| there is vulnrebility this should be fun
FLASH 6 VULNERABILITY
Jarle Dahl Bergersen
The previous version of the Flash 6 player (revision 23) has a ActiveX flaw that could expose Flash users to hacks
ZDNet writes about a buffer overflow vulnerability in the previous version of the Flash 6 player (revision 23), the overflow allows for attacks via some HTML e-mail clients and when visiting malicious web sites. The problem only exist for Internet Explorer on the Windows platform.
ZDNews reports that Marc Maiffret, chief hacking officer at eEye, attributed the Macromedia Flash flaw to a buffer overflow vulnerability connected to an ActiveX control called Flash.ocx.
If you haven't already, its a good idea to update to the latest version of the Flash 6 player - the update fixes the overflow vulnerability, and also fixes some other serious bugs in the Flash 6 revision 23 player. |