|
|
|
Vulnerability Note VU#128491Macromedia Flash Player continues to download flash files until browser is closedOverviewMacromedia Flash 6 does not terminate connections when a web user leaves the page. These connections may consume excessive amounts of bandwidth and limit the flow of other data.I. DescriptionThe Macromedia Flash media format enables frame-based animations with sound to be viewed within a web browser. Flash uses a scripting language called ActionScript, which includes the commands loadMovie and loadSound to download associated video and audio clips.It is typical and generally expected for downloads of embedded web page elements to cease when a user leaves one web page for another. However, in version 6 of the Flash player plug-in for Microsoft Internet Explorer (IE), connections started by the loadMovie and loadSound commands persist after the user has left the web page containing the Flash animation. These connections remain open for downloading video or audio, which can be relatively large and exhaustive of the user's bandwidth to the Internet.
References
Thanks to Dan Browder for reporting this vulnerability. This document was written by Shawn Van Ittersum.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||