Description: Sun has issued updated packages for Netscape, which address various vulnerabilities in the Macromedia Flash plugin.
The first vulnerability can be exploited by malicious people to read arbitrary files on a user's system.
The second vulnerability is caused due to a boundary error in the decoder. This can be exploited to cause a buffer overflow when a flash file with a specially crafted SWF header is executed. Successful exploitation may allow execution of arbitrary code on a user's system.
Solution: The Macromedia Flash plugin will no longer be included, because the latest secure version doesn't support Netscape 4.x browsers.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.