The 3.4 version of Flex SDK is available. An important vulnerability has been identified in Flex 3.3 SDK and earlier versions which could result in cross-site scripting. This technote explains the important vulnerability found in the previous version of the Flex SDK.
Please go to Adobe Open Source website and download the Flex 3.4 SDK version.
It seems that Flex 4 SDK is not affected by this vulnerability because it uses SWFObject templates.
Resources:
http://www.adobe.com/support/security/bulletins/apsb09-13.html
http://kb2.adobe.com/cps/495/cpsid_49530.html
http://opensource.adobe.com/wiki/display/flexsdk/Download+Flex+3
Tags: flex sdk, Security, update, vulnerability
This post was written by Andrei Ionescu
Views: 2884








