"Symantec: Sorry, Flash Player attack not a zero day"
http://www.zdnet.com.au/news/security/soa/Symantec-Sorry-Flash-Player-attack-not-a-zero-day/0,130061744,339289430,00.htm
Symantec: Sorry, Flash Player attack not a zero day
Liam Tung, ZDNet.com.au
29 May 2008 03:14 PM
Tags: adobe, flash, flaw, nishad herath, security, symantec, zero day, ibm
After suspecting a zero day exploit was being used to attack the latest version of Flash Player (9.0.124.0), Symantec says the call was a mistake — it was an exploit for versions 9.0.115.0 and prior.
Yesterday it was feared that hackers were using a malicious ShockWave Flash file which Symantec researchers thought was a zero day exploit for the latest version of Flash Player.
Symantec, however, shied away from confirming that it was a zero day exploit, as it appears to be designed for a flaw which Adobe patched in April, prior to it being publicly disclosed by an IBM security researcher.
"Originally this issue was believed to be unpatched and unknown, but further technical analysis has revealed that it is the previously reported Adobe Flash Player Multimedia File Remote Buffer Overflow Vulnerability (BID 28695), discovered by Mark Dowd of IBM," Symantec reported on its ThreatCon page today.
Adobe has also confirmed the exploit is not new. "This exploit does NOT appear to include a new, unpatched vulnerability as has been reported elsewhere — customers with Flash Player 9.0.124.0 should not be vulnerable to this exploit," it states on its Product Security Incident Response Team site.
The CEO of security consultancy Novologica, Nishad Herath, who yesterday acquired a sample of the exploit, told ZDNet.com.au today that the error appears to have been caused by a reference in the malicious SWF file to the new version of Flash Player.
"Actually [the code] does have references to the latest version of Flash, but it is not exploiting a new zero day — it is exploiting the old patched vulnerability," he said.
"It means Adobe patched the flaw properly, but Symantec has made a mistake... The exploit writer had made a reference to a SWF file with the name 9.0.124.0.swf, so it may just be that they were planning to add something to that exploit that may work on the new version in the future, should a zero day vulnerability be released… They might have been attempting to make this code base future-proof, but it's of no real relevance [to the exploit]," said Herath.
Adobe recommends updating Flash Player to the latest version since older versions are vulnerable to the exploit which Symantec discovered yesterday.
正確文章網址如下:
Symantec: Sorry, Flash Player attack not a zero day
回應 :
請填寫您的回應,長度限為1,000個字,回應不計點數,也不限使用次數
相關問答
- 使用Ajax的網頁安全性
- [RoR] 簡單畫出 216 網頁安全色表
- vPro的資安管理
- 請問目前最新最熱門的資訊安全技術是哪些呢?
- 網頁瀏覽器本身是否也可能成為駭客下手的目標,怎麼做到的?
- 什麼是網頁應用程式源碼檢測
- 什麼是惡意檔案執行攻擊(Malicious File Execution)?
- 資安30招
- 【訊息快遞】2008 企業資安普查-10/17前,填完送卡巴,還可抽大獎!!
- 資安管理的十一大領域
- 讓讓稽核幫資安加分 - 製造業北中南巡迴研討會,敬請把握報名機會!
- 資安-微軟 Windows SteadyState
- [小財神有問題!]你曾經遇過最大的資安危機是什麼?
- IThome 2008資安研討會
- HI-NET 2.0 資安團隊
- 如何制訂資安政策
- 資安管理制度的文件架構
- 什麼是JavaScript Hijacking?
- 資安人員與電腦稽核的角色
- 資安 - 最新國內分區研討會










