0-day attacks exploiting Flash just got harder thanks to new defenses

postmortemIA

Diamond Member
Jul 11, 2006
7,721
40
91
yep, new defense called "uninstall flash :D "

My quick and dirty summary of article: Flash now uses technique in memory allocation that reduces chance that buffer overflow will lead to an exploit.
 

TheRyuu

Diamond Member
Dec 3, 2005
5,479
14
81
What's this Chrome?

What?

The heap partitioning is Chrome only right now but will be extended to all other Flash verions in next months regular update. The validation to Vector objects is in both right now. They both aim to make exploiting the Vector object stuff much harder.