Online Security, Safety, Tips, Compliance, Standard
Adobe Security Updates
Adobe has shipped a critical Flash Player update to fix at least seven documented security vulnerabilities that expose nearly every computer user to dangerous hacker attacks.
The Flash Player 10.0.42.34 update is available for all platforms (Windows, Linux and Mac OS X). A new version off Adobe AIR is also available. Here are the raw details:
From Adobe’s advisory:
- This update resolves a vulnerability in the parsing of JPEG data that could potentially lead to code execution (CVE-2009-3794).
- This update resolves a data injection vulnerability that could potentially lead to code execution (CVE-2009-3796).
- This update resolves a memory corruption vulnerability that could potentially lead to code execution (CVE-2009-3797).
- This update resolves a memory corruption vulnerability that could potentially lead to code execution (CVE-2009-3798).
- This update resolves an integer overflow vulnerability that could potentially lead to code execution (CVE-2009-3799).
- This update resolves multiple crash vulnerabilities that could potentially lead to code execution (CVE-2009-3800).
- This update resolves a Windows-only local file name access vulnerability in the Flash Player ActiveX control that could potentially lead to information disclosure (CVE-2009-3951). This updates the previously patched issue, CVE-2008-4820.
Adobe recommends users of Adobe AIR version 1.5.2 and earlier versions update to Adobe AIR 1.5.3.
| Print article | This entry was posted by Tokwear on December 14, 2009 at 5:42 PM, and is filed under Security News. Follow any responses to this post through RSS 2.0. Responses are currently closed, but you can trackback from your own site. |
Comments are closed.