Top Stories
|
Adobe plugs multi-platform Flash vulns20 Dec 2007 11:19 A patch in time...Adobe has published an update fixing numerous security vulnerabilities in Adobe Flash. Earlier versions of Flash prior to 9.0.115.0 on multiple platforms (Mac OS, Linux, Windows) are subject to various security bugs that create the possibility of all sorts of mischief, including cross-site scripting attacks and information disclosure attacks. Denial of service or code injection attacks may also be possible. Several of the issues addressed involve input validation errors, which could allow an attacker to execute arbitrary code after tricking users of vulnerable Flash clients into opening content on maliciously-constructed websites. Separately Adobe also patched bugs in its GoLive HTML editor. Exploitation of the bugs involves tricking a user into including crafted BMP, DIB, RLE or PNG content into a GoLive document. That's not the easiest exploit scenario but, since the flaws carry the possibility of injecting malicious code onto vulnerable systems, worth guarding against nonetheless. ® 6 comments posted — Comment period finished Old news?Posted: 12:42 20th December 2007 Flash oooeeeooo, savour of the universePosted: 13:55 20th December 2007 @archiePosted: 19:17 20th December 2007 surprisingPosted: 01:44 21st December 2007 @archiePosted: 10:45 21st December 2007
Track this type of story as a custom Atom/RSS feed or by email. Related storiesBuggy Flash code continues to plague the web (27 March 2008)
|
Breaking Hardware News
When Nvidia - allegedly - entered into an anti-Atom alliance with VIA, it was really preparing the ground to improve its negotiations with Intel. Allegedly. So say the latest rumours about rumours about rumours.
Newsletter |