Closed
Bug 978505
Opened 12 years ago
Closed 11 years ago
Mozilla plugincheck says latest Flash Player 11.7 (Extended Support Release) is vulnerable and tells me to update
Categories
(Websites :: plugins.mozilla.org, defect)
Websites
plugins.mozilla.org
Tracking
(Not tracked)
RESOLVED
WORKSFORME
People
(Reporter: mustafacan, Unassigned)
References
Details
User Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:27.0) Gecko/20100101 Firefox/27.0 (Beta/Release)
Build ID: 20140212131424
Steps to reproduce:
Mozilla.org plugincheck found on this URL: https://www.mozilla.org/plugincheck/ says me my Flash player plug-in is vulnarable, but I already have latest security updates released. (I have version 11.7.700.269 which is released on 2/20/2014 installed, latest on 3/2/2014)
Steps to reproduce:
1) Install latest version of Flash Player 11.7 (Extended Support Release)
2) Visit https://www.mozilla.org/plugincheck/
What happened?
Plugin check page shows vulnerable on the status section
What should have happened?
Plugin check page should'nt show my plug-in vulnerable because latest security updates are installed.
| Reporter | ||
Updated•12 years ago
|
Component: Untriaged → General
OS: Windows 8.1 → All
Product: Firefox → www.mozilla.org
Hardware: x86_64 → All
Version: 27 Branch → Production
Updated•12 years ago
|
Component: General → plugins.mozilla.org
Product: www.mozilla.org → Websites
QA Contact: cbook
Version: Production → unspecified
Comment:
I imagine tracking the "Extended Support Release" versions of Plugins as well as the 'more popular versions' is not easy.
Adobe's very useful test page
http://www.adobe.com/software/flash/about/
lists the current versions of the 'more popular versions' of Flash.
In my opinion, it would be good to include "Extended Support Release" versions of Plugins
but this should be a lower priority than the 'more popular versions'.
"Archived Flash Player versions"
http://helpx.adobe.com/flash-player/kb/archived-flash-player-versions.html
has the link for "(Released 2/20/2014) Flash Player 11.7.700.269 (140.37 MB)"
From my reading in Bugzilla I believe that Carsten Book [:Tomcat] knows more than most about the database so I am CC'ing him.
mustafacan please read "RFE an "About plugincheck" page, visible from plugincheck" bug 965812
where there is more information about the changes that are being made to the 'plugincheck service'.
In my opinion, if bug 965812 was worked on (after bug 956905 but before bug 938885) it would help users to know:
* What the 'new (28+) plugincheck service' can test / assess and
* What the 'new (28+) plugincheck service' can NOT test / assess.
I will, in bug 965812, cite this bug as an example of where an "About plugincheck" page could be very useful.
DJ-Leith
Comment 2•12 years ago
|
||
This came up in the support forum:
https://support.mozilla.org/en-US/questions/989281 Plugin check incorrectly marks flash ESR as "vulnerable"
Note http://helpx.adobe.com/security/products/flash-player/apsb14-07.html dated February 20, 2014:
"For users of Flash Player 11.7.700.261 and earlier versions for Windows and Macintosh, who cannot update to Flash Player 12.0.0.44, Adobe has made available the update Flash Player 11.7.700.269, which can be downloaded here."
The "here" link is missing but the latest Adobe Flash Player 11.7 ESR download is currently 11.7.700.269 and is available from http://www.adobe.com/products/flashplayer/distribution3.html
Comment 3•12 years ago
|
||
there is working going on in plugincheck currently see https://bugzilla.mozilla.org/show_bug.cgi?id=968726
Updated•12 years ago
|
Summary: mozilla.org plugincheck says latest flash update is vulnarable and tells me to update → Mozilla plugincheck says latest Flash Player 11.7 (Extended Support Release) is vulnerable and tells me to update
Comment 4•12 years ago
|
||
Confirmed in Firefox 24-ESR, 11.7.700.269 is marked "vulnerable" while it's the most up-to-date version, see also https://support.mozilla.org/en-US/questions/989281
Comment 5•12 years ago
|
||
See bug 956905 comment 128 which refers to this bug.
Updated•12 years ago
|
Status: UNCONFIRMED → NEW
Ever confirmed: true
Comment 6•12 years ago
|
||
In plugincheck, Flash (13.0.0.214 - latest version) is displayed as vulnerable and outdated also with Fx 30 beta 8 (Build ID: 20140527133511) on Windows 7 32bit, Ubuntu 13.04 x64 and on a Microsoft Surface Pro 2 device running Windows 8.1 64bit:
Mozilla/5.0 (Windows NT 6.1; rv:30.0) Gecko/20100101 Firefox/30.0
Mozilla/5.0 (X11; Linux x86_64; rv:30.0) Gecko/20100101 Firefox/30.0
Mozilla/5.0 (Windows NT 6.3; WOW64; rv:30.0) Gecko/20100101 Firefox/30.0
Information from Adobe's web sites includes:
The "Adobe Flash Player Distribution" page
http://www.adobe.com/uk/products/flashplayer/distribution3.html
Has, for Linux:
"... Note: Flash Player 11.2 is the last supported Flash Player version for Linux OS. Adobe will continue to provide security updates. ..."
Has, for ESR:
"...
Flash Player 13.0.0.214 (Win and Mac)
Attention: Please read for important changes regarding Flash Player 11.7
Beginning May 13, 2014 we have updated the version of our "Extended Support Release" from Flash Player
11.7 to Flash Player 13 for Mac and Windows. To continue to stay current with all available security
updates, you will need to install the version 13 Extended Support Release or update to the most recent
available release. For full details, please see this blog post:"
The link leads to:
"Upcoming changes to Flash Player’s extended support release"
By Chris Campbell
March 5, 2014
http://blogs.adobe.com/flashplayer/2014/03/upcoming-changes-to-flash-players-extended-support-release.html
"Beginning May 13th, 2014, we will be upgrading Flash Player's extended support release from version 11.7 to version 13. This change impacts enterprise and IT customers that currently deploy Flash Player using the extended support releases available through our distribution channel. ..."
(In reply to Alexandra Lucinet, QA Mentor [:adalucinet] from comment #6)
> In plugincheck, Flash (13.0.0.214 - latest version) is displayed as vulnerable ...
For the issue of 'plugincheck not detecting correctly Flash on Fx 30 and above'
see also bug 1011824
"Plugin check page displays Flash plugin as vulnerable even if the latest version
is installed in Beta30b4, Aurora31.0a2 and Nightly32.0a1"
For tests being done, by Schalk Neethling [:espressive],
see bug 1010132 "Flash 13.0.0.206 shown as up to date"
Some of the results are reported in the 14th comment:
https://bugzilla.mozilla.org/show_bug.cgi?id=1010132#c14
DJ-Leith
Comment 8•11 years ago
|
||
11.7 is no longer the ESR branch, Adobe's current ESR branch is 13.0.x which plugin check now knows about.
Status: NEW → RESOLVED
Closed: 11 years ago
Resolution: --- → WORKSFORME
You need to log in
before you can comment on or make changes to this bug.
Description
•