Adobe Flash Player Multiple Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in Adobe Flash Player, which could be exploited by remote attackers to bypass security restrictions, gain knowledge of sensitive information or take complete control of an affected system.
1. Due to a buffer overflow error in the processing of "Declare Function (V7)" tags, which could be exploited by attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.
2. Due to an integer overflow error when processing malformed SWF files, which could be exploited by attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.
3. Due to an unspecified error when handling specially crafted Flash files, which could be exploited to conduct DNS rebinding attacks.
4. Due to an error when interpreting cross-domain policy files, which could be exploited to conduct privilege escalation attacks against web servers hosting Flash content and cross-domain policy files.
5. Due to an error when processing HTTP headers, which could be exploited to bypass cross-domain policy restrictions.
6. Due to input validation errors in various APIs, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.
Impact
- Cross-Site Scripting
- Remote Code Execution
- Security Restriction Bypass
System / Technologies affected
- Adobe Flash Player 9.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to a fixed version.
- Flash Player 9.0.115.0 and earlier [ Update to version 9.0.124.0. ]
- http://www.adobe.com/go/getflash - Flash Player 9.0.115.0 and earlier - network distribution [ Update to version 9.0.124.0. ]
- http://www.adobe.com/licensing/distribution - Flex 3.0 [ Update to version 9.0.124.0. ]
- http://www.adobe.com/support/flashplayer/downloads.html#fp9 - AIR 1.0 [ Update to version 1.0.1. ]
- http://www.adobe.com/go/getair
Vulnerability Identifier
Source
Related Link
Share with