TITLE: Adobe Flash Player Multiple Vulnerabilities Criticality level: Highly critical Impact: System access Where: From remote http://secunia.com/advisories/40907/ DESCRIPTION: Multiple vulnerabilities have been reported in Adobe Flash Player, which can be exploited by malicious people to conduct click-jacking attacks or compromise a user's system. 1) An error in the ActionScript Virtual Machine 1 (AVM1) when handling the "ActionPush" command can be exploited to corrupt memory. 2) Unspecified errors can be exploited to corrupt memory. No more information is currently available. 3) An unspecified error can be exploited to corrupt memory. No more information is currently available. 4) An error in the "connect" method exposed via ActionScript native object number 2200 can be exploited to corrupt memory by calling the method several times with differing strings. 5) An unspecified error can be exploited to corrupt memory. No more information is currently available. Successful exploitation of vulnerabilities #1 through #5 may allow execution of arbitrary code. 6) A click-jacking error can be exploited to trick a user into performing unintended actions. SOLUTION: Update to a fixed version. ORIGINAL ADVISORY: Adobe: http://www.adobe.com/support/security/bulletins/apsb10-16.html ZDI: http://www.zerodayinitiative.com/advisories/ZDI-10-149 US-CERT VU#660993: http://www.kb.cert.org/vuls/id/660993 ========================= The list's FAQ's can be seen by sending an email to PCWorks-request@xxxxxxxxxxxxx with FAQ in the subject line. To unsubscribe, subscribe, set Digest or Vacation to on or off, go to //www.freelists.org/list/pcworks . You can also send an email to PCWorks-request@xxxxxxxxxxxxx with Unsubscribe in the subject line. Your member list settings can be found at //www.freelists.org/cgi-bin/lsg2.cgi/l=pcworks . Once logged in, you have access to numerous other email options. The list archives are located at //www.freelists.org/archives/pcworks/ . All email posted to the list will be placed there in the event anyone needs to look for previous posts. -zxdjhu-