RSS RSS Twitter Twitter
macnn

04/10/2008, 11:05am, EDT

Thursday, April 10th

Adobe closes critical Flash exploit

Adobe has released an update for its ubiquitous Flash Player, addressing a critical security vulnerability. The v9.0.124.0 patch specifically targets an exploit related to Shockwave (SWF) files; in order to be affected, a user must load a malicious SWF file within Flash Player, which in turn gives hackers the ability to run authorized code on a computer. The vulnerability exists in Flash Player versions 9.0.115.0 and 8.0.39.0, and all prior incarnations. The update is available for all operating systems supported by Flash and browsers including Firefox, Opera and more.

Contained in the fix is a new feature, called cross-domain policy check. The Flash Player uses policy files to grab content from other domains, but although this enables advanced functions, it is possible for hackers to create their own policy files. If these files receive acceptance from the appropriate server, SWF files can then be used to load content from outside an official server's domain.


Filed under: security, software
Other story tags: Adobe, Flash

, , comment, del.icio.us, slashdot, digg, buzz , Twitter



post a comment
Reader Reactions (Please use <i></i> for italic text)

subscribe to comments
for this article




Expand All   Global Settings
Be the first to post comments on this story.
Your Comments

In order to post comments: If you are a registered member, please login with your MacNN Forums username and password otherwise please uncheck the checkbox below.


Registered Member?
macnn forums login:

macnn forums password:

Not a member of the MacNN forums? Register now for free.

RSS Feeds

Have the latest content delivered to your desktop via RSS. Use the links below to get access to a specific blog, news, or reviews feed.



  MacNN -all

  MacNN Reviews

  MacNN Podcasts

  iPodNN

  Electronista

  Left Lane News
Want To Sell Your Laptop? Any Condition - receive Top Cash. Get an instant quote. Free shipping www.CashForLaptops.com

Internet Marketing School - 100% Online: Master SEO, SEM, E Commerce, Media & More with a U of San Francisco Certificate.

Buy from The Apple Store, iTunes.com, Amazon.com, TechDepot, OfficeDepot, Computers4Sure, or donate.