Help - Search - Members - Calendar
Full Version: Adobe Shockwave for Director
Malwarebytes Forum > Updates and Alerts > Security Software Updates
Jacktivity
Adobe has released a critical security advisory for Shockwave for Director.

QUOTE
Security updates available for Shockwave Player
Release date: November 3, 2009

Vulnerability identifier: APSB09-16

CVE number: CVE-2009-3244, CVE-2009-3463, CVE-2009-3464, CVE-2009-3465, CVE-2009-3466

Platform: Windows and Macintosh


Summary
Critical vulnerabilities have been identified in Adobe Shockwave Player 11.5.1.601 and earlier versions. The vulnerabilities could allow an attacker, who successfully exploits the vulnerabilities, to run malicious code on the affected system. Adobe has provided a solution for the reported vulnerabilities. It is recommended that users update their installations using the instructions provided below.


Affected software versions
Shockwave Player 11.5.1.601 and earlier versions




To update your version:

Begin by uninstalling the old version.
  • Download the uninstaller
  • Before beginning , close all open applications, including your Web browsers.
  • Double click to run the program and follow the prompts. It will remove Shockwave Flash for Director from all browsers and any applications that use it.


Download and Install the new version
For Windows 98/2000/XP/Vista/Win7
  • Download the installation file
  • Before beginning, close all applications and open Web browsers.
  • Double click the downloaded file to begin the installation.
  • Follow the prompts.
  • Note: When presented with a screen for the optional Norton scan, click the check box to turn it off.

You can test your installation here
If you see animation in the box, then your installation was successful.
noknojon
@ Jacktivity -
Even though I have followed these instructions and, the 'wording' over the Flash Wave says I have updated, I still can not get the wave to move - huh.gif
I have D/loaded it several times and get a message that I have the latest, (even words over the wave) yet it is still only version 10.0.32.18 -shown in my documents - Have I missed anything ?? unsure.gif (I did delete old version first) -
(XP - SP3 - Desktop)
mountaintree16
Thanks for the update, Jacktivity! I'll update as soon as possible. For now, I have disabled it in my plug-in list.
catscomputer
QUOTE (noknojon @ Nov 7 2009, 11:06 AM) *
@ Jacktivity -
Even though I have followed these instructions and, the 'wording' over the Flash Wave says I have updated, I still can not get the wave to move - huh.gif
I have D/loaded it several times and get a message that I have the latest, (even words over the wave) yet it is still only version 10.0.32.18 -shown in my documents - Have I missed anything ?? unsure.gif (I did delete old version first) -
(XP - SP3 - Desktop)


Hi there. I think Adobe Shockwave Director and Adobe Flash Player are two different things. It's very confusing because the Firefox plugin for Flashplayer is called Shockwave Flash - but I believe that is actually Flashplayer and not Shockwave Player. 10.0.32.18 is the latest version for Flashplayer. If you go to this page http://www.adobe.com/products/ you will see icons to click on for get flashplayer & for get shockwave player, clicking on those icons will take you to more info about the version numbers & what you have installed on your system.

(I'm sure someone will correct me if I am wrong!)
mountaintree16
@ catscomputer & noknojon

I took this screen shot of my plug-ins (for Firefox anyway, as I rarely use IE) for clarification of what each looks like smile.gif

Hope it helps!
catscomputer
Ah there you go. Thanks Mountaintree. I suspected as such... I don't have Shockwave, only Flash player so couldn't say what the plugin for the actual shockwave was called in FF. It is confusing for people to called the flash player plugin "shockwave", don't you think? It's like Javascript and Java - two TOTALLY different things.
mountaintree16
You're welcome Catscomputer smile.gif I kinda figured it out on my own after a while, by the numbers, but I was confused by it at first too, and I agree, it is DEFINITELY confusing. I don't know why its called that in the plug-in list.

Oh, hehe, I don't really know the difference too well between Javascript and Java, well, I kinda do, but not really. I should probably learn that too tongue.gif hehe.
Jacktivity
QUOTE (noknojon @ Nov 6 2009, 02:06 PM) *
@ Jacktivity -
Even though I have followed these instructions and, the 'wording' over the Flash Wave says I have updated, I still can not get the wave to move - huh.gif
I have D/loaded it several times and get a message that I have the latest, (even words over the wave) yet it is still only version 10.0.32.18 -shown in my documents - Have I missed anything ?? unsure.gif (I did delete old version first) -
(XP - SP3 - Desktop)


Hi noknojon -

catscomputer is right -

You've gotten the regular Adobe Flash Player confused with the Macromedia Shockwave player - which is very easy to do. I will be the first to admit that they can be confusing and with both of them installed, I can't tell the difference in a browser when one is running or the other. The version number you are referring to is the current regular Adobe Flash version.

