Adobe Flash Player Code Execution and Information Disclosure Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in Adobe Flash and Flex, which could be exploited by attackers to disclose sensitive information or compromise a vulnerable system.
These issues are caused by input validation and memory corruption errors when processing malformed Flash content, which could be exploited by attackers to gain knowledge of sensitive information, crash an affected application or execute arbitrary code.
Impact
- Remote Code Execution
- Information Disclosure
System / Technologies affected
- Adobe Flash Player versions prior to 10.1.102.64
- Adobe Flash Player versions prior to 9.0.289.0
- Adobe Flash Professional CS5
- Adobe Flash CS4 Professional
- Adobe Flash CS3 Professional
- Adobe Flex 3
- Adobe Flex 4
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to Flash version 10.1.102.64 or 9.0.289.0 :
http://www.adobe.com/go/getflash
Vulnerability Identifier
- CVE-2010-3636
- CVE-2010-3637
- CVE-2010-3638
- CVE-2010-3639
- CVE-2010-3640
- CVE-2010-3641
- CVE-2010-3642
- CVE-2010-3643
- CVE-2010-3644
- CVE-2010-3645
- CVE-2010-3646
- CVE-2010-3647
- CVE-2010-3648
- CVE-2010-3649
- CVE-2010-3650
- CVE-2010-3652
- CVE-2010-3654
- CVE-2010-3976
Source
Related Link
Share with