Critical Hole Found in Flash Player

Tushar Teredesai <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
Macromedia warned Monday of what it called a critical security flaw in 
the latest version of its Flash animation player and advised users to 
install a new version that it released on the Web to fix the problem.

The vulnerability affects the integrity of the player's "sandbox," which 
is supposed to act as a cordoned-off area where Flash code retrieved 
from the Web can be run safely, without access to a user's files. The 
flaw could allow a malicious hacker to run native code on a user's 
computer, outside the sandbox, possibly without the user's knowledge, 
according to information on the company's Web site.

No users had reported having being affected by the problem as of Monday 
evening, a Macromedia representative said. Nevertheless, the company 
advised users to download a new version of the player--version 
6.0.79.0--from its Web site immediately.

As well as fixing the latest vulnerability, the new version serves as a 
cumulative patch, fixing other security flaws 
<http://www.pcworld.com/news/article/0,aid,108033,00.asp> reported since 
the product's release, including memory buffer overflows, Macromedia 
said. It also offers other tweaks intended to boost performance of the 
product.

-- 
Tushar Teredesai
   http://www.linuxfromscratch.org/~tushar/
   http://www.geocities.com/tushar/


-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.