-
1. Re: Shockwave Flash has crashed - 27.0.0.170
jeromiec83223024Oct 16, 2017 2:52 PM (in response to upn0rth)
2 people found this helpfulThanks, and sorry for the inconvenience. We're aware of the issue and are investigating to see if we can provide some relief.
For background, to address the security issue discovered in the wild that prompted this release [1], we more tightly enforce rules in the initial validation of the SWF bytecode. For some reason, the SWF that VMWare uses is failing those validation checks.
This has always been the case, but weren't treating the validation failure as fatal, and would apply some more nuanced heuristics. We're now aborting immediately at the validation failure to ensure that we're addressing the entire set of possible related issues.
It's not immediately clear why it happens to be this particular SWF, but it's old, and there's the possibility that a compiler bug or third-party toolchain created some invalid bytecode that wouldn't normally exist in an equivalent SWF compiled from a newer toolchain.
We're now looking to see if we can be a little more surgical and allow this content to run normally again, now that we've made it through the immediate priority of addressing the vulnerability being abused in the wild. We'll be happy to update the thread as we have new information about the availability of a fix, etc. In the meantime, we'd strongly recommend using Flash Player 27.0.0.170 for general browsing, and keeping a dedicated VM or browser with Flash Player 27.0.0.156 for the specific task of accessing this content.
[1] Adobe Security Bulletin APSB17-32 - https://helpx.adobe.com/security/products/flash-player/apsb17-32.html
-
2. Re: Shockwave Flash has crashed - 27.0.0.170
upn0rth Oct 16, 2017 3:42 PM (in response to jeromiec83223024)Thank you very much. Is there a timeline for an updated release that handles the validation for VMWare?
-
3. Re: Shockwave Flash has crashed - 27.0.0.170
jeromiec83223024Oct 16, 2017 4:02 PM (in response to upn0rth)
Without a fix committed and tested, any guess I gave you about when the patch would land wouldn't be very meaningful. The target would be to drop something as soon as possible in a beta as pain relief and shoot for November's patch Tuesday as the mainstream release vehicle, but the most important thing is that we maintain the integrity of the mitigation we've deployed for the security issue.
-
4. Re: Shockwave Flash has crashed - 27.0.0.170
haroldg95709523 Oct 17, 2017 7:52 AM (in response to jeromiec83223024)I am one of the UI managers at VMware. How can we help you with this? Can we instrument our code or do anything else to help isolate the issue?
-
5. Re: Shockwave Flash has crashed - 27.0.0.170
jeromiec83223024Oct 17, 2017 2:30 PM (in response to haroldg95709523)
1 person found this helpfulThanks for reaching out! I think we're actually okay at this point.
We checked in a candidate fix late yesterday. The builds ran overnight, so we'll start evaluating them today. Assuming that both the functional fix and original security mitigation pass muster (I'm fairly confident they will), it should land in a beta early next week. We have some external operational constraints that preclude doing a drop sooner.
In terms of what happened, there's a java-style idiom that you use (presumably for library versioning) that uses undefined functions (i.e. functions with blank bodies) that are called repeatedly. When compiled, this resulted in bytecode that was getting flagged. We've been able to safely make affordances for it. This approach seems to be pretty rare (the number of distinct SWFs impacted appears to be very small at this point), but whenever we ding a relatively obscure edge case like this, it's invariably an important enterprise application that breaks.
-
6. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
madmax5657682 Oct 17, 2017 11:50 AM (in response to jeromiec83223024)Hi,
How do you revert to version 27.0.0.159 when I don't have it. I uninstalled and reinstalled flash but doesn't help.
Also looking at this workaround Shockwave Flash crashes with vSphere Web Client 6.x (2151945) | VMware KB didn't help, same issue.
I can't wait until November to have see if something works.
