toggle

AAPL Stock: 436.36 ( -4.99 )

http://www.macnn.com/articles/08/04/10/adobe.fixes.flash.exploit/

Adobe closes critical Flash exploit

updated 11:05 am EDT, Thu April 10, 2008

 

Adobe fixes Flash exploit


Adobe has released an update for its ubiquitous Flash Player, addressing a critical security vulnerability. The v9.0.124.0 patch specifically targets an exploit related to Shockwave (SWF) files; in order to be affected, a user must load a malicious SWF file within Flash Player, which in turn gives hackers the ability to run authorized code on a computer. The vulnerability exists in Flash Player versions 9.0.115.0 and 8.0.39.0, and all prior incarnations. The update is available for all operating systems supported by Flash and browsers including Firefox, Opera and more.

Contained in the fix is a new feature, called cross-domain policy check. The Flash Player uses policy files to grab content from other domains, but although this enables advanced functions, it is possible for hackers to create their own policy files. If these files receive acceptance from the appropriate server, SWF files can then be used to load content from outside an official server's domain.


by MacNN Staff

Post tools:

TAGS :

 security, software, Adobe, Flash
toggle

Comments

Login Here

Not a member of the MacNN forums? Register now for free.

 
close
Photo
toggle

Network Headlines

toggle

Most Popular

MacNN Sponsor

Recent Reviews

MaxUpgrades MaxConnect for 2006-2008 Mac Pro

Nobody outside of Cupertino's privileged bunch knows the future of the Mac Pro line for sure. Despite Apple's reluctance to tell us wh ...

Brother HL-3170CDW LED Printer

We've mentioned before that we are far from a paperless society. For now, at least, there are tasks that require a piece of paper for ...

HTC One

It is hard to overstate just how critically important the HTC One is to the Taiwanese company’s fortunes. Despite its alarming decline ...

toggle

Most Commented