Skip to main content

Adobe Flash Player / AIR Multiple Vulnerabilities

Last Update Date: 9 Jul 2014 09:36 Release Date: 9 Jul 2014 3137 Views

RISK: High Risk

TYPE: Clients - Audio & Video

TYPE: Audio & Video

Multiple vulnerabilities have been identified in Adobe Flash Player and Adobe AIR, which can be exploited by malicious people to bypass certain security restrictions.

  1. An error when handling JSONP callbacks can be exploited to provide arbitrary, otherwise restricted SWF files using certain JSONP endpoints and subsequently e.g. disclose potentially sensitive information.
  2. Two unspecified errors can be exploited to bypass certain security restrictions.

Impact

  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • Adobe Flash Player versions 14.0.0.125 and prior for Windows and Macintosh.
  • Adobe Flash Player versions 11.2.202.378 and prior for Linux.
  • Adobe AIR versions 14.0.0.110 and prior for Android.
  • Adobe AIR SDK and AIR SDK & Compiler versions 14.0.0.110 and prior for Windows, Macintosh, Android, and iOS.

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to a fixed version.

Vulnerability Identifier


Source


Related Link