4 ms·
It was marked as "never fix", though.
by frenger 13y ago
It was marked as "never fix", though.
- AaronFriel 13y agoI'm so glad we're able to read so much into so few words. Today I learned: "never fix" means they will never ever solve the problem when it's used on a bug report submitted due to a performance regression on what might have been a zero-day vulnerability with in-the-wild attacks: > Adobe is aware of reports that CVE-2013-0633 is being exploited in the wild in targeted attacks designed to trick the user into opening a Microsoft Word document delivered as an email attachment which contains malicious Flash (SWF) content. The exploit for CVE-2013-0633 targets the ActiveX version of Flash Player on Windows. > > Adobe is also aware of reports that CVE-2013-0634 is being exploited in the wild in attacks delivered via malicious Flash (SWF) content hosted on websites that target Flash Player in Firefox or Safari on the Macintosh platform, as well as attacks designed to trick Windows users into opening a Microsoft Word document delivered as an email attachment which contains malicious Flash (SWF) content. Yes, that's a reasonable reaction.