Jump to content


Photo

Flash Critical Update: v10.3.183.10


  • Please log in to reply
No replies to this topic

#1 Chachazz

Chachazz

    Is GSF inventory

  • General Admin
  • 33,498 posts

Posted 21 September 2011 - 11:37 PM

Security update available for Adobe Flash Player (APSB11-26)
September 21, 2011

Today, a Security Bulletin (APSB11-26) has been posted to address critical security issues in Adobe Flash Player. This Security Bulletin affects Flash Player 10.3.183.7 and earlier versions for Windows, Macintosh, Linux and Solaris, and Flash Player 10.3.186.6 for Android. There are reports that one of these vulnerabilities (CVE-2011-2444) is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an email message. This universal cross-site scripting issue could be used to take actions on a user’s behalf on any website or webmail provider if the user visits a malicious website. Adobe recommends users apply the updates for their product installations....Adobe Product Security Incident Response Team (PSIRT) Blog

Security update available for Adobe Flash Player
Release date: September 21, 2011
Vulnerability identifier: APSB11-26

Critical vulnerabilities have been identified in Adobe Flash Player 10.3.183.7 and earlier versions for Windows, Macintosh, Linux and Solaris, and Adobe Flash Player 10.3.186.6 and earlier versions for Android. These vulnerabilities could cause a crash and potentially allow an attacker to take control of the affected system.

There are reports that one of these vulnerabilities (CVE-2011-2444) is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an email message. This universal cross-site scripting issue could be used to take actions on a user's behalf on any website or webmail provider if the user visits a malicious website.

Adobe recommends users of Adobe Flash Player 10.3.183.7 and earlier versions for Windows, Macintosh, Linux and Solaris update to Adobe Flash Player 10.3.183.10. Users of Adobe Flash Player for Android 10.3.186.6 and earlier versions should update to Adobe Flash Player for Android 10.3.186.7. ...Security Bulletin (APSB11-26)

This update resolves a universal cross-site scripting issue that could be used to take actions on a user's behalf on any website or webmail provider if the user visits a malicious website (CVE-2011-2444).

Note: There are reports that this issue is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an email message.
  • This update resolves an AVM stack overflow issue that may allow for remote code execution. (CVE-2011-2426).
  • This update resolves an AVM stack overflow issue that may lead to denial of service and code execution. (CVE-2011-2427).
  • This update resolves a logic error issue which causes a browser crash and may lead to code execution. (CVE-2011- 2428).
  • This update resolves a Flash Player security control bypass which could allow information disclosure. (CVE-2011-2429).
  • This update resolves a streaming media logic error vulnerability which could lead to code execution. (CVE-2011-2430).



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users