Adobe updates Flash Player for 10 vulnerabilities

Adobe has issued a security update for Flash Player and AIR to address a number of critical vulnerabilities which could potentially allow an attacker to take control of the affected system.

The flaws affect the current versions of Adobe Flash Player 9 and 10 for Windows, Macintosh and Linux operating systems and Adobe AIR 1.5.1 and earlier versions, Adobe said in its security bulletin.

The update addresses 10 vulnerabilities in total. Specifically, it addresses a bug caused by a flaw in Microsoft's Active Template Library (ATL) that Microsoft patched in Internet Explorer and Visual Studio on Tuesday. This vulnerability could allow an attacker to take control of an affected system, Adobe said.

In addition, the update addresses a memory corruption vulnerability that Adobe said last week was being exploited in the wild in targeted attacks. The critical bug, which affects not only Flash Player and AIR, but also Adobe Reader and Acrobat, could cause a computer to crash or enable an attacker to take control of an affected system. Adobe said it plans to update Adobe Reader and Acrobat to address this vulnerability soon.

Also, this week's update addresses a clickjacking vulnerability, which could allow an attacker to trick users into clicking a link or dialogue that they did not intend to. A number of other issues that could lead to code execution and one that could lead to information disclosure also were mitigated with this update, Adobe said.



See original article on scmagazineus.com

Copyright © SC Magazine, US edition
Adobe updates Flash Player for 10 vulnerabilities

What are your thoughts on this article? Add your comment below.

To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.

NOTE: You must be a registered member of SC Magazine to post a comment.

Click here to login | Click here to register
comments powered by Disqus
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read