Secunia Logo  


Secunia PSI WorldMap
 
Adobe Flash Player Multiple Vulnerabilities
Secunia Advisory: SA34012
Release Date: 2009-02-25
Popularity: 73,169 views

Critical:
Highly critical
Impact: Security Bypass
Exposure of sensitive information
Privilege escalation
System access
Where: From remote
Solution Status: Vendor Patch

Software:Adobe AIR 1.x
Adobe Flash CS3
Adobe Flash CS4
Adobe Flash Player 10.x
Adobe Flash Player 9.x
Adobe Flex 3.x

Binary Analysis: BA664 :: Available for 1 Credit

Secunia CVSS-2 Score: Available in Secunia business solutions

Subscribe: Instant alerts on relevant vulnerabilities


Advisory Content (Page 2 of 3)[ 1 ] [ 2 ] [ 3 ]

Solution:
Apply vendor updates.

Flash Player 9.x:
Update to version 9.0.159.0.
http://www.adobe.com/go/kb406791

Flash Player 10.0.12.36 and prior:
Update to version 10.0.22.87.
http://www.adobe.com/go/getflash

Flash Player 10.0.12.36 and prior (network distribution):
Update to version 10.0.22.87.
http://www.adobe.com/licensing/distribution

Flash Player 10.0.15.3 and prior for Linux:
Update to version 10.0.22.87.
http://www.adobe.com/go/getflash

AIR 1.5:
Update to version 1.5.1.
http://get.adobe.com/air

Flash CS4 Professional:
Update to version 10.0.22.87.
http://www.adobe.com/support/flashplayer/downloads.html#fp10

Flash CS3 Professional:
Update to version 9.0.159.0.
http://www.adobe.com/support/flashplayer/downloads.html#fp9

Flex 3:
Update to version 10.0.22.87.
http://www.adobe.com/support/flashplayer/downloads.html#fp9

Provided and/or discovered by:
1) Javier Vicente Vallejo, reported via iDefense
2) The vendor credits Roee Hay from IBM Rational Application Security.
3) The vendor credits Eduardo Vela.
4) The vendor credits Josh Bressers of Red Hat and Tavis Ormandy of the Google Security Team.

Original Advisory:
Adobe:
http://www.adobe.com/support/security/bulletins/apsb09-01.html

iDefense:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=773

Change Page:
[ 1 ] [ 2 ] [ 3 ]



Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Today
New advisories: 3
New vulnerabilities: 13
Updated advisories: 4

Moderately // 45 views
Red Hat update for expat

7th Dec, 2009
New advisories: 20
New vulnerabilities: 53
Updated advisories: 39

Less // 233 views
Ubuntu update for bind9

Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Red Hat update for expat // 35 views
2. Internet Explorer Charset Inheritance Cross-Site Scripting Vulnerability // 22 views
3. Kaspersky Anti-Virus 2010 klavemu.kdl Denial of Service Vulnerability // 21 views
4. Joomla YOOtheme Template Cross-Site Scripting Vulnerability // 20 views
5. Internet Explorer Layout Handling Memory Corruption Vulnerability // 20 views
6. Adobe Flash Player Multiple Vulnerabilities // 17 views
7. Adobe Illustrator Encapsulated Postscript Parsing Vulnerability // 16 views
8. Sun Solaris Python Multiple Vulnerabilities // 15 views
9. AROUNDMe "language_path" File Inclusion Vulnerability // 15 views
10. IBM HTTP Server TLS Session Renegotiation Plaintext Injection // 14 views