Krb5 and Flash

Hi all,

Like most people I suspect, I received a Krb5 security notification today (unless it was triggered by some anti-hacker tweaks I did today).

I like the idea of Krb5… upon installation, an Adobe Flash Player licensing agreement form was presented to me. I declined to this. There are so many bugs in Flash on the Windoze side, that I do not trust it at all (this is a security update? oops). I received a very nasty virus in My space. com running Windoze. I suspect that it was built into Flash- McAfee could not even detect it, nevermind removing. There are approx. 40 threads concerning problems with Flash in the forums here.

Is there a way to install Krb5 but avoid Flash?

I am trying to understand your question / situation here…

You received a notice that there some security patches available for install, I think there were more than one (krb patches and some for adobe flash), but I guess you only saw the one for krb (I doubt krb needs adobe flash).

And you chose to cancel the update because of flash.

If you are sure you do not want adobe flash patched, you can manually update from yast (manually select patches) and choose the ones to install and deselect flash update.

I really do not understand why you would do that: you already have adobe flash player installed and the version you have is vulnerable - choosing not to update / patch it would be bad for you.

Cheers

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Agreed; I think this was coincidence and another patch may be trying to
pull in flash. None of krb5’s dependencies show anything browser-related
from what I can tell:

rpm -q --requires krb5

Good luck.

On 05/26/2010 07:06 AM, ghostintheruins wrote:
>
> I am trying to understand your question / situation here…
>
> You received a notice that there some security patches available for
> install, I think there were more than one (krb patches and some for
> adobe flash), but I guess you only saw the one for krb (I doubt krb
> needs adobe flash).
>
> And you chose to cancel the update because of flash.
>
> If you are sure you do not want adobe flash patched, you can manually
> update from yast (manually select patches) and choose the ones to
> install and deselect flash update.
>
> I really do not understand why you would do that: you already have
> adobe flash player installed and the version you have is vulnerable -
> choosing not to update / patch it would be bad for you.
>
> Cheers
>
>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.12 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQIcBAEBAgAGBQJL/R/pAAoJEF+XTK08PnB5Q6MP/A236M7OFAGNTHdLmcfvrCPA
hWtYd3ea0Sxk6VQ2tWWliWo1lkUYts5qnugH3Mh1TNozVvbXV3GnaG0tNJiwNAKM
VB+GCKi7eMFq6xxoadyXcFtMakH+eHK4x7v9d94Vt++zM7Ksad+a0L3g5WxzBbZI
zr/vrweJAqmNmPudMSW9OtgMqEOO+9JobCR5x3TadQw6nBmcZ+B/yggWGeylr3MZ
+y/hmcPYM0mycDnVitqbVG/umg0zpP8bV86T4H5U5E4TRdwE9OMCm5JGJEYNJB5q
nOrD2snlPx3UJ23APByHG8gTVO9hTBpma5o5GGPU9VbcJGFtgmIPozCShNDwU1K7
X2UuqhfsJ2/oEwki0bnwuceox6HCr3xABoYnMTV3UQlabBguFI8Puacv4Bw7jQ4k
ptufJQZ8nqsc7GX1/xpwZZ1czlHjrNceZBe5HSXzHs5Cq1duXtDoWjY+cI2DuYL7
UJlKs3ju/s57fMoIX5Pn59m170CPHY8Hai0adjVUWfmH4BUFfv6NaNgBT4WoXoKJ
mrnCLSpYAMefN6tLx7Ux0cX+KjG/Sv9eFkjFDq/bAXGWIj3E8iy1+cxYW5rcI6kJ
zi5A2Nd6xum//6AipGn7Hzi34AukheOsnxFWO6XAO7PRyeHnc5AUu7YK8TUCN2q6
JcBWK3z72egCsLUiTd9x
=gJRx
-----END PGP SIGNATURE-----

To Ghost and ab,

Thank you for your response. I think I know what happened. If I am accurate, you both guessed the scenario. I did have Adobe Flash installed at one time. I decided against it and consequently removed it from Mozilla in browser ‘Manage Content Plugins’ option. Somehow the string ‘install Adobe Flash’, (did not pay that much attention to it- could have been 'Remove Adobe Flash) appeared in my Software Update list. When the Krb5 and other upgrade packages were displayed - the Krb5s were at the top of the list. I think that somehow that Adobe Flash string got ‘caught in’ with the Krb5s as an upgrade, even though it was not displayed as an item to be upgraded. When the licensing agreement form was displayed, the Flash and also whatever else was selected as an upgrade was cancelled by me.

Today I clicked on the two Krb5 upgrades in Software Update - Only the Krb5 packages installed rather smoothly and quickly. No licensing prompts were displayed. I looked in Mozilla - Tools | Manage Conten Plugins, and found VLC Multimedia Plugin - Flash Video listed only.

I hope that the above makes sense. If you have any questions, or if something is unclear, please let me know.

Removing it (flash) from firefox plugins (disableing the plugin) does NOT uninstall the software from your system.

If you did not un-install it from the software manager you still have it on your system and needs patching. Otherwise there would be no notice regarding patching.

So I still suggest - either uninstall it from yast / zypper or patch it.

Cheers.