It certainly doesn't help that in the add-ons manager of Internet Explorer, the regular old flash is called the Shockwave Flash Object and the other (Shockwave for Director) is called Shockwave ActiveX Control. If you right click and select More Information on each of them you will see they are both ActiveX controls. The regular flash add-on refers to file name Flash10c.ocx and the Shockwave Director add-on refers to file name SwDir.dll.

Even in Firefox, it's a little confusing on the plug-ins page. Regular Flash is called Shockwave Flash, and the other is called Shockwave for Director.

A good part of this confusion can be attributed to Adobe who bought out Macromedia in 2005. In my opinion, they've gotten a little sloppy with the "Shockwave" term. Here's a little history of Macromedia and the Shockwave name at Wikipedia if you are interested.

Here's a quick comparison chart at Adobe.
Here's a better verbal comparison at Adobe.

For simplicities sake, think of *.FLV (Flash Video) files as regular Flash and *.SWF files as Shockwave for Director.

Here's a little more information on FLV files and SWF files at File-Extensions Org.

What documents are you referring to with that version number? do you mean the browser add-ons control page?
If you go to the test page I linked to at the end of the first post, you should get two separate animations if you have both the Adobe Flash Player, and Shockwave for Director Player installed. One should be stacked above the other.

The top one has a text label that says Adobe Shockwave Player (what this post originally referred to) The actual graphic should say Macromedia Shockwave Player and give the version number of 11.5.2r602.

The bottom one should have a text label of Adobe Flash Player. The actual graphic should say Macromedia Flash Player without a version number.

Not confusing at all, right? tongue.gif

If you use Firefox and the NoScript add-on, then you must allow scripts to run on that page or you won't see the graphics.


Hey - as I'm writing this, you guys are getting ahead of me. Every time I do a post preview, I see another response. I actually started writing this before catscomputer posted. I modified mine a little to acknowledge/include that post. laugh.gif laugh.gif
Anyway, this will at least give you some more background.
mountaintree16
Thanks for the additional info, Jacktivity.

Super confusing at first though (not what you posted, Shockwave vs Flash hehe).

Oh, and if you didn't see already, I posted a screenshot of my Firefox plugins to show the difference between the two for anyone that might need a visual smile.gif
catscomputer
Thanks Jacktivity - that's a very comprehensive reply and explains it well. Glad I wasn't putting anyone wrong there.

I appear to have Shockwave Active X installed in IE. I never use IE and I have that particular plugin disabled, so I won't worry about updating mine unless I happen to use IE & it tells me that Macromedia is needed for something. That shouldn't leave me vulnerable in the mean time in any way should it?
Jacktivity
@mountaintree16 - I see that you DID include a screen shot. I considered doing that myself, but you were to quick for me. As it was, if I had taken any longer, you guys would have figured it all out on your own and I'd have been useless. laugh.gif

@catscomputer - No, you didn't steer anyone wrong. As for your add-on in IE, unlike the Adobe Flash Player add-on that requires different installers for Internet Explorer and Firefox, this one just uses the same installer for both. I've never done an uninstall and re-install of an add-on that was disabled, but I'm assuming the disabled add-on is just removed and replaced as if it were not disabled. You can check this for yourself very easily. Even a disabled add-on still shows the installed version number. Regardless, as long as it is disabled, you have nothing to worry about.
mountaintree16
@Jacktivity

Yep. I like taking screen shots sometimes, hehe.

Ah stoppit, you wouldn't have been useless! Don't say that smile.gif You had some very useful information on this topic, and of course we are very grateful for the initial announcement! biggrin.gif
noknojon
QUOTE (noknojon @ Nov 7 2009, 09:06 AM) *
@ Jacktivity -
Even though I have followed these instructions and, the 'wording' over the Flash Wave says I have updated, I still can not get the wave to move - huh.gif
I have D/loaded it several times and get a message that I have the latest, (even words over the wave) yet it is still only version 10.0.32.18 -shown in my documents - Have I missed anything ?? unsure.gif (I did delete old version first) -
(XP - SP3 - Desktop)

Sorry that I have not been able to respond sooner - I wrongly worded my answer (flash/shock) but it was the 'Shockwave' that I have now downloaded 4 times -
The wave will still not 'wave' at me even after the 4th time I downloaded - Even from the 'critical updates' area I hit that update - I must be doing something wrong but it is late here and I will try again to uninstall all the downloads I have and see if I can get it right (it must just be me) -
Jacktivity
@noknojon -

It might be that all we have here is a misunderstanding about what is animated. The graphic logo does not wave on this test page. The animation can be seen when you hover the mouse over the hotspot buttons labeled Create See About.
noknojon
So if those 3 'buttons' are active then it is completed wink.gif - I get that and they show further info if you want !! smile.gif
Thanks for all that Jack - Sorry we (me) misunderstood - blush.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.