGA Charts
    • Editorials
    • Dated content
  • HARDWARE REVIEWS
    • Videocards
    • Processors
    • Audio
    • Motherboards
    • Memory and Flash
    • SSD Storage
    • Chassis
    • Media Players
    • Power Supply
    • Laptop and Mobile
    • Smartphone
    • Networking
    • Keyboard Mouse
    • Cooling
    • Search articles
    • Knowledgebase
    • More Categories
  • FORUMS
  • NEWSLETTER
  • CONTACT

New Reviews
Scythe Mugen 5 Rev.C CPU Cooler review
be quiet Pure Loop 2 FX 280mm LCS review
HP FX900 1 TB NVMe Review
Scythe FUMA2 Rev.B CPU Cooler review
SK Hynix Platinum P41 2TB M.2 NVMe SSD Review
Corsair K70 RGB PRO Mini Wireless review
MSI MPG A1000G - 1000W PSU Review
Goodram IRDM PRO M.2 SSD 2 TB NVMe SSD Review
Samsung T7 Shield Portable 1TB USB SSD review
DeepCool LS720 (LCS) review

New Downloads
AMD Radeon Software Adrenalin 22.8.1 driver download
Prime95 download version 30.8 build 16
Memtest86 9.5 download
Intel ARC graphics Driver Download Version: 30.0.101.1743
GeForce 516.94 WHQL driver download
Display Driver Uninstaller Download version 18.0.5.4
FurMark Download v1.31
Intel HD graphics Driver Download Version: 31.0.101.3222
AMD Radeon Software Adrenalin 22.7.1 driver download
GeForce 516.93 WHQL Studio driver download


New Forum Topics
The AMD Ryzen All In One Thread /Overclocking/Memory Speeds & Timings/Tweaking/Cooling Part 2 Info Zone - gEngines, Ray Tracing, DLSS, DLAA, TSR, FSR, XeSS, DLDSR etc. New Upcoming ATI/AMD GPU's Thread: Leaks, Hopes & Aftermarket GPU's 96-core AMD Epyc Genoa CPU spotted Samsung Galaxy Z Flip4 and Galaxy Z Fold4: Starting at 1800 USD AMD Software: Adrenalin Edition 22.8.1- Driver download and discussion ClockTuner 2.0 for Ryzen (CTR) Guide and download Microsoft pushing driver 512.15 AMD Radeon Software Customize Setup - Radeon Setup Tool DesktopOverlayHost Overlay display freeze issue




Guru3D.com » News » Adobe Patches Flash Bugs, Attackers Targeted Firefox Users

Adobe Patches Flash Bugs, Attackers Targeted Firefox Users

by Hilbert Hagedoorn on: 03/01/2013 10:06 AM | source: | 7 comment(s)
Adobe Patches Flash Bugs, Attackers Targeted Firefox Users

If you are a Firefox user and missed the update released yesterday, Adobe has patched three security flaws that specifically targeted the Mozilla Firefox browser.Adobe patched three new security flaws in its near-ubiquitous Flash Player, of which two were already being exploited in the wild. Attackers were specifically targeting Mozilla Firefox users, the company said. 

The two zero-day vulnerabilities, CVE 2013-0643 and CVE 2013-0648, were being exploited in targeted attacks where users were tricked into clicking on a link to a Website hosting malicious Flash files, Adobe said in its security advisory released Tuesday. The company did not credit any organization or researcher who found the zero-day vulnerabilities, but credited IBM X-force for reporting the third security hole..

Adobe security engineers at the RSA Conference also declined to provide any additional information. “The exploit for Cve 2013-0643 and CVE 2013-0648 is designed to target the Firefox browser,” Adobe said in the advisory. Attackers could trigger the vulnerabilities to cause Flash Player to crash and gain remote control of the computer, Adobe said. The zero-day bugs are related to a permissions issue with the Flash Player Firefox sandbox and a flaw in the ExternalInterface ActionScript feature, which can be exploited to execute malicious code. The third, currently not yet being exploited, bug was a buffer overflow vulnerability in a Flash Player broker service, and could be used to execute malicious code, Adobe said. The update affects all versions of Flash on Windows, Mac OS X, and Linux. Users can download the latest version from the Adobe website, or turn on background updates and let the software grab the version automatically. Google and Microsoft will update Flash on Chrome and Internet Explorer 10 (for Windows 8) separately.







« Corsair H90 Gets Tested and a Review · Adobe Patches Flash Bugs, Attackers Targeted Firefox Users · 3DMark 11 is now fully compatible with Windows 8 »

2 pages 1 2


Veeshush
Senior Member



Posts: 1095
Joined: 2010-11-28

#4541871 Posted on: 03/02/2013 11:22 AM
I find this compliments Noscript on Firefox for plugin security:
https://blog.mozilla.org/security/2012/10/11/click-to-play-plugins-blocklist-style/

At the moment, click-to-play blocklisted plugins is a security feature that protects against drive-by attacks targeting plugins that are known to be vulnerable. It does not prevent attacks where a user is convinced to activate a vulnerable plugin on a malicious site. It also is not an all-purpose plugin management system.

This feature is enabled by default, so users are automatically protected. For the adventurous, the about:config preference “plugins.click_to_play” can be set to true to enable click-to-play for all plugins, not just out-of-date ones. However, this aspect of the feature is still in development


tsunami231
Senior Member



Posts: 12990
Joined: 2003-05-24

#4542364 Posted on: 03/03/2013 12:45 AM
this update to flash seems to of fix the whole issue of FF freezing a few seconds when loading heavy websites, with lots of things being loaded. Which in turn would freeze everything else like games in windowed fullscreen while FF was frozen for those few seconds. Atlest I have yet to see it happen this update.

2 pages 1 2


Post New Comment
Click here to post a comment for this news story on the message forum.


Guru3D.com © 2022