Flash Vulnerability Found, Adobe Says No Fix Forthcoming 355
Posted
by
timothy
from the more-from-the-slums-of-the-internet dept.
from the more-from-the-slums-of-the-internet dept.
An anonymous reader writes "Security researchers at Foreground Security have found an issue with Adobe Flash. Any site that allows files to be uploaded could be vulnerable to this issue (whether they serve Flash or not!). Adobe has said that no easy fix exists and no patch is forthcoming. Adobe puts the responsibility on the website administrators themselves to fix this problem, but they themselves seem to be vulnerable to these problems. Every user with Flash installed is vulnerable to this new type of attack and — until IT administrators fix their sites — will continue to be."
OH NO!!! (Score:4, Funny)
Someone has found an issue with Flash?! Say it isn't so...
Re:OH NO!!! (Score:5, Funny)
I lost count. Can someone help me out again? This time I'll count using Binary on my fingers.
iPhone (Score:5, Funny)
I'm very angry that I can't use this vulnerability on my iPhone.
Re:Client or server? (Score:4, Funny)
Apparently it's a server-side vulnerability, but this puts users at risk since hijacking trusted websites makes it much easier to socially engineer malware onto people's computers. I.e., if gmail were to be compromised, and you login to gmail and there's a link to download some special gmail-improving program, a lot of people will download and install it, even though it was placed there by a hacker and not Google themselves.
Warning - 2nd link points to a FLASH AD (Score:5, Funny)
Kind of ironic that an article that warns about flash vulnerabilities as:
Oh, wait - it's ComputerWorld. Sorry, I had my expectations too high.
We need to move beyond Flash (Score:5, Funny)
so we can have malware based on open standards.
Re:iPhone (Score:5, Funny)
I'm very angry that I can't use this vulnerability on my iPhone.
There is not an app for that?
Re:OH NO!!! (Score:5, Funny)
Re:OH NO!!! (Score:5, Funny)
I lost count. Can someone help me out again? This time I'll count using Binary on my fingers.
I tried that, but when I got to 132 vulnerabilities, I felt that was an appropriate enough representation of my opinion and stopped counting.
Re:Counting binary on your fingers. (Score:3, Funny)
I'll have to find the right web site to browse to in order to handle the carry
Re:OH NO!!! (Score:3, Funny)
Hmm... looks like you'll need 11 bits to count them all, so please do it in another room.
Re:iPhone (Score:1, Funny)
Droid Does!!
Re:OH NO!!! (Score:3, Funny)
More importantly, what about ECC?
I had a spasm in my left pinky and now I cant remember if its supposed to be bent or not.
Re:OH NO!!! (Score:5, Funny)
Useful, but make sure no one is right in front of you when you get to four or they might punch you.
Re:wait (Score:3, Funny)
This should all be so sandboxed and open sourced
Let some smart people around the world fix all this stuff
No bloat, faster, safer and Adobe can keep its secrets for media/vids ect.