[prev in list] [next in list] [prev in thread] [next in thread] 

List:       emerging-sigs
Subject:    Re: [Emerging-Sigs] ET POLICY Outdated Windows Flash Version IE with Windows 8 and Windows 10
From:       Francis Trudeau <ftrudeau () emergingthreats ! net>
Date:       2016-02-08 19:26:11
Message-ID: CAA-Ja_7YC9rxouBOLOcaQfWcRoCj04KW8BNwDGAYQj17grjYuQ () mail ! gmail ! com
[Download RAW message or body]

Accidentally replied off list:

https://helpx.adobe.com/security.html#flashplayer

According to that the last security patches were in late December.  It
appears the January release didn't patch any vulns (that we know of).

2/9/16 appears to be when the new version is out for February.  I can
modify the sig to not fire on .272, but I would rather not since I am
not sure there were no security patches in there.

If the 2/9 date gets pushed back more, I will modify the sig to not
fire on .272, otherwise I will update it to reflect the new versions
when they come out.

Thanks,

Francis



On Fri, Feb 5, 2016 at 2:55 PM, Jeff H <jeff61225@gmail.com> wrote:
> I've been getting hits on this for Windows 8 and Windows 10 machines running
> Flash in IE.
>
> I verified that the machines are up to date via Windows Update. But their
> flash version is 20.0.0.272 and the sig is looking for 20.0.0.286. Then I
> found this stating that IE for Windows 8 and 10 wouldn't be getting this
> update and would instead get updated during the normal February patch.
> https://forums.adobe.com/thread/2069452?start=0&tstart=0
>
> I can't tell for sure if there were security fixed effecting the IE version
> in this release, but it doesn't look like it to me (no related security
> bulletin)
>
> Just wondering if anything can be done about this to prevent alerts when no
> patch is available? Or if this is such a rare occurrence that its better to
> just power through (as Flash will be patched in a few days and it will
> become a non-issue)
>
> Jeff
>
> _______________________________________________
> Emerging-sigs mailing list
> Emerging-sigs@lists.emergingthreats.net
> https://lists.emergingthreats.net/mailman/listinfo/emerging-sigs
>
> Support Emerging Threats! Subscribe to Emerging Threats Pro
> http://www.emergingthreats.net
>
>
_______________________________________________
Emerging-sigs mailing list
Emerging-sigs@lists.emergingthreats.net
https://lists.emergingthreats.net/mailman/listinfo/emerging-sigs

Support Emerging Threats! Subscribe to Emerging Threats Pro http://www.emergingthreats.net

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic