Critical Hole Found in Flash Player
Tushar Teredesai <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
Macromedia warned Monday of what it called a critical security flaw in the latest version of its Flash animation player and advised users to install a new version that it released on the Web to fix the problem. The vulnerability affects the integrity of the player's "sandbox," which is supposed to act as a cordoned-off area where Flash code retrieved from the Web can be run safely, without access to a user's files. The flaw could allow a malicious hacker to run native code on a user's computer, outside the sandbox, possibly without the user's knowledge, according to information on the company's Web site. No users had reported having being affected by the problem as of Monday evening, a Macromedia representative said. Nevertheless, the company advised users to download a new version of the player--version 6.0.79.0--from its Web site immediately. As well as fixing the latest vulnerability, the new version serves as a cumulative patch, fixing other security flaws <http://www.pcworld.com/news/article/0,aid,108033,00.asp> reported since the product's release, including memory buffer overflows, Macromedia said. It also offers other tweaks intended to boost performance of the product. -- Tushar Teredesai http://www.linuxfromscratch.org/~tushar/ http://www.geocities.com/tushar/ -- Unsubscribe: send email to [email protected] and put 'unsubscribe lfs-security' in the subject header of the message