Original URL: http://www.channelregister.co.uk/2007/12/20/adobe_flash_security_update/
Adobe has published an update (http://www.adobe.com/support/security/bulletins/apsb07-20.html) fixing numerous security vulnerabilities in Adobe Flash.
Earlier versions of Flash prior to 9.0.115.0 on multiple platforms (Mac OS, Linux, Windows) are subject to various security bugs (http://secunia.com/advisories/28161) that create the possibility of all sorts of mischief, including cross-site scripting attacks and information disclosure attacks. Denial of service or code injection attacks may also be possible. Several of the issues addressed involve input validation errors, which could allow an attacker to execute arbitrary code after tricking users of vulnerable Flash clients into opening content on maliciously-constructed websites.
Separately Adobe also patched (http://www.adobe.com/support/security/bulletins/apsb07-17.html) bugs in its GoLive HTML editor. Exploitation of the bugs involves tricking a user into including crafted BMP, DIB, RLE or PNG content into a GoLive document. That's not the easiest exploit scenario but, since the flaws carry the possibility of injecting malicious code onto vulnerable systems, worth guarding against nonetheless. ®
Buggy Flash code continues to plague the web (27 March 2008)
http://www.channelregister.co.uk/2008/03/27/buggy_flash_menace/
Adobe hands Kevin Lynch keys to CTO door (6 February 2008)
http://www.channelregister.co.uk/2008/02/06/adobe_kevin_lynch_cto/
Major HTML update unveiled (22 January 2008)
http://www.channelregister.co.uk/2008/01/22/html_five_preview/
Stay ahead of Web 2.0 worms (7 January 2008)
http://www.channelregister.co.uk/2008/01/07/xss_tactics_strategy/
Google researcher calls for Flash flush (2 January 2008)
http://www.theregister.co.uk/2008/01/02/buggy_flash_fix/
Serious Flash vulns menace at least 10,000 websites (21 December 2007)
http://www.channelregister.co.uk/2007/12/21/flash_vulnerability_menace/
With one bound, Apple is free of 54 security bugs (15 November 2007)
http://www.channelregister.co.uk/2007/11/15/behemoth_apple_patch_batch/
We'll beat Microsoft and Sun, says Adobe's chief software architect (18 October 2007)
http://www.theregister.co.uk/2007/10/18/adobe_air_platform-ambitions/
Flash flaw may prompt Wii to 'hang' (24 July 2007)
http://www.reghardware.co.uk/2007/07/24/flash_wii_flaw/
Adobe takes on Java and .NET (6 February 2007)
http://www.theregister.co.uk/2007/02/06/adobe_flex_apollo/
Adobe patches Acrobat, Reader flaws (17 December 2004)
http://www.theregister.co.uk/2004/12/17/adobe_patches_bugs/
© Copyright 2008