FirefoxAndAdobeFlashNPAPI

Firefox blocks Adobe Flash NPAPI plugin for 11.2.202.481 and earlier

Several serious security vulnerabilities were found in Adobe's flash plugin with exploits known to be in the wild. Because of the critical nature of the vulnerabilities, the Mozilla foundation decided to block this version of the plugin. Unfortunately, at the time of the blocklist, only the PPAPI version of the plugin (as used by chromium) was available and Firefox users found the NPAPI plugin was blocked via Firefox's click-through security mechanism.

UPDATE: As of 2015/07/16, Adobe released 11.2.202.491 which fixes all known issues for PPAPI and NPAPI and updates are available for Ubuntu

Timeline

  • 2015 Jul 14: Adobe releases flash plugin security update for PPAPI ahead of NPAPI

  • 2015 Jul 14: Ubuntu Security contacts Adobe regarding NPAPI. Ubuntu told NPAPI plugin will be ready soon
  • 2015 Jul 14: Ubuntu releases adobeflash-plugin and flashplugin-nonfree with updates for PPAPI only
  • 2015 Jul 16: Adobe releases updates for NPAPI (11.2.202.491)
  • 2015 Jul 16: Ubuntu releases adobeflash-plugin and flashplugin-nonfree with updates for NPAPI (11.2.202.491), including the previous PPAPI fixes

SecurityTeam/KnowledgeBase/FirefoxAndAdobeFlashNPAPI (last edited 2015-07-16 13:36:40 by jdstrand)