Original URL: http://www.reghardware.co.uk/2007/07/24/flash_wii_flaw/
Nintendo's Wii gaming console could be at risk from vulnerabilities within Adobe's Flash software, incorporated in the console's Opera-based web browser, security firm Symantec has warned.
The vulnerability, which affects Flash .FLV video files, means creators could send gamers a link to a "specially crafted video" that once opened would cause the console to crash or hang.
Videos of the crash occurring on Wii consoles worldwide have already begun appearing on You Tube (http://www.youtube.com/watch?v=seZYSor_7T8):
Symantec's Wii hangs via YouTube
Adobe has already issued a patch (http://www.adobe.com/support/security/bulletins/apsb07-12.html) for malicious .SWF files that could affect Flash Player versions 9.0.45.0 and earlier, 8.0.34.0 and earlier, and 7.0.69.0 and earlier. However, while the patch does cover the plug-in for the Opera browser on a variety of computer platforms, it's still unclear whether it fixes the potential vulnerability on the Wii console.
The Wii version of Opera is only available through the console's own internet channel. Originally free, it now costs 500 Wii points - which cost $5 or €5 in real money. At this stage it's not known whether Nintendo has posted a revised version of the browser containing Adobe's changes.
Symantec has also warned video hosting sites accessible through the Wii that they too should be mindful of content, even going as far as to suggest the scanning of all new video content.
Google researcher calls for Flash flush (2 January 2008)
http://www.theregister.co.uk/2008/01/02/buggy_flash_fix/
Adobe plugs multi-platform Flash vulns (20 December 2007)
http://www.theregister.co.uk/2007/12/20/adobe_flash_security_update/
Wii wins console war, market watcher claims (24 August 2007)
http://www.reghardware.co.uk/2007/08/24/wii_wins_console_war/
Planned Wii production boost blocked? (17 August 2007)
http://www.reghardware.co.uk/2007/08/17/wii_production_ramp_blocked/
Laser-sight gun grip targets Wii gamers (23 July 2007)
http://www.reghardware.co.uk/2007/07/23/wii_wifle_accessory/
Star Wars laptops - for the Jedi in you (20 July 2007)
http://www.reghardware.co.uk/2007/07/20/star_wars_laptop/
Wii sales top 3m in Japan (20 July 2007)
http://www.reghardware.co.uk/2007/07/20/wii_tops_3m_in_japan/
Java and Flash fixes tax system security (16 July 2007)
http://www.theregister.co.uk/2007/07/16/flash_java_patches/
Fake flash player site used to spread malware (22 June 2007)
http://www.theregister.co.uk/2007/06/22/shockwave_social_engineering_ruse/
Wii gets wee add-on screen (22 June 2007)
http://www.reghardware.co.uk/2007/06/22/wii_clipon_screen/