Welcome Guest [Log In] [Register]

Kia Ora
You are currently viewing our forum as a guest. This means you are limited to certain areas of the board and that there are some features you can't use or read.

We are an active community of worldwide senior members participating in chat, politics, travel, health, blogging, graphics, computer issues & help, book club, literature & poetry, finance discussions, recipe exchange and much more. Also, as a member you will be able to access member only sections, many features, send personal messages, make new friends, etc.

Registration is simple, fast and completely free. Why not register today and become a part of the group. Registration button at the very top left of the page.

Thank you for stopping by.

Join our community!

In case of difficulty, email worldwideseniors.org@gmail.com.
If you're already a member please log in to your account to access all of our features:

Username:   Password:
Add Reply
Adobe Flash Player / AIR Two Vulnerabilities; HIGHLY CRITICAL
Topic Started: Apr 2 2012, 08:35 PM (269 Views)
Deleted User
Deleted User

Advisory SA48623
Adobe Flash Player / AIR Two Vulnerabilities

HIGHLY CRITICAL

Remediation status Secunia CSI, Secunia PSI
Automated scanning Secunia CSI, Secunia PSI

Software: Adobe AIR 3.x
Adobe Flash Player 11.x

Secunia CVSS Score Available in Customer Area
CVE Reference(s) CVE-2012-0772 CVSS available in Customer Area
CVE-2012-0773 CVE-2012-0773 CVSS available in Customer Area
Description
Two vulnerabilities have been reported in Adobe Flash Player and Adobe AIR, which can be exploited by malicious people to compromise a user's system.

1) An error within an ActiveX Control when checking the URL security domain can be exploited to corrupt memory.

NOTE: This vulnerability affects Windows Vista and Windows 7 only.

2) An unspecified error within the NetStream class can be exploited to corrupt memory.

Successful exploitation of the vulnerabilities may allow execution of arbitrary code.

The vulnerabilities are reported in the following versions:
* Adobe Flash Player versions 11.1.102.63 and prior for Windows, Macintosh, Linux, and Solaris.
* Adobe Flash Player versions 11.1.111.7 and prior for Android 3.x and 2.x.
* Adobe AIR versions 3.1.0.4880 and prior for Windows, Macintosh, and Android.

Solution
Update to a fixed version.
Further details available in Customer Area

Provided and/or discovered by
The vendor credits:
1) Microsoft Vulnerability Research (MSVR)
2) An anonymous person via ZDI

Original Advisory
http://www.adobe.com/support/security/bulletins/apsb12-07.html

Quote Post Goto Top
 
1 user reading this topic (1 Guest and 0 Anonymous)
« Previous Topic · SOFTWARE & HARDWARE · Next Topic »
Add Reply