oss-sec mailing list archives

Re: Latest flash player is not vulnerable


From: security curmudgeon <jericho () attrition org>
Date: Fri, 30 May 2008 20:43:51 +0000 (UTC)


: Adobe announced that the flaw that is in the wild is not a new one. The 
: attack took the advantage of other security flaws to redirect the user 
: from legitimate sites to malicious domains serving exploit SWFs
: 
: http://blogs.adobe.com/psirt/2008/05/more_information_on_recent_fla.html
: 
: Just for informing for those who missed the news :-)

This was quite the frenzy, all based on some fairly poor vulnerability 
'research' and testing.

http://osvdb.org/blog/?p=246
Whos to blame? The hazard of 0-day.
May 30th, 2008


Current thread: