Global Security Watch > Heads up: Prepare for the Flash Player 9 security update

Serge Jespershttp://www.webkitchen.be/2008/03/27/heads-up-prepare-for-the-flash-player-9-security-update/ [Serge Jespers] Important when you have SWFs that are exported for Flash Player 7 (SWF7) or earlier that communicate with the hosting HTML by any means

Some related posts from Technorati and Google.

peabee[peabee] Adobe Flash Player Security, April 2008 Looms: Specifics on these points can be found at the DevNet link above. If you haven’t yet ensured that your application meets these stricter requirements, it’s highly recommended that you do some heavy testing now otherwise you may find your app dead in the water come April.

I2fly[I2fly] Adobe Flash Player 9 update to destroy and save Web apps!!: The April update addresses two security flaws in Adobe Flash 9, relating to cross-site scripting (XSS) and DNS rebinding attacks — common techniques used to attack computer systems by exploiting flaws in Web applications.

The ADC Bloghttp://blogs.adobe.com/adc/2008/03/prepare_for_the_flash_player_9.html [The ADC Blog] Prepare for the Flash Player 9 April 2008 Security Update: April is just around the corner and so is a planned security update for Flash Player 9 to strengthen the security of the ubiquitous player. To ensure a seamless transition to the update, which may impact SWF content, check out Preparing .

Carmen Ferrara's Weblog 2.0[Carmen Ferrara's Weblog 2.0] Flash security and local file playback: By default, local Flash content - can no longer contact the Internet, perform HTTP communication, or communicate with local HTML files. The security measures are in place to ensure a system is secure even if it runs a malicious flash file directly on their machine - much like Microsoft has improved security around ActiveX controls.

rabidgadfly[rabidgadfly] Be Ready for the Flash Player 9 April 2008 Security Update: To defend against malicious HTTP headers, the update requires a cross-domain policy check before allowing SWFs to send headers to another domain.

Brajeshwarhttp://www.brajeshwar.com/2008/flash-on-the-iphone/ [Brajeshwar] Flash on the iPhone ”” No, Yes, Nope, very Likely Yes: The other drawback for Adobe is that apple have already blocked outside developers from working on the system with out special permission, also if they could get permission to do the development they would then need permission to have the application on the iPhone, they could risk using the decoded phones some people have created by breaking the iPhone’s security code but the risk is to big. Adobe runs in so many home and business computers they don’t want to upset one of their main buyers.

Rich internet applications experiments[Rich internet applications experiments] Adobe - Developer Center : Preparing for the Flash Player 9 April ...: The Flash Player security update provides further mitigations for issues listed in the December 2007 Security Bulletin ABSP07-20 for DNS rebinding and cross-domain policy file vulnerabilities, and Security Advisory APSA07-06 for .

Tiago's Weblog[Tiago's Weblog] Flash Player 9 - Security Update: Next month (April) Adobe is going to release a security update for the current versions of Flash Player 9, as usual such updates change a lot of things, they improve the stability, they add new features, or they change methods to connect to services because of security risks. This time Adobe is closing down a few vulnerabilities that had been issued.

[Unfiction][[Unfiction]] April Flash Player Security Update: Writing about web page http://www.adobe.com/devnet/flashplayer/articles/flash_player9_security_update.html. This is just a heads-up for myself really - there’sa Flash Security Update coming in April, and one of the changes might affect ...

James Mc Parlane's Blog[James Mc Parlane's Blog] Adobe Flash Player Security Change - Prepare For Some Breaking ...: Adobe is planning to release a security update for Flash Player 9 in April 2008 to strengthen the security of Adobe Flash Player. This security update will make the optional socket policy file changes introduced in Flash Player 9,0115,0 .

Rogue Interactive Bloghttp://blog.rogueinteractive.co.uk/2008/03/core-3-launched.html [Rogue Interactive Blog] Core 3 Launched!: Each Core3 system comes complete with a full staff administration and access level system for overall and sub website control and setup. Each sub-site has administrative access for control over all functionality relating to its specific toolsets and content control.

Don.Net's WPF Design Bloghttp://blog.donburnett.com/2008/03/flash-for-iphone-huh-no-not-really-well.html [Don.Net's WPF Design Blog] Flash for iPhone? Huh? No Not Really, well maybe, huh? WTF?: It seems from the comments that I am seeing, is they see Flash as being a competing platform for Apple (they did do QuickTime for gosh sake with Flash Tracks). If QuickTime can/could play older Flash player files or imported and converted to QuickTime at least , why couldn't they also expand QuickTime to playback current SWF File)..

Reflected tags on Technorati: Blog, , , ,