Adobe Flash Player and AIR Multiple Code Execution Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in Adobe Flash Player and AIR, which could be exploited by attackers to bypass security restrictions, disclose sensitive information or compromise a vulnerable system. These issues are caused by memory corruption, buffer overflow, privilege escalation, null pointer, sandbox bypass, and input validation errors when processing specially crafted web pages or animations, which could be exploited to execute arbitrary code, gain elevated privileges, gain knowledge of certain information and conduct clickjacking attacks.
Impact
- Elevation of Privilege
- Remote Code Execution
- Security Restriction Bypass
- Information Disclosure
System / Technologies affected
- Adobe Flash Player version 9.0.159.0 and prior
- Adobe Flash Player version 10.0.22.87 and prior
- Adobe AIR version 1.5.1 and prior
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Upgrade to Adobe Flash Player version 9.0.246.0 or 10.0.32.18 :
http://www.adobe.com/go/getflashplayerUpgrade to Adobe AIR version 1.5.1 :
http://get.adobe.com/air
Vulnerability Identifier
- CVE-2009-0901
- CVE-2009-1862
- CVE-2009-1863
- CVE-2009-1864
- CVE-2009-1865
- CVE-2009-1866
- CVE-2009-1867
- CVE-2009-1868
- CVE-2009-1869
- CVE-2009-1870
- CVE-2009-2395
- CVE-2009-2493
Source
Related Link
Share with