Closed Bug 968726 Opened 12 years ago Closed 10 years ago

Need better ways for detecting flash version on linux

Categories

(Plugin Check Graveyard :: UI, defect)

x86
Linux
defect
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: cbook, Assigned: espressive)

References

Details

Attachments

(1 file)

seems we have a problem with flash on linux. actual version is 11.2.202.336 but plugincheck detected the latest version as 11.2.202.0 and the versions before too, so we need to find a way to detect the version properly expressive, do you know who could be a good contact for this ?
There is a lot of work being done here: https://bugzilla.mozilla.org/show_bug.cgi?id=956905 and here: https://bugzilla.mozilla.org/show_bug.cgi?id=938885 This might very well have an effect on this, but I cannot be 100% until we are done with the work that is currently underway.
Adobe started adding the plugin version to their Linux builds only recently, but now the .version field should be correct: navigator.mimeTypes['application/x-shockwave-flash'].enabledPlugin.version "11.2.202.310"
Blocks: 990857
(In reply to Benjamin Smedberg [:bsmedberg] from comment #2) > Adobe started adding the plugin version to their Linux builds only recently, > but now the .version field should be correct: > > navigator.mimeTypes['application/x-shockwave-flash'].enabledPlugin.version > "11.2.202.310" yeah but that doesn't work on plugincheck sadly :( i tested again with the plugin and plugincheck (and even sandbox to make sure its just not my entry in the database or so). And the issue is still that the way plugincheck detects plugins is showing for flash on linux 11.2.202.0 - and ignores basically that i have 11.2.202.350 and need to be fixed like mentioned in comment #1 The of course bad thing is that we are having the problem here to flag security updates not on a subversion area below 11.2.202.X like the 350 vs 356 Version. Not much i can do here sadly :( So its the way broken how we detect flash
Carsten, I don't understand comment 5. When you say "it doesn't work on plugincheck" do you mean that the code snippet I provided doesn't return the correct results (it does in all of my testing)? Or that plugincheck is not using the code snippet I provided? If the latter, this bug should be about using the code snippet I provided.
(In reply to Benjamin Smedberg [:bsmedberg] from comment #6) > Carsten, I don't understand comment 5. When you say "it doesn't work on > plugincheck" do you mean that the code snippet I provided doesn't return the > correct results (it does in all of my testing)? Or that plugincheck is not > using the code snippet I provided? > > If the latter, this bug should be about using the code snippet I provided. Oh i guess its more that plugincheck is not using the code snippet and so detects the versions not with complete version information
See screenshot; with today's nightly (Build identifier: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:32.0) Gecko/20100101 Firefox/32.0) on Windows 7, and: File: NPSWF32_13_0_0_206.dll Path: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll Version: 13.0.0.206 State: Enabled Shockwave Flash 13.0 r0 Adobe says I'm up-to-date, but plugin check says it's outdated.
(In reply to Stephen Donner [:stephend] from comment #8) I find that Adobe update the 'flash/about' page http://www.adobe.com/software/flash/about/ as soon as there is an "Adobe Security Bulletin". For example: > Security updates available for Adobe Flash Player > Release date: May 13, 2014 > Vulnerability identifier: APSB14-14 http://helpx.adobe.com/security/products/flash-player/apsb14-14.html The 'flash/about' page also has the benefit of listing all the 'current versions' (for different OS and browser). In bug https://bugzilla.mozilla.org/show_bug.cgi?id=956905#c128 there is discussion about the fact that Adobe sometimes use DIFFERENT version numbers for 'current versions'. (source bug 956905 comment # 128) > From 2014-01-14 (APSB14-02) > http://helpx.adobe.com/security/products/flash-player/apsb14-02.html > > Until 2014-02-04 (APSB14-04) [for 3 weeks] > http://helpx.adobe.com/security/products/flash-player/apsb14-04.html > > The main versions of Flash were: > Windows (Internet Explorer), 12.0.0.38 > Windows (Firefox), 