Advertisement
Promo

Security threats Toolkit

Adobe fixes flaws in Flash Player, ColdFusion

David Meyer ZDNet.co.uk

Published: 07 Nov 2008 12:19 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Adobe has released fixes for security flaws in its Flash Player and ColdFusion application server.

The software maker released the updates on Wednesday. According to Adobe, the critical vulnerabilities were identified in Flash Player 9.0.124.0 and earlier versions, and the fixes do not apply to those who have already upgraded to version 10.0.12.36. Users who cannot move to Flash Player 10 can get a patched version of its predecessor, version 9.0.151.0.

On the release of the free download of Flash Player 10 in October, Adobe claimed that more than 98 percent of internet-enabled desktops use the multimedia and web-application player, and that more than 80 percent of videos watched online are delivered using the product.

One of the Flash Player fixes changes the way the application interprets HTTP response headers, so as to prevent cross-site scripting attacks. Others aim to stop potential DNS rebinding attacks, HTML injection "issues" and non-root domain policy bypasses. Two of the patches are targeted at stopping information disclosure that could take place through the Flash Player ActiveX control and the software's interpretation of jar: protocols in Mozilla browsers.

The vulnerability in ColdFusion, Adobe's web-application development software, "could allow a lower-privileged user to bypass sandbox security and access sensitive information, and could potentially lead to a privilege escalation attack", Adobe said on Wednesday. Although the flaw is not remotely exploitable, the company has warned that it is "particularly applicable to ColdFusion servers in a shared hosting environment".

Adobe has identified ColdFusion 8, ColdFusion 8.0.1 and ColdFusion MX 7.0.2 Solution as vulnerable products, and has issued a hot fix that can be downloaded from the company's security site.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters