Untitled.

Gespeichert in:
Bibliographische Detailangaben
Titel: Untitled.
Autoren: Flinders, Karl
Quelle: Computer Weekly. 1/8/2008, p42-42. 1p.
Schlagwörter: *COMPUTER security, *PROGRAMMING languages, *SECURITY systems, *DATA protection, *MALWARE, *COMPUTER software, ACTIONSCRIPT (Computer program language), JAVASCRIPT programming language
Geografische Kategorien: UNITED States
Abstract: The article focuses on the security vulnerabilities in Flash (SWF) file code as reported by the U.S. Computer Emergency Readiness Team (US-Cert). It claims that such security vulnerabilities could allow a remote, unauthenticated attacker to conduct cross-site scripting attacks on a vulnerable system. The flaws then exist in the way that input is validated when passed to ActionScript and JavaScript in the file. Aside from this, US-Cert also reports that there is exploit code in the wild to take advantage of a flaw in RealPlayer. The exploit further affects RealPlayer 11 build 6.0.14.748.
Datenbank: Business Source Index
Beschreibung
Abstract:The article focuses on the security vulnerabilities in Flash (SWF) file code as reported by the U.S. Computer Emergency Readiness Team (US-Cert). It claims that such security vulnerabilities could allow a remote, unauthenticated attacker to conduct cross-site scripting attacks on a vulnerable system. The flaws then exist in the way that input is validated when passed to ActionScript and JavaScript in the file. Aside from this, US-Cert also reports that there is exploit code in the wild to take advantage of a flaw in RealPlayer. The exploit further affects RealPlayer 11 build 6.0.14.748.
ISSN:00104787