Thank you
-
7. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
upn0rth Oct 17, 2017 12:09 PM (in response to madmax5657682)1 person found this helpfulThe archived versions can be found at https://helpx.adobe.com/flash-player/kb/archived-flash-player-versions.html
-
8. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
madmax5657682 Oct 17, 2017 1:54 PM (in response to upn0rth)thanks upn0rth. I downloaded it. Uninstalled the current version, rebooted and installed 27.0.0159 and worked again in Chrome.
-
9. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
charlesb55271113 Oct 18, 2017 11:36 AM (in response to jeromiec83223024)Like madmax, we too are not in a position to wait for November. We have 2000 users unable to access their vApps + VM consoles through vCloud Director right now. Downgrading flash to the vulnerable version in our enterprise is not an option.
-
10. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
buzz3791 Oct 18, 2017 11:48 AM (in response to jeromiec83223024)Has this issue been assigned a bug in https://tracker.adobe.com?
A comment on the Chrome bug
references this Adobe bug FP-4198653...
-
11. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
upn0rth Oct 18, 2017 12:02 PM (in response to upn0rth)1 person found this helpfulI can confirm that 27.0.0.180 allows access to vCloud. The install was downloaded from Adobe Flash Player 27 Beta page.
Download Adobe Flash Player 27 Beta for Desktops - Adobe Labs
-
12. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
charlesb55271113 Oct 18, 2017 12:11 PM (in response to upn0rth)Interesting. Its release notes state:
Known Issues
Oct 17, 2017
Flash Player Flashplayer quits unexpectedly when logging into VCD (Virtual Cloud) Portal(FP-4198649)
-
13. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
maria__Oct 18, 2017 12:21 PM (in response to charlesb55271113)
27.0.0.180 fixes the vCloud/vSphere crash and is now available from the labs page link, posted in comment #11
-
14. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
mg40 Oct 19, 2017 1:57 AM (in response to upn0rth)does it also fix the same problem with vmware vcenter flash client?
-
15. Re: Shockwave Flash has crashed - 27.0.0.170
denism30607946 Oct 19, 2017 3:15 AM (in response to upn0rth) -
16. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
tfencl Oct 19, 2017 3:27 AM (in response to mg40) -
17. Re: Shockwave Flash has crashed - 27.0.0.170
maria__Oct 19, 2017 7:16 AM (in response to denism30607946)
Microsoft embeds Flash Player in IE and Edge on Windows 10, as such, the standalone installer does not work, and all Flash Player updates for IE/Edge are released by Microsoft via Windows Update. You'll need to use a different browser until this fix is in the release channel and Microsoft releases the update.
-
18. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
bob_down Oct 19, 2017 9:12 AM (in response to upn0rth)Because of vulnerabilities in previous versions we had been setting our clients to auto-update automatically. This just goes to show that trying to be proactive isn't always the best option. We lost access to our VCentre, thank fully we had a RemoteApp that is a sterile environment. Damned if you do, damned if you don't.
-
19. Re: Shockwave Flash has crashed - 27.0.0.170
denism30607946 Oct 19, 2017 9:28 AM (in response to maria__) -
20. Re: Shockwave Flash has crashed - 27.0.0.170
maria__Oct 19, 2017 9:56 AM (in response to denism30607946)
1 person found this helpfulThat's for Windows 7 and below.
I thought there was a comment on the labs page about the ActiveX Control being for Windows 7 and below, but don't see it. I have submitted a query to the folks who maintain that page.
-
21. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
tapokoh98116643 Oct 20, 2017 5:15 AM (in response to denism30607946)Correct. and unless you have Firefox installed, you don't need flash activeX nor the ( flash plugIn for Firefox) starting from Windows 8.1
-
22. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
madmax5657682 Oct 23, 2017 9:35 AM (in response to maria__)I don't see any 27.0.0.180 in that web page in commment #1. It shows 170 which is the one causing all the trouble:
https://helpx.adobe.com/security/products/flash-player/apsb17-32.html
-
23. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
maria__Oct 23, 2017 9:38 AM (in response to madmax5657682)
27.0.0.180 is a beta release, which fixes the VMWare crashing issue. Since it's a beta release, it's not listed on the security bulletin page.
