May 28, 2008

Slashdot   Slashdot It!
Comments

SecurityFocus advisory yesterday (updated today): Adobe Flash Player SWF File Unspecified Remote Code Execution Vulnerability.

And currently from Symantec ThreatCon:

The DeepSight ThreatCon currently at Level 2 in response to the discovery of in-the-wild exploitation of a vulnerability affecting Adobe Flash Player. The flaw occurs when processing a malicious SWF file. Originally it was believed that this issue was unpatched and unknown, but further technical analysis has revealed that it is very similar to the previously reported Adobe Flash Player Multimedia File Remote Buffer Overflow Vulnerability (BID 28695), discovered by Mark Dowd of IBM. However, we are working with Adobe to identify the precise details, because we have observed the malicious files affecting patched versions of Flash, suggesting that it may be a variant or may have been incorrectly patched. We have begun to observe numerous attacks. [...MORE...]

Flash is teh 3\/iL.

Posted by: paranoid at May 28, 2008 12:14 PM
Post a comment









Remember personal info?




Comments must be previewed once before posting (this discourages automated posting).


Did you happen to see these?
Beer Over IP! - May 26, 2008
Running the Tables - Apr 11, 2008
Berkeley Wants to Tell You Jokes - Apr 10, 2008


Add Discourse.net to your RSS/RDF/XML reader: Full feed
Partial feed

Powered by Movable Type 2.64.


   out of