<<< Date Index >>>     <<< Thread Index >>>

Re: Internet Explorer and Opera local zone restriction bypass



In-Reply-To: <20031024135303.26267.qmail@xxxxxxxxxxxxx>

All:

Macromedia is dedicated to protecting the security of our customers, and we are 
taking steps to resolve this issue. 

To summarize, the Flash Player stores cookies in a somewhat predictable 
location (assuming the username can be guessed), and some of the contents are 
stored as plain text. While this is not in itself a directly exploitable 
vulnerability, an exploit can be created in combination with a security flaw in 
the browser. Macromedia will therefore make changes so that browser 
vulnerabilities of this nature cannot be exploited using the Flash Player. 

Once an updated Flash Player is available, we will post the new software and 
notify both our customers and the BugTraq community with this information. 

Any questions can be directed to <mailto:secure@xxxxxxxxxxxxxx> 
secure@xxxxxxxxxxxxxxx

Regards,
-was-
William A. Schulze
Sr. Director
Flash Player Management Team
Macromedia, Inc.