Requires Free Membership to View
|
||||
Notable high-level updates include a repair for a flaw that could enable an attacker to use mismatched URLs to execute arbitrary JavaScript within the context of another site, and a fix for a pair of Adobe Flash problems that could, respectively, initiate HTTP requests to arbitrary third-party sites and enable an attacker to perform cross-site request forgery attacks against them, and place cookie-like objects on a user's computer and track them across multiple sites.
|
||||
Version 3.0.7, released March 5, repaired five flaws that could have allowed cybercriminals to conduct URL spoofing attacks and other errors that could potentially expose sensitive information. Version 3.0.6, released Feb 3, corrected several memory corruption errors and cross-site scripting flaws that could have been exploited by an attacker to gain access to critical files.
Security Management Strategies for the CIO
Join the conversationComment
Share
Comments
Results
Contribute to the conversation