MSFN Forum: Adobe Patches Zero Day XSS Flash Flaw

Jump to content






Icon Latest News Comments


Icon MSFN Statistics

  • Total Posts 802362
  • Total Members 102224
  • Newest Member Jani899 
  • Online At Once Record 17869
  • Online Now: 3818



    Icon Recommended Sites

    AskVG.com Bink Filehorse FreewareFiles IT Magazine lunarsoft Where unprofessional journalism looks better OSNN TechLog The Windows Club WinBeta

Adobe Patches Zero Day XSS Flash Flaw -----

Posted on Jun 08 2011 06:07 AM by xper  in Security | Viewed 1303 Times

Adobe issued a new security update for its Adobe Flash Player on Sunday, fixing a vulnerability that has been categorized as being, 'important'. The important rating is Adobe's second highest security rating behind 'critical' and above 'moderate'.

The important flaw is a cross site scripting (XSS) vulnerability that affects Windows, Macintosh, Linux, Solaris and Android versions of Flash Player. According to Adobe, the flaw is already being exploited in the wild via malicious email links.

"This universal cross-site scripting vulnerability (CVE-2011-2107) could be used to take actions on a user's behalf on any website or webmail provider, if the user visits a malicious website," Adobe warned it is advisory.

The new Adobe Flash Player 10.3.181.22 provides a fix for the XSS flaw for Windows, Macintosh, Linux and Solaris. Adobe has not yet issued an update for Android users, though the plan is to have a new Flash Player for Android release out this week.

Adobe's Reader and Acrobat programs may also potentially be at risk as well.

"Adobe is still investigating the impact to the Authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.2) and earlier 10.x and 9.x versions of Adobe Reader and Acrobat for Windows and Macintosh operating systems," Adobe warned.

Source: internet.com




0 Comments

Page 1 of 1

No comments have been made yet

You do not have permission to leave comments on this article
Page 1 of 1



All trademarks mentioned on this page are the property of their respective owners
Copyright © 2001 - 2013 msfn.org
Privacy Policy