Adobe Plugs Critical Flash Vulnerability

By the Betanews Staff | Published March 15, 2006, 3:04 PM

Adobe on Tuesday issued a security advisory urging all Macromedia Flash users to upgrade to version 8.0.24.0. The company says it has identified "critical vulnerabilities" in Flash Player that could lead to a full system compromise. The flaw can be exploited through a malicious SWF file.

The problem, which discovered and reported by Microsoft, affects all operating systems. Adobe has made available updates for a number of its products that include Flash, such as Breeze, Shockwave and Flex. Fixed versions of Flash 7 for Linux and Solaris are also available for download.

Comments

View comments by with a score of at least

adobe plugs critical flash vulnerability? lol

Score: 0

|

Hurry! You won't want to miss a single flash ad. This tags right along with Java when I have to work on a system.

Straight to the bitbucket.

Score: 0

|

Why does the DLL file for the plugin say its from Jan 2 2006?

I checked in Seamonkey, Firefox, and Opera, and all of their DLLs are from the same date.

Score: 0

|

Ya, it's not apparent. What is apparent is how many ads are .swf files. It's a big vulnerability anytime something like .swf is compromised.

Score: 0

|

Also the security announcement doesn't state a priv escalation or if the exploit will just be run at the user's perm levels? Important distinction. One I scramble on, the other I basically ignore.

Score: 0

|

Does anyone see architectural issues with a browser plug-in even having the capability of compromising a system?

Score: 0

|

Yes. If you're so inclined, you can download 912945 on Windows updates. Then you can see what happens. =)

Effectively, if you give an application the ability to upload or scan your tree, this stuff is inherent.

Score: 0

|

Don't forget to de-select the Yahoo toolbar option. It's selected to install by default. Bastiges.

Score: 0

|

Sometimes I think Flash vulnerabilities are used for pushing new versions more than anything.

Score: 0

|

It definitely seemed that way with the release of Flash 8.

Score: 0

|

Breakthrough: AMD and Intel settle antitrust dispute, reach new cross-license agreement

UPDATED Only exclusionary business practices, not some rebates, may be covered by a new agreement on Intel's future business conduct.

Windows Marketplace for Mobile now available in browser, iTunes' App Store still not

You can now check out what Windows Marketplace for Mobile has to offer without a Windows Phone.

Microsoft damage control after marketer claims Win7 inspired by Mac

Have you ever said anything you wish you could take back? Ever? No? Not even once? Well then, you won't sympathize with a mid-level Microsoft manager today.

Facebook for iPhone developer goes from Apple supporter to 'I quit!' in 3 months

Fed up with Apple's App Store policies, the developer of Facebook for iPhone has bailed on the iPhone.

Google acquires Gizmo5, builds IP telephony portfolio

Google Voice today confirmed rumors that it would acquire IP telephony company Gizmo5

'A pivot from war to peace:' The AMD + Intel armistice, in their own words

An extraordinary day in technology history is recognized by two long-time rivals that mutually decided it's futile to fight anyplace else except the marketplace.

PS3, Xbox to soon get Twitter, Facebook integration

Both Microsoft's Xbox 360 and Sony's PlayStation 3 will integrate with Facebook in the near future.

The iTunes App Store at 100,000: Can we stop counting, already?

Carmi Levy | Wide Angle Zoom: Is a six-digit number truly reflective of a healthy applications ecosystem? Or is it another type of bloat?

Analysis: The end of business-by-litigation?

The AMD v. Intel case ended neither with a bang nor a whimper, but almost with a song. Is it catchy enough for the rest of the PC world to sing in perfect harmony?

The agreement: Intel and AMD 'wipe the slate clean'

As the Securities and Exchange Commission document shows, AMD did indeed make some compromises in favor of Intel, especially with regard to conduct.

EC still holds Intel accountable even after AMD settlement

Though the future of relations between AMD and Intel may be peaceful now, the EC believes Intel may still owe restitution for its past conduct.