SHARE
Facebook X Pinterest WhatsApp

Adobe updates open source Flex for XSS security issue

Aug 21, 2009
adobe.jpg

From the

Busy Times For Adobe Security

files:

Another day, another Adobe security update.

US-CERT warned this morning that there is a security flaw in Adobe’s Flex 3.3 SDK and earlier versions.

“This vulnerability may allow an attacker to conduct a cross-site scripting attack,” US-CERT warned.

Adobe has a fix available now in the Flex 3.4 SDK, which also includes the latest version of the Flash Player. Adobe updated Flash at the end of July for a critical security issue.

The actual flaw fixed by Adobe is a Cross-Site Scripting (XSS) attack within something known as the Flex SDK express-install templates. Adobe credited Adam Bixby of Gotham Digital Science with discovering and reporting the flaw.

“An instance of a DOM-based Cross Site Scripting (XSS) vulnerability was
found in the default index.template.html file of the SDK which is a
template used by FlexBuilder to generate the wrapper html for all
application files in your project,” Bixby wrote in his advisory. “The XSS vulnerability appears to
affect all user’s that download and utilize this html wrapper.”

Flex is Adobe’s open source framework for building RIA web applications. The flaw does not affect Adobe’s under-development Flex 4 SDK which is still in beta.

“This fix does not apply to Flex 4 projects, as they use the SWFObject templates by default,” Adobe wrote in its advisory.

Recommended for you...

Facebook Becomes Meta, But Did It Move Too Soon?
Rob Enderle
Oct 29, 2021
Microsoft Gets Rid Of Passwords: I Can Almost Hear Angels Singing
Rob Enderle
Sep 17, 2021
Why AMD Has Been So Successful: Mark Papermaster
Rob Enderle
Sep 9, 2021
Another Crazy Week in Cybersecurity
Paul Shread
Jul 2, 2021
Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.