Re: More SWF vulnerabilities?

From: the Pull (osioniusxat_private)
Date: Tue Mar 19 2002 - 23:58:51 PST

  • Next message: Wojciech Purczynski: "Bypassing libsafe format string protection"

    --- Drew Daniels <umdanie8at_private> wrote:
    > 
    > 
    > Vulnerable systems: unpatched "standalone Flash 
    > players" (Macromedia Shockwave Flash player 
    > versions before January 2002?)
    
    <snip>
    
    The first article (from McWilliams at Newsbytes),
    states that:
    
    "Neither the new vulnerability nor January's
    SWF/LFM-926 virus affects the millions of users of
    Macromedia's browser-based Flash plug-in or ActiveX
    control. Those players do not have access to special
    commands, and Flash files played back through a
    browser are secure, according to Macromedia. "
    
    ..
    
    "'Since these flaws only affect the authorware version
    of Flash, it's unlikely they'll be exploited in a
    widespread way,' said Coursen." 
    
    
    
    > 
    > From:
    > http://cartome.org/flash-hole.htm
    
    <snip>
    
    __________________________________________________
    Do You Yahoo!?
    Yahoo! Sports - live college hoops coverage
    http://sports.yahoo.com/
    



    This archive was generated by hypermail 2b30 : Wed Mar 20 2002 - 12:38:17 PST