|
|
|
>> Adobe Products Multiple Code Execution Vulnerabilities
|
Multiple vulnerabilities have been identified in Adobe Flash Player, AIR, and Reader and Acrobat, which could be exploited by attackers to bypass security restrictions, disclose sensitive information or compromise a vulnerable system. These issues are caused by memory corruption, buffer overflow, privilege escalation, null pointer, sandbox bypass, and input validation errors when processing specially crafted web pages or animations, which could be exploited to execute arbitrary code, gain elevated privileges, gain knowledge of certain information and conduct clickjacking attacks.
Certain issues are related to : VUPEN/ADV-2009-2065 - VUPEN/ADV-2009-1986
Affected Products
Adobe Flash Player version 9.0.159.0 and prior
Adobe Flash Player version 10.0.22.87 and prior
Adobe AIR version 1.5.1 and prior
Adobe Reader version 9.1.2 and prior
Adobe Acrobat version 9.1.2 and prior
Solution
Upgrade to Adobe Flash Player version 9.0.246.0 or 10.0.32.18 :
http://www.adobe.com/go/getflashplayer
Upgrade to Adobe AIR version 1.5.1 :
http://get.adobe.com/air
Upgrade to Adobe Reader version 9.1.3 :
http://get.adobe.com/reader/
Upgrade to Adobe Acrobat version 9.1.3 :
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=158&platform=Windows
http://www.adobe.com/support/downloads/product.jsp?product=1&platform=Macintosh
References
http://www.vupen.com/english/advisories/2009/2086 http://www.adobe.com/support/security/bulletins/apsb09-10.html
Credits
Vulnerabilities reported by lakehu (Tencent Security Center), David Dewey (IBM ISS X-Force), Ryan Smith (VeriSign iDefense Labs), Microsoft Vulnerability Research Program (MSVR), Mike Wroe, iDefense, Chen Chen (Venustech), Joran Benker, and Roee Hay (IBM Rational Application Security).
ChangeLog
2009-07-31 : Initial release
2009-08-27 : Updated Solution
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time alerts with CVE, CWE, and CVSS when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
 |