Graphic Design Blog > US-CERT Vulnerability Note VU#204889
[US-CERT Recently Published Vulnerability Notes] . This ActiveX control contains a use-after-free vulnerability, which can result in heap memory corruption. Note that this vulnerability does not affect systems that have Flash 9 or later installed, as newer versions of the Flash installer will replace the Macromedia Flash control that is provided by Windows.
[Previous] Macromedia Flash 8.0 - GFXnew -Yor Best GFX Place...
[Next] Friday Fresh Free Fonts #31 | Abduzeedo | Graphic De...
Some related posts from Technorati and Google.
[gHacks technology news] Install Adobe Flash Without Adobe DLM: Make sure to check for updates after the installation to verify that the latest version of Adobe Flash has been installed (one option to verify that is to look at the version number of the plugin in Firefox and compare that to the latest version posted on the Adobe website).
[eggheadcafe.com Security Posts] insecure Adobe Flash file in Security Home Users: I notice that at the Secunia forum back in March one person said the following: one called flash10b.ocx but for some reason, the a file is not deleted when Flash is updated and it seems to be what PSI is looking at." Does this seem like a reasonable thing to do? Interestingly, at this point I have these two files in the indicated folder: Flash10b.ocx Flash10d.ocx Would it be worth renaming the first file to .
[Simple Thoughts - Java and Web Blog] Sony to support SD flash memory cards, not just home-brewed ...: Sony finally settles the class action lawsuit filed in California caused by their highly controversial decision to install a rootkit for DRM protection of their music CDs. If you are a Sony CD customer read the full details below to claim your rights.
[Windows BBS] [Resolved] AdobeFlashPlayer/cabinstaller/inf HELL: Description Provided by CVE) : Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 on Windows allows remote attackers to obtain the names of local files via unknown vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4820.
[The Technology Library] Free Download: Video tutorial Linux computer based training Debian ...: Examine Nessus process utilization while vulnerability scans are in progress Lockdown (Debian GNU/Linux System Lockdown) Explain potential network-based entry points to the system Identify superfluous daemons/services using NETSTAT & NMAP .
[InsideRIA] Top security threats to Flash/Flex applications and how to avoid ...: An application may be hosted on a server where the Cross-domain policy allows loading a remote SWF and then have unintended access to the loader's domain and data. If the loading SWF loads the remote SWF into its security domain, then the loaded SWF could gain access to the parent SWF's data, modify properties, and even send that information back to an attacker.
[AppDeploy Package KB] AppDeploy > Package Knowledgebase > Macromedia Shockwave Player: Should you need to install just Flash Player 6 (Active X version), Flash Player 6, or Shockwave; you can run the extracted installers individually.
[SecurityLab.ru] (MS06-069) Vulnerabilities in Macromedia Flash Player from Adobe ...: If you are using any of the Windows versions called out in Which versions of the Flash Player are redistributed with Windows? you can visit Windows Update to receive security updates for these versions of Windows. If you use any other supported Windows version, or if you are using Flash Player 7 and higher, you can visit the Adobe download center as called out under the affected software section of the Adobe security bulletin to install the update
[Persian Networks] ÙÛÙÙ Ø¢Ù ÙØ²Ø´Û -Video tutorial LinuxCBT Debian 3 Edition - Persian ...: Computer based Training Planet offers comprehensive computer training and blended learning solutions that enable individuals and enterprise organizations alike to receive the training they need efficiently. Dozens of options exist ranging from IT certification boot camps such as the MCITP 2008 boot camp and self-study CBTs to online computer training and onsite training programs.
[Download Free Ebook Video Training] Download Free Ebook Video Training » Blog Archive » Video tutorial ...: Computer based Training Planet offers comprehensive computer training and blended learning solutions that enable individuals and enterprise organizations alike to receive the training they need efficiently. Dozens of options exist ranging from IT certification boot camps such as the MCITP 2008 boot camp and self-study CBTs to online computer training and onsite training programs.
[Hacking Accounts] Hacking Accounts » Blog Archive » Web 2.0 Security Testing Approach: Somnath has been working as an Information Security Consultant iViZ Techno Solutions,India and have successfully carried out countless assignments on vulnerability assessment, penetration testing, web application security, Threat modeling,PCI DSS Compliance for various Banking sector firms, financial institutions, Govt. organizations, Defense, Software development Companies, leading BPOs and various small-mid-large industries.He holds security certifications like OSCP and CNSM.
[Basic Warez Blog] Microsoft Windows XP Professional SP3 Integ. November 2009: 923561 - MS09-010: Vulnerability in WordPad and Office text converters could allow remote code execution * 923789 - MS06-069: Vulnerabilities in Macromedia Flash Player from Adobe could allow remote code execution .
[from.hell] sqli webgames and tools (owasp repost) - from.hell: http://www.macromedia.com/software/flash/about/ Test your installation of Java software - http://java.com/en/download/installed.jsp?detect=jre&try=1 WebPageFingerprint - Light-weight Greasemonkey Fuzzer - http://userscripts.org/scripts/show /30285 ... Php-Brute-Force-Attack Detector - Detect your web servers being scanned by brute force tools such as WFuzz, OWASP DirBuster and vulnerability scanners such as Nessus, Nikto, Acunetix ..etc. ...
[Bardissi Enterprises Blog] Flash Player Update Fixes Pwn2Own Zero Day Vulnerability ...: If your user plays the file, Flash’s lack of input validation enables the attacker to execute code on that user’s computer, with that user’s privileges. Since most Windows administrators grant their users local administrative privileges, an attacker could potentually exploit these flaws to gain complete control of a victim’s computer.
[Serge Jespers] Update on Flash Player vulnerability | Serge Jespers: The malicious SWF file found in-the-wild has been found to affect Adobe Flash Player 9.0.115.0 and earlier, not the latest version 9.0.124.0. Originally this issue was believed to be unpatched and unknown, but further technical analysis has revealed that it is the previously reported Adobe Flash Player Multimedia File Remote Buffer Overflow Vulnerability (BID 28695), discovered by Mark Dowd of IBM.
[CNET News.com] Firefox, Adobe top buggiest-software list | InSecurity Complex ...: but there are also the custom tools promoted by free products and that violate your privacy: 'Yahoo!' is probably the worst in this game of who will jeopardize your PC and monitor everything you do on your PC, as it does not even evaluates and revokes the usage rights from many third-parties that are customizing the Yahoo toolbar for their own promotion and to gain some pennies from ads or for modifying the content of results displayed in your favorite search engine, just to force you do adopt very unsecure programs that will just steal your money)
Reflected tags on Technorati: Blog, Macromedia, Graphic Design Blog