ZDNet UK


Skip to Main Content

  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Macromedia Flash has critical vulnerability

Tom Espiner ZDNet.co.uk

Published: 07 Nov 2005 17:10 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Internet Explorer and Opera users have been urged to upgrade to protect against a newly discovered flaw.

The vulnerability, in Flash Player version 7.0.19.0 and earlier, could allow a hacker to compromise a user's PC.

Macromedia confirmed the existence of the flaw, which it classified as critical, on Friday afternoon. It recommends the users upgrade to version 8.0.22.0.

"There was a problem with bounds validation for indexes of certain arrays in Flash Player 7 and earlier, thus leaving open the possibility that a third party could inject unauthorised code that would have been executed by Flash Player," Macromedia warned.

To see more details on the vulnerability, and download the updated version, click here. Security firm Secunia also classifies the vulnerability as highly critical.

"The Flash Player plug-in is used by more people than [just those using] Internet Explorer," said Thomas Kristensen, Secunia's chief technical officer. According to Secunia, only those who use the IE and Opera Web browsers are vulnerable to the Macromedia flaw, since other browsers, such as Firefox, do not include Flash player in their default set-up.

Kristensen added that he was surprised that Macromedia had issued the patch on Friday afternoon, as many potential victims might have been returning home and not learned about the problem until Monday, or later.

"The bad guys have had a whole weekend to write exploits," Kristensen said.

eEye Digital Security, a research firm, says it told Macromedia about the existence of the flaw on 27 June.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
112 out of 233 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Sentry Posts Blog

Police seize phone-gun

Italian police have seized a gun disguised as a mobile phone, according to a report on Gizmodo. The phone can hold four bullets, and is powerful enough to kill somebody. Gizmodo... More

3 comments

Gov't loses a PC a week

The government averaged losing one PC per week over the last year, according to figures collated by the Conservatives. A Friday report by the Press Association said that Tory front-bencher... More

1 comment

The Technological Singularity

Are we approaching a point when machines may wake up and become self or seemingly self aware? Vernor Vinge in 1993 seemed to think so. He refered to this event as the "technological... More

5 comments