Prolly the worst [anti-Flash] troll post so far.
Prolly the worst [anti-Flash] troll post so far.
Reading the original article, the issues seems to be with AVM1, the portion of the Flash Player dedicated to legacy Flash (v8 and older). Flash Player was updated in 2006 to include AVM2 and that's been Adobe's focus ever since.
Translation for HTML people: it's like pointing out IE6 bugs that still show up in IE7.
This is nothing more than an out of date flame post.
(Downvoters: have you actually looked at the nature of the bug?)
But this is very different the plugin actually crashes. The security issues comes in to play because when the plugin crashes it is doing something it wasn't designed to do. So (in theory) someone malicious could take this crash and make the flash player do something specific it wasn't designed to do like run some code outside of it's sandbox. Which obviously would be a very big deal.
This is different then the lock up/DoS case where a product is doing what it is meant to do, but will just take a very long time (maybe forever) to finish it.
If they had actually fixed that bug in the Flash plugin and people were using older versions, then you might have a point.
A better analogy would be he's making a stink about a Carbon bug for obsolete OS 8/9 apps. Carbon still ships with OSX and serves the same purpose as AVM1 in Flash Player: basic (but not perfect) backwards-compatibility for legacy code.
Incidentally this use case isn't completely unheard of. There is still a lot of AS2 content out there that companies haven't bothered to migrate to AS3 yet (for whatever reason).