Go Back   Scifi-Meshes.com > General Discussions > General Discussion

General Discussion Post, chat, or discuss topics related to science fiction, 3D graphics, or something close to this.

Reply
 
Thread Tools Display Modes
Old 05-30-2008, 10:45 PM   #1 (permalink)
SFM Guru
 
Salvator's Avatar

 
Realname: Gareth
Join Date: May 2006
Age: 24
Posts: 151
Vulnerability In Flash Player Can Compromise Your PC; Upgrade ASAP

I couldn't find where else to post this, so I put it in here

US-CERT Vulnerability Notes

Quote:
Overview
Adobe Flash contains a vulnerability that may allow an attacker to run code on a system that has a vulnerable version of the Flash player installed. There are reports that this vulnerability is being actively exploited

I. Description
The Adobe Flash Player is a player for the Flash media format and enables frame-based animations and multimedia to be viewed within a web browser.

Adobe Flash Player contains a code execution vulnerability. An attacker may be able to trigger this overflow by convincing a user to open a specially crafted SWF file. The SWF file could be hosted or embedded in a web page. If an attacker can take control of a website or web server, trusted sites may exploit this vulnerability.

II. Impact
A remoted, unauthenticated attacker may be able to execute arbitrary code.
Quote:
III. Solution
Update

This issue has been addressed in the most recent version (9.0.124.0) of Adobe Flash. Microsoft Windows users should browse to the Adobe Flash Player Support Center downloads and install the most recent version of Flash site using Internet Explorer, then repeat the process for all other installed browsers (Firefox, Opera, Safari, etc). Systems that are not running Windows should be updated by going to the Adobe Flash Player Support Center downloads and installing the most recent version of Flash with all each web browser on the system.

Users who rely their operating system vendor to provide a packaged version of Adobe Flash should confirm that they have the most recent version.

Workarounds for users running Mozilla-based browsers

* Using the Mozilla Firefox NoScript extension to whitelist websites that can run scripts and access installed plugins may prevent this vulnerability from being exploited. Note that NoScript is not likely to stop all attack vectors for this vulnerability, see the NoScript FAQ for more information.
* On Linux systems, the Flash player can be disabled by renaming the Flash plugin. The plugin may be found in several locations, including /usr/lib/firefox/plugins /usr/lib/iceweael/plugins /usr/lib/mozilla/plugins, and is named flashplugin-alternative.so
* Firefox 3 users can disable the Flash plugin by going to tools, Add-ons, then clicking the Disable button next to the Shockwave Flash plugin. Note that this setting only applies to Mozilla Firefox, and other browsers such as Mozilla, Konqueror, Opera, and Epiphany will still be able to access the Flash plugin.


Workarounds for users running Internet Explorer

* Applying the kill bit for the following CLSID will prevent the Flash plugin from running:
{D27CDB6E-AE6D-11cf-96B8-444553540000}
More information about how to set the kill bit is available in Microsoft Support Document 240797.

Workarounds for web server administrators

* Ensure that security updates are applied to software running on the server.
* Reverse proxy servers and web application firewalls may be able to detect and block some attacks. Administrators may also use iptables string matching to block or whitelist the Flash MIME type (application/x-shockwave-flash). Note that firewalls and IPS systems are not likely to stop all attacks.
* Administrators and web developers should confirm that third parties (such as ad providers) hosting content on their domains are not acting as attack vectors for this vulnerability.


Workarounds for network administrators

* Firewall, web proxies and IPS systems may be able to stop some attacks. Iptables string matching or the Squid req_mime_type ACL can be used to block access by restricting which sites can send the Flash MIME type (application/x-shockwave-flash). For example, the below iptables command will log all packets that contain the string x-shockwave-flash. Note that this filter can be circumvented by using IPS evasion techniques.
iptables -A INPUT -m string --algo bm --string 'x-shockwave-flash' -j LOG --log-prefix FLASH

"I am Bill Gatus of MSBorg Lower your copywrites and surrender your programs your companies will be assimilated into our collective. Your employees will adapt to work for us. Resistance is futile." -Mauiman
Salvator is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

« - | - »

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

 
Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump


New To Site? Need Help?

All times are GMT. The time now is 10:31 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.1.0
Template-Modifikationen durch TMS