Adobe Plugs Critical Flash Vulnerability

By the Betanews Staff | Published March 15, 2006, 3:04 PM

Adobe on Tuesday issued a security advisory urging all Macromedia Flash users to upgrade to version 8.0.24.0. The company says it has identified "critical vulnerabilities" in Flash Player that could lead to a full system compromise. The flaw can be exploited through a malicious SWF file.

The problem, which discovered and reported by Microsoft, affects all operating systems. Adobe has made available updates for a number of its products that include Flash, such as Breeze, Shockwave and Flex. Fixed versions of Flash 7 for Linux and Solaris are also available for download.

Comments

View comments by with a score of at least

adobe plugs critical flash vulnerability? lol

Score: 0

|

Hurry! You won't want to miss a single flash ad. This tags right along with Java when I have to work on a system.

Straight to the bitbucket.

Score: 0

|

Why does the DLL file for the plugin say its from Jan 2 2006?

I checked in Seamonkey, Firefox, and Opera, and all of their DLLs are from the same date.

Score: 0

|

Ya, it's not apparent. What is apparent is how many ads are .swf files. It's a big vulnerability anytime something like .swf is compromised.

Score: 0

|

Also the security announcement doesn't state a priv escalation or if the exploit will just be run at the user's perm levels? Important distinction. One I scramble on, the other I basically ignore.

Score: 0

|

Does anyone see architectural issues with a browser plug-in even having the capability of compromising a system?

Score: 0

|

Yes. If you're so inclined, you can download 912945 on Windows updates. Then you can see what happens. =)

Effectively, if you give an application the ability to upload or scan your tree, this stuff is inherent.

Score: 0

|

Don't forget to de-select the Yahoo toolbar option. It's selected to install by default. Bastiges.

Score: 0

|

Sometimes I think Flash vulnerabilities are used for pushing new versions more than anything.

Score: 0

|

It definitely seemed that way with the release of Flash 8.

Score: 0

|

Will Firefox beat IE9 to Direct2D rendering?

Just days after Microsoft executives gave conference attendees a peek at a new rendering technology, a Mozilla contributor revealed he's working on the same thing.

AOL's decision to rebrand as Aol. takes a bad brand and makes it worse

The idea behind the social Web is to crowd source before bringing out something new. But not at AOL, which new logo debuted with a cry of "fail!" across the blogosphere and Twittersphere today.

Microsoft's Bob Muglia and Ray Ozzie on Silverlight vs. standards

Bob Muglia: "We're trying to provide people with an environment that has capabilities that you just simply can't do today in the standards-based world."

Uh-oh, netbooks -- not Windows 7 -- will lift 2009 PC sales

Santa may bring a lump of coal to the Windows PC industry this holiday season. Netbook sales will sap PC margins, while weak Windows 7 PC sales could further drive down average selling prices.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.

Action Replay maker sues Microsoft for Xbox 360 'predatory technological barriers'

Third-party video game accessory maker Datel has filed an antitrust lawsuit against Microsoft over the Xbox 360's recent Dashboard update.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

Microsoft's .NET Micro Framework is now free and open source

The latest version of Microsoft's .NET Micro framework is now in the hands of the FOSS community.

Google's value proposition for Chrome OS: Should we feel insulted?

For a search engine that has direct access to all the world's online history, it appears to have taught Google nothing about selling a machine.

E-book readers will be in short supply this holiday season

E-readers are hot this year, and a lot of compelling new products have been released, but are there enough electrophoretic displays to go around?