Adobe Flash Player Code Execution and Clickjacking Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in Adobe Flash Player, which could be exploited by attackers to gain knowledge of sensitive information, manipulate certain data, cause a denial of service or compromise a vulnerable system.
1. A vulnerability is caused by an invalid object references when creating and destroying certain objects during the processing of a Shockwave Flash file, which could allow attackers to execute arbitrary code by tricking a user into visitig a malicious web page.
2. A vulnerability is caused by an unspecified input validation error, which could be exploited to cause a denial of service or potentially execute arbitrary code.
3. A vulnerability is caused by an unspecified error related to the Settings Manager, which could be exploited to conduct clickjacking attacks.
4. A vulnerability is caused by an unspecified error related to mouse pointer display, which could be exploited to conduct clickjacking attacks against Windows systems.
5. A vulnerability is caused by an unspecified information disclosure issue in the Flash Player binary for Linux, which could be exploited by local attackers to gain elevated privileges.
Impact
- Denial of Service
- Remote Code Execution
- Information Disclosure
System / Technologies affected
- Adobe Flash Player version 10.0.12.36 and prior
- Adobe Flash Player version 10.0.15.3 for Linux and prior
- Adobe AIR 1.5
- Adobe Flash CS4 Professional
- Adobe Flash CS3 Professional
- Adobe Flex 3
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Flash Player 9.x:
Update to version 9.0.159.0.
http://www.adobe.com/go/kb406791Flash Player 10.0.12.36 and prior:
Update to version 10.0.22.87.
http://www.adobe.com/go/getflashFlash Player 10.0.12.36 and prior (network distribution):
Update to version 10.0.22.87.
http://www.adobe.com/licensing/distributionFlash Player 10.0.15.3 and prior for Linux:
Update to version 10.0.22.87.
http://www.adobe.com/go/getflashAIR 1.5:
Update to version 1.5.1.
http://get.adobe.com/airFlash CS4 Professional:
Update to version 10.0.22.87.
http://www.adobe.com/support/flashplayer/downloads.html#fp10Flash CS3 Professional:
Update to version 9.0.159.0.
http://www.adobe.com/support/flashplayer/downloads.html#fp9Flex 3:
Update to version 10.0.22.87.
http://www.adobe.com/support/flashplayer/downloads.html#fp9
Vulnerability Identifier
Source
Related Link
Share with