Compromised in a Flash: Macromedia flaw found

A flaw found in Macromedia's animation software leaves Web surfers vulnerable to attack when they visit an Internet site or, possibly, open an e-mail, a security firm said Tuesday.

The vulnerability, found by security firm eEye Digital Security, allows an attacker to create a hand-edited Macromedia Flash, or SWF, file that can compromise a PC or Macintosh if its user views the file with the Shockwave Flash Player plug-in for Internet Explorer, Netscape or other browsers.

The flaw's danger is compounded by the fact that Flash is so widespread and the software doesn't have a built-in upgrade system, said Marc Maiffret, chief hacking officer for eEye.

"Almost every user is going to have Flash, so they can become compromised," Maiffret said. "Unless the user is smart enough to get the latest version of Flash, then they are going to be vulnerable."

More than 90 percent of Web browsers have the Flash software installed, according to Macromedia. While nearly 53 percent of Web surfers use the latest version, Shockwave Flash Player 6, the number still falls well short of the total, underscoring the problem of convincing people to upgrade.

Macromedia warned its developers of the problem last Friday, said Troy Evans, product manager for the Flash Player. He added that the only way to notify software users that they need to get the latest software is via new versions of Flash animations, so the company is focused on getting developers to do more updates.

Although getting users to upgrade is a challenge, Evans said, the company has been fairly successful. "We have 3 million downloads per day, so the players that are out there are getting updated," he said.

The flaw affects the Flash plug-in for browsers on Windows, Unix, Linux and the Macintosh.

By editing the header of a Flash file, an attacker can cause the file to execute commands and compromise the computer system. In some cases, it's possible to cause HTML e-mail to perform a similar attack, eEye said in its advisory.

The danger of flaws that require a victim to go to a specific Web site tends to be offset by the fact that a Web site can be shut down fairly quickly. For that reason, a virus that attempts to use a vulnerability in Flash or another Web technology usually has a limited effect.

In many respects, the flaw resembles another vulnerability that eEye found in the Flash Player in August. That flaw also allowed an attacker to modify the header of an SWF file and cause the Flash Player to compromise the machine on which the software was running.

"The outcome of the attack is basically identical to the one back in August," Maiffret said. "It just goes to further show that the average software company is in great need of real-world security" checking.

Advertisement

Talkback 2 comments

  1. While your article states there is no problem in version 6 you neglect to mention what version of the plug-in has this security flaw. 4, 5.X??? Randy Smith -- 19/12/02

    While your article states there is no problem in version 6 you neglect to mention what version of the plug-in has this security flaw. 4, 5.X???

  2. There are so many uncertain things in this article. I read it through and I still haven't got a clear idea of how I can hack with the help of Flash Movies. One thing that is clear is that I'm in great danger if I don't upgrade my flash player. But already Anonymous -- 19/12/02

    There are so many uncertain things in this article. I read it through and I still haven't got a clear idea of how I can hack with the help of Flash Movies. One thing that is clear is that I'm in great danger if I don't upgrade my flash player. But already belong to those 54%.

Add your opinion


Latest Videos

ZDNet's CIO Vision Series

Department of Defence | Greg Farr, CIO (part two)

In the second part of his interview, Defence CIO Greg Farr talks about outsourcing, the skills crisis and reveals his most urgent IT priority.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Angus Kidman I'm a celebrity, don't back me up
    Celebrity comes with its perks — free alcohol, better-looking partners, lots of holiday time — and disadvantages — constant media intrusions, being forced to appear in films with Eddie Murphy for the long-term good of your career, and having to do mindless radio interviews with angry men who've been awake since 4am.
  • Array Lies, damned lies and telco stupidity
    Earlier this month, Telstra put out a press release trumpeting that it's come up with a new phone coaching service to help people who are "bamboozled" by their mobiles. Another excellent example of wrongheaded thinking from the mobile industry.
  • Array Dear carriers: More walking, less talking
    Sometimes, a well-placed and well-timed letter can make all the difference. Other times, it can make no difference at all — and even hurt your case. This week's missive by the Competitive Carriers' Coalition, I would suggest, falls into the latter category.
  • More blogs »

Tags

Back to top

Featured