<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Preparing for the Flash Player 9 April 2008 Security Update in Security</title>
<link>http://www.dslreports.com/forum/r20224537</link>
<description></description>
<language>en</language>
<pubDate>Fri, 29 Aug 2008 21:11:48 EDT</pubDate>
<lastBuildDate>Fri, 29 Aug 2008 21:11:48 EDT</lastBuildDate>

<item>
<title>Re: Preparing for the Flash Player 9 April 2008 Security Update</title>
<link>http://www.dslreports.com/forum/remark,20224747</link>
<description><![CDATA[<A HREF="/useremail/u/937228"><b>altermatt</b></A> : <div class="bquote"><small>said by  NICK ADSL UK <A HREF="/useremail/u/957998"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>You have SWFs that are exported for Flash Player 7 (SWF7) or earlier that communicate with the hosting HTML by any means  </div>If I'm reading this correctly (and I most likely am not ;)), it sounds like anyone with a website that has an .swf that was created for Flash 7, which works fine in current versions, will have a problem with the new update? does the .swf have to be completely re-created using a later version of Flash? If so, this is pretty awful for website owners, but I'm guessing I'm misunderstanding?<br><small>--<br>The truth of a thing is the feel of it, not the think of it. &#9;-- Stanley Kubrick</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20224747</guid>
<pubDate>Tue, 25 Mar 2008 18:56:05 EDT</pubDate>
</item>

<item>
<title>Preparing for the Flash Player 9 April 2008 Security Update</title>
<link>http://www.dslreports.com/forum/remark,20224537</link>
<description><![CDATA[<A HREF="/useremail/u/957998"><b>NICK ADSL UK</b></A> : Adobe is planning to release a security update for Flash Player 9 in April 2008 to strengthen the security of Adobe Flash Player for our customers and end users, and to provide further mitigations for previously disclosed vulnerabilities. The Flash Player security update provides further mitigations for issues listed in the December 2007 Security Bulletin ABSP07-20 for DNS rebinding and cross-domain policy file vulnerabilities, and Security Advisory APSA07-06 for cross-site scripting vulnerabilities in SWFs. Due to the possibility that these security enhancements and changes may impact existing content, Adobe is providing relevant information in advance to allow customers to better prepare for the pending release.<br><br>Customers are advised to review the upcoming Flash Player updates to determine if their content will be impacted, and to begin implementing necessary changes immediately to help ensure a seamless transition. This document provides an overview of the upcoming Flash Player changes, links to TechNotes, and relevant documentation to help you better prepare.<br><br>If any of the following situations apply, you should read this article in detail:<br><br>&raquo;<A HREF="http://www.adobe.com/devnet/flashplayer/articles/flash_player9_security_update.html" >www.adobe.com/devnet/flashplayer&middot;&middot;&middot;ate.html</A><br><br>You use sockets or XMLSockets, regardless of the domain to which you are connecting <br>You use addRequestHeader or URLRequest.requestHeaders in any network API call when sending or loading data cross-domain<br><br>or<br><br>You provide access to content on remote domains as a web service provider<br><br>You have SWFs that are exported for Flash Player 7 (SWF7) or earlier that communicate with the hosting HTML by any means <br>You use "javascript:" through network APIs to communicate outside a SWF<br><small>--<br><A HREF="http://www.wilderssecurity.com/index.php">Wilders Security Forum Admin<br>Microsoft MVP - Consumer Security<br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20224537</guid>
<pubDate>Tue, 25 Mar 2008 18:21:41 EDT</pubDate>
</item>

</channel>
</rss>
