Where:From remote
Impact:Security Bypass, System access
Solution Status:Vendor Patch
Description
Two vulnerabilities have been reported in Adobe Flash Player and Adobe AIR, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system.
1) An unspecified error can be exploited to bypass certain security restrictions.
2) A use-after-free error can be exploited to corrupt memory.
Successful exploitation of this vulnerability may allow the execution of arbitrary code.
The vulnerabilities are reported in the following versions and products:
* Adobe Flash Player for Windows and Macintosh versions 14.0.0.145 and prior.
* Adobe Flash Player for Linux versions 11.2.202.394 and prior.
* Adobe AIR versions 14.0.0.110 and prior.
* Adobe AIR for Android, AIR SDK, and AIR SDK & Compiler versions 14.0.0.137 and prior.
http://secunia.com/advisories/58593/