Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Flash, bang, wallop - you're own3d
The Register ^ | 8 November 2005 | John Leyden

Posted on 11/08/2005 9:07:40 AM PST by ShadowAce

Security researchers have discovered a vulnerability in Macromedia's Flash Player that creates a mechanism for hackers to attack the PCs of users running the popular application. The security bug - described as critical - affect Macromedia Flash Player 6.x and 7.x. Macromedia has issued security updates.

The flaw stems from a failure to reject malformed SWF files as invalid. This bug might be exploited by using specially crafted (malformed) SWF file to execute arbitrary code on the machines of users induced into visiting sites under the control of hackers.

Click Here

Flash Player version 7.0.19.0 and prior on the Windows platform, and in versions prior to 7.0.25.0 on Unix, are reportedly vulnerable. Users are advised to upgrade to Flash Player 8 (8.0.22.0) or apply a Flash Player 7 update (7.0.61.0 or 7.0.60.0) in order to guard against possible attack. An advisory from Macromedia explaining the security glitch can be found here. The bug was independently discovered by Fang Xing of eEye Digital Security (advisory here) and Bernhard Mueller of SEC Consult (advisory here). ®


TOPICS: Technical
KEYWORDS: flaw; j00rpwn3d; macromedia; patch; yetanothermbug; yetanothermsbug

1 posted on 11/08/2005 9:07:41 AM PST by ShadowAce
[ Post Reply | Private Reply | View Replies]

To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...

2 posted on 11/08/2005 9:08:04 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce
Adobe buys Macromedia. Now both are own3d.


3 posted on 11/08/2005 9:11:39 AM PST by rdb3 (Get rid of all of the repetitive redundancy, why don't ya?)
[ Post Reply | Private Reply | To 2 | View Replies]

To: ShadowAce
This is why I don't run Flash or any other Macromedia crap in Firefox.
4 posted on 11/08/2005 9:16:34 AM PST by Doohickey (If you choose not to decide, you still have made a choice...I will choose freewill.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Doohickey

Yup--the more you block, the better off you are. With AdBlock, 95% of everything out there never reaches my machine.


5 posted on 11/08/2005 9:18:17 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 4 | View Replies]

To: ShadowAce

Whether you want Flash on your computer is one issue; but if you have it, this problem was fixed when Flash 8 was released, quite some time ago.


6 posted on 11/08/2005 10:02:58 AM PST by Cicero (Marcus Tullius)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

Macromedia : You got pwnt.


7 posted on 11/08/2005 10:05:58 AM PST by mysterio
[ Post Reply | Private Reply | To 2 | View Replies]

To: ShadowAce

PWND BY TEH L337 HAX0RZ!!


8 posted on 11/08/2005 10:26:19 AM PST by KoRn
[ Post Reply | Private Reply | To 1 | View Replies]

To: KoRn

"PWND BY TEH L337 HAX0RZ!!"

alright now, this is not the usenet stop it with the cripted stuff. i hate reading that crap.(grin)


9 posted on 11/08/2005 3:21:33 PM PST by postaldave (i've given up on being mad in exchange for bitter sarcasm.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: postaldave

where am i? slashdot?


10 posted on 11/08/2005 4:41:25 PM PST by kpp_kpp
[ Post Reply | Private Reply | To 9 | View Replies]

To: kpp_kpp

no, if we were at slashdot you would hear 50 posts how somehow this is bush's fault. i love the tech stuff but good god the moonbats over there are LOONS!!!!


11 posted on 11/08/2005 5:50:23 PM PST by postaldave (i've given up on being mad in exchange for bitter sarcasm.)
[ Post Reply | Private Reply | To 10 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson