A new vulnerability in the way Internet Explorer deals with
Macromedia Flash files
could leave users open to phishing attacks.
The vulnerability was discovered by a user called Hai Nam Luke and posted on
security firm Secunia's list of
advisories.
The problem is caused by a 'race condition' in the loading of web content and
Macromedia .swf files in browser windows.
Malicious users could exploit this to spoof the address bar in a browser
window that displays a Flash file from a malicious website. Secunia ranked the
problem as 'moderately critical'.
"The impact of exploitation is reduced because the URL of the malicious Flash
file is visible in the title of the browser window," said the security firm in a
statement.
The vulnerability has been confirmed on a fully patched system running
Internet Explorer 6.0 and Microsoft Windows XP with Service Pack 1 and 2.
Secunia said that other versions of the operating system and browser may also
be affected.
Aylesbury, Buckinghamshire, United Kingdom | Grass Roots
Business Analyst - £35,000 - £50,000 + benefits - Aylesbury Grass Roots are one of the Sunday Times Top 100 companies to work for (2007 and 2008). Established in 1980, we're part of the ... more >
Position # 396477 Environment Support Engineer Location - Reading Job Description: There is an initial requirement an Environment Support Engineer to provide support and maintenance for the development environments within ATLAS. This role encompases many ... more >
ICT Project Officer - Guildhall, London EC2 18-month fixed-term contract Bring your project management expertise to one of the country's most prestigious institutions. The City of London is the local authority for the Square Mile, ... more >
EDS are currently looking to recruit a Change, Risk and Issue Analyst to join our Project Management Defence team in Swindon, Wiltshire. Summary: The Regional Operations Cell Analyst will work as part of a small ... more >More job opportunities