12.0.0.43 > Macintosh (Firefox), 12.0.0.38 > Linux (Firefox), 11.2.202.335 > > Also > Flash ESR (Windows and Macintosh), 11.7.700.260 > Shockwave (Windows and Macintosh), 12.0.7.148 > > I cite Flash because it is: > ubiquitous, frequently updated, has an 'ESR version' and is often being exploited in the wild. > It is a hard case (puns intended). So, I find http://helpx.adobe.com/flash-player.html less useful (because it is not always updated quite so rapidly). However, in Stephen Donner's example (comment # 8) Adobe were correct and plugincheck was wrong. Carsten Book did not add Flash 13.0.0.214 until "2014-05-14 00:02:36 PDT" see https://bugzilla.mozilla.org/show_bug.cgi?id=1010085 DJ-Leith
(In reply to Stephen Donner [:stephend] from comment #8) On reflection, I think the phenomena you have witnessed and documented is more likely to be an example of (or 'side effect of') bug 1008321. It might be an example of bug 1010132 "Flash 13.0.0.206 shown as up to date" In the sense that, I paraphrase: 'Flash detection and reporting at plugincheck is not consistent'. However, I think it more likely to be bug 1008321 - "/plugincheck page not working in Firefox > 30". Chronology helps: > Security updates available for Adobe Flash Player > Release date: April 8, 2014 > Vulnerability identifier: APSB14-09 http://helpx.adobe.com/security/products/flash-player/apsb14-09.html Carsten Book [:Tomcat] 2014-04-08 06:09:37 PDT opens bug 993385 - "update flash to 13.0.0.182". Bob Clary [:bc:] 2014-04-08 10:30:37 PDT opens bug 993530 - "Update plugincheck for Flash for Win/OSX 13.0.0.182; Linux 11.2.202.350". Bob Clary has doubts about the Linux. > Security updates available for Adobe Flash Player > Release date: April 28, 2014 > Vulnerability identifier: APSB14-13 http://helpx.adobe.com/security/products/flash-player/apsb14-13.html Carsten Book [:Tomcat] 2014-04-28 09:19:46 PDT opens bug 1002536 - "update for flash 13.0.0.206". Alex Gibson [:agibson] 2014-05-09 11:12:10 PDT opens bug 1008321 - "/plugincheck page not working in Firefox > 30". Stephen Donner [:stephend] 2014-05-12 14:01:31 PDT adds comment # 8 to this bug with the helpful screenshot: https://bug968726.bugzilla.mozilla.org/attachment.cgi?id=8421255 This is BEFORE Adobe's announcement and BEFORE the 'update to the plugin database' which took place on 2014-05-14 00:02 PDT. > Security updates available for Adobe Flash Player > Release date: May 13, 2014 > Vulnerability identifier: APSB14-14 http://helpx.adobe.com/security/products/flash-player/apsb14-14.html Carsten Book [:Tomcat] 2014-05-14 00:02:36 PDT opens bug 1010085 - "update flash for 13.0.0.214" (from comment # 9) > However, in Stephen Donner's example (comment # 8) Adobe were correct > and plugincheck was wrong. because APSB14-14 (Flash 13.0.0.214 for Windows and OS X, 11.2.202.359 for Linux) was RELEASED after comment # 8 was posted. So *this* bug: "Need better ways for detecting flash version on linux" is still valid. DJ-Leith
Hey all and thanks for all the input and feedback. I have set-up a bunch of VMs for testing and will spend most of today testing various scenarios in an attempt to weed out most if not all of these problems. As with the other bug related to Flash [https://bugzilla.mozilla.org/show_bug.cgi?id=1010132] I will update this one once I complete testing.
Assignee: nobody → schalk.neethling.bugs
Status: NEW → ASSIGNED
I have this same problem on my Arch Linux machine (Flash 11.2.202.400, Nightly 34.0a1). This started happening about a month ago, I would say. No flash will run in the browser either.
To clarify, it seems that mine IS detecting the latest and correct version of flash, but plugin check says it is vulnerable and will not run any flash.
No longer blocks: 968722, 990857
Component: plugins.mozilla.org → UI
Product: Websites → Plugin Check
QA Contact: cbook
Hey All, Can someone please take plugin check for a test run again, in Firefox, and let me know whether this is still problematic or whether it identifies and classifies Flash correctly. Thanks!
Closing this as there has been no reports of problems for a very long time. Please feel free to reopen if there is still problems out there in the wild.
Status: ASSIGNED → RESOLVED
Closed: 10 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: