Adobe Flex update patches flaw in Flex application development framework

News

Adobe Flex update patches flaw in Flex application development framework

SearchSecurity.com Staff

Adobe has issued an update to its Flex software development kit (SDK), repairing a vulnerability that could cause developers to create applications susceptible to cross-site scripting attacks.

Flex SDK is an open source software development framework used by developers to create applications that can function on desktops, on smartphones and on tablet devices.  The vulnerability affects Flex SDK version 4.5.1 and earlier and 3.6 and earlier running on Windows, Macintosh and Linux.

Many applications built with the earlier versions of the Flex SDK are vulnerable to cross-site scripting attacks, Adobe warned. In its security bulletin issued Wednesday, Adobe said developers should verify whether any Flash (.swf) files in their applications are vulnerable, and update any vulnerable .swf files by fixing them or completely rebuilding them using an updated SDK.

The software vendor issued a technical note recommending developers repair applications built with Flex or rebuild them after upgrading to the latest SDK.

“To minimize the impact to your Flex projects, Adobe has released numerous different fixed versions of the Flex SDK, enabling you to replace each of your vulnerable versions of the SDK with a fixed version

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

that is nearly identical, aside from the fix itself,” Adobe said.

Adobe warned that the security fix could cause issues with applications that use ModuleLoader to load modules from different domains.

~Robert Westervelt


Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.