-
24. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
coreys75070144 Oct 23, 2017 10:24 AM (in response to maria__)@ m_vargas Any idea when 27.0.0.180 is going to go from beta to production? We don't really want to uninstall 170 and then install a beta product, I would rather keep it production and just get a new build for production release. Do you have an ETA?
-
25. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
maria__Oct 23, 2017 1:36 PM (in response to coreys75070144)
We're aiming for an update posted to adobe.com on Wednesday, barring unforeseen issues between now and then. We can't speak to when Google (Chrome) or Microsoft (Win8.x/10 for IE/Edge) would release the update.
-
26. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
Divya_GuptaOct 25, 2017 1:44 AM (in response to upn0rth)
1 person found this helpfulHi,
27.0.0.183 fixes the crash and is now available.
Please go to get.adobe.com/flashplayer to download the latest version.
We can't speak as to when Google (Chrome) or Microsoft (Win 8.x/10 for Edge/IE) would release the update.
Thanks!
-
27. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
タカハシヒロシ Oct 25, 2017 2:48 AM (in response to upn0rth)I installed the latest 27.0.0.183, but the flex application crash in IE11 will reoccur.
It was fixed in 27.0.0.180 beta.
Please help me.
-
28. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
jeromiec83223024Oct 25, 2017 9:52 AM (in response to タカハシヒロシ)
Can you provide a link to your flex application?
-
29. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
タカハシヒロシ Oct 25, 2017 5:40 PM (in response to jeromiec83223024)I can not publish the link of my Flex application because it is internal use, but it occurs in Flash Player Help (https://helpx.adobe.com/flash-player.html ). I attached a screenshot.
-
30. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
jeromiec83223024Oct 25, 2017 7:55 PM (in response to タカハシヒロシ)
I don't believe this is the same issue. A crash dump would be helpful in understanding what's happening, since we can't debug it directly.
Please see the following guide on how to report a crash or error:
https://helpx.adobe.com/flash-player/kb/report-flash-player-crash.html
-
31. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
タカハシヒロシ Oct 25, 2017 9:07 PM (in response to jeromiec83223024)Bug report was added. I was able to attach DxDiag.txt and screenshot but iexplore.exe.5908.dmp does not seem to be attached. This label name is not displayed. iexplore.exe.5908.dmp has 374 MB but can you attach it to bug report?
-
32. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
jeromiec83223024Oct 26, 2017 9:53 AM (in response to タカハシヒロシ)
For large files, you can simply post them to a file sharing service, like Dropbox, Adobe Send and Track, Google Drive, Microsoft OneDrive, etc., and just post a public link.
-
33. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
charlesb55271113 Oct 26, 2017 1:46 PM (in response to Divya_Gupta)Just wanted to thank the Adobe staff for jumping on this and getting a beta and general release out in a timely manner.
-
34. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
jeromiec83223024Oct 26, 2017 1:48 PM (in response to charlesb55271113)
Much appreciated, glad we could help!
-
35. Re: Shockwave Flash has crashed - 27.0.0.170 - VMWare
タカハシヒロシ Oct 26, 2017 6:43 PM (in response to jeromiec83223024)There is no way to upload large files outside the company because it is our company's compliance violation. Looking at the answer to the thread "Flash Player crash introduced in 27.0.0.159 persists in 27.0.0.183, but is fixed in beta builds", in 27.0.0.180 beta, since the phenomenon that "Flash Player Help" crash in IE 11 does not occur, Wait for the next cycle release.
thanks a lot.
-
36. Re: Shockwave Flash has crashed - 27.0.0.170
denism30607946 Oct 31, 2017 1:07 AM (in response to upn0rth)This problem is not solved yet for Internet Explorer...
It's very important to solve this issue for IE because this is the only browser in which VMware Client Integration Plug-in (CIP) works...