- Recommend:
- 0 Comments
Security Flaw Found in Flash Files
Vulnerability could be exploited anytime a Web browser views the infected files.
A security hole in the widely used Macromedia Flash file format used with Web browsers can allow an attacker to execute code of their choice on affected systems, according to a new security alert released Friday by eEye Digital Security.
The vulnerability is limited, however, to Flash files edited by hand with a binary editor, meaning that the Flash application will not produce files that contain the vulnerability on its own, according to a separate security alert from Macromedia, which is based in San Francisco.
Browser-Based
The vulnerability is serious because it affects Web browsers, which are trusted by firewalls to receive incoming traffic, and because it affects all versions of Flash used in the Internet Explorer and Netscape Navigator Web browsers running on both Windows and Unix, eEye says.
The flaw comes as the result of a problem in the data header of Flash files which allows an attacker to supply more data to the file decoder than is expected and in turn can eventually lead to code execution, eEye says.
Because the vulnerability is browser-based, it can be exploited in any situation in which a Web browser views a Flash file, such as on Web pages, in e-mail, or newsgroups, eEye writes.
Fixing the Problem
Macromedia has released a new Flash player that addresses the flaw and is available on Macromedia's Web site. More information about the vulnerability is also located at on the site.
EEye, which has found numerous other vulnerabilities in applications like Microsoft's Internet Information Services, discovered another security hole in Flash in May.
More Macromedia bug reports are likely to come, though, as eEye warns in its alert that it had found about 17 other vulnerabilities in Flash.
Would you recommend this story? YES NO
- Recommend:
- 0 Comments
-
ThinkPad Edge E420 Lenovo Style in an Affordable Package
Buy now direct from Lenovo -
ThinkPad X220 Fast and light, with great input ergonomics and battery life, this powerhouse ultraportable is best-of-breed.
Buy now direct from Lenovo -
ThinkPad X120e One of the best netbooks ever, X120e has the best netbook keyboard ever--nothing else comes close
Buy now direct from Lenovo
- Adobe Gives Users Control of Privacy with Flash Player 10.3
- Adobe Updates Acrobat, Reader to Guard against Flash Zero-Day
- Adobe Patches Flash Zero-Day: Deja vu All Over Again - Part 2
- How to Quit Flash: A Three-Step Program
- Urgent: Patch Adobe Flash to Protect against Zero-Day Exploit
- Skype iPhone, iPod Touch App Has Security Hole
- Attacks Use IE to Exploit Windows MHTML Flaw
- 12 Criteria for Selecting the Best ERP System Replacement An ERP system is your information backbone and reaches into all areas of your business and value chain. Replacing it can open unlimited business opportunities. This white paper explains the 12 criteria that allow you to identify and select the solution that will meet these expectations.
- Leveraging Social Computing Technologies for ERP Applications This white paper details how Web 2.0 technologies support business strategies by improving efficiency, productivity, and collaboration.














