New Flash zero-day exploit that allows system takeover
blogs.adobe.com
blogs.adobe.com
Is Flash really that bad or is everyone else just bad at reporting zero-day exploits publicly?
http://en.wikipedia.org/wiki/Adobe_Flash#Flash_client_securi...
Also "Zero Day Exploits" generally mean that the exploit was released to 3rd parties before it was given to the company whose software was being exploited.
Vulnerability known before the vendor can release a fix is "zero-day".
One of the best ways to get any bug fixed in any Library, OS etc... is to find a way to exploit it.
Acrobat 9.4.1 takes over to install. Oh that's right, there's a vulnerability in that version, so now we're gonna have to push 9.4.2
When a user's Flash installation is corrupted, many times the uninstaller fails, so we have to use Windows Installer Cleanup to remove it. Every week, there's a new issue. Can't these fellows get it right?
Java has ~3 times as many holes as Flash does (if one is comparing in the context of "browser plugins").
So when I got an iPad, I was especially mystified at why anyone should complain about this garbage being missing.
edit: Useful links.
Go grab ClickToFlash (Safari, OS X):
Or the Safari extension for Mac or Windows:
http://hoyois.github.com/safariextensions/clicktoflash/
Or the Firefox equivalent:
The new, Safari-extensionized version that is mentioned second is much better and updated frequently. (this link: http://hoyois.github.com/safariextensions/clicktoflash/)
(mathematical stickler: seeing as ClickToFlash is free, it's price/performance ratio is always zero)
https://chrome.google.com/extensions/detail/mfidmkgnfgnkihnj...
Still, per-site whitelisting is nice.
It isn't the easiest or most intuitive way, but so far worked well enough to me.
I did it fairly early getting my android, it makes a big difference
http://googlechromereleases.blogspot.com/2011/03/chrome-stab...
Microsoft has only recently caught up with its insecure legacy. That suggests that we have another 15 years before Flash becomes stable software.
=SUM(SWF1:SWFn)Simply put, Microsoft and Adobe will cram as much crap into their fileformats (pdfs...) as they think random middle managers in large corporations want (and sadly actually use...).
I've seen such things done. It hurts to get a word doc that's just full of embedded jpgs from a scan of a printed out pdf that was originally a website...