The Mudcat Café TM
Thread #107233   Message #2221823
Posted By: Bonnie Shaljean
24-Dec-07 - 07:56 AM
Thread Name: Tech: Flash player vulnerability
Subject: Tech: Flash player vulnerability
A vulnerability in Flash players has been discovered (info links below) so Firefox users might like to take a look at:

http://flashblock.mozdev.org

or

https://addons.mozilla.org/en-US/firefox/addon/4

The only thing I can think of offhand that I really USE a Flash player for is YouTube, and if you have Flashblock and want to play a YouTube clip, all you have to do is click on the little "f" icon that appears in the middle of the video box, so it seems a small hassle for the extra protection you get. I've only tried it with Firefox, as this is an FF add-on, but no complaints so far. It's a fast simple (free) download - and it saves you from being annoyed by all those animated adverts, which seem to be Flash's main purpose in life. Don't know what the story with IE is, nor if Safari (being a Mac application) is vulnerable.   

- - -

News item in The Register (http://www.theregister.co.uk/security)
http://www.theregister.co.uk/2007/12/21/flash_vulnerability_menace/

Blog:
http://stage.vambenepe.com/archives/140

SlashDot sez [excerpt]: Flash Vulnerabilities Affect Thousands of Sites
   http://it.slashdot.org/article.pl?sid=07/12/22/2240257   
The problem is compounded by the fact that some of the most
popular Web development tools for generating SWF produce files
containing the recently disclosed vulnerabilities ... which leave
thousands of websites susceptible to attacks that steal the personal
details of visitors. A web search reveals more than 500,000 vulnerable
applets on major corporate, government and media sites...
Updates in the Adobe software
that renders SWF files in browsers are also likely, but they probably
wouldn't quell the threat completely. No patch in sight from Adobe,
that's the price to pay for depending on proprietary solutions."

Discuss this story at:
    http://it.slashdot.org/comments.pl?sid=07/12/22/2240257