论坛: 黑客进阶 标题: 最新的AdobeFlashPlayer跨站脚本执行漏洞 复制本贴地址    
作者: DarK-Z [bridex]    论坛用户   登录
Security update available for Adobe Flash Player
Release date: June 5, 2011

Last updated: June 7, 2011

Vulnerability identifier: APSB11-13

CVE number: CVE-2011-2107

Platform: All Platforms

Summary
An important vulnerability has been identified in Adobe Flash Player 10.3.181.16 and earlier versions for Windows, Macintosh, Linux and Solaris, and Adobe Flash Player 10.3.185.22 and earlier versions for Android. This universal cross-site scripting vulnerability (CVE-2011-2107) could be used to take actions on a user's behalf on any website or webmail provider, if the user visits a malicious website. There are reports that this vulnerability is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an email message.

Adobe recommends users of Adobe Flash Player 10.3.181.16 and earlier versions for Windows, Macintosh, Linux and Solaris update to Adobe Flash Player 10.3.181.22 (10.3.181.23 for ActiveX). Adobe recommends users of Adobe Flash Player 10.3.185.22 and earlier versions for Android update to Adobe Flash Player 10.3.181.23.


Adobe is still investigating the impact to the Authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.3) and earlier 10.x and 9.x versions of Adobe Reader and Acrobat for Windows and Macintosh operating systems. Adobe is not aware of any attacks targeting Adobe Reader or Acrobat in the wild.

Affected software versions
Adobe Flash Player 10.3.181.16 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems
Adobe Flash Player 10.3.185.22 and earlier versions for Android
To verify the version of Adobe Flash Player installed on your system, access the About Flash Player page, or right-click on content running in Flash Player and select "About Adobe (or Macromedia) Flash Player" from the menu. If you use multiple browsers, perform the check for each browser you have installed on your system.

To verify the version of Adobe Flash Player for Android, go to Settings > Applications > Manage Applications > Adobe Flash Player 10.x.

Solution
Adobe recommends all users of Adobe Flash Player 10.3.181.16 and earlier versions for Windows, Macintosh, Linux and Solaris upgrade to the newest version 10.3.181.22 (10.3.181.23 for ActiveX) by downloading it from the Adobe Flash Player Download Center. Windows users and users of Adobe Flash Player 10.3.181.16 for Macintosh can install the update via the auto-update mechanism within the product when prompted.

Users of Adobe Flash Player 10.3.185.22 and earlier for Android can update to Adobe Flash Player 10.3.185.23 by browsing to the Android Marketplace on an Android phone.

Severity rating
Adobe categorizes these as important updates and recommends affected users update their installations to the newest versions.

Details
An important vulnerability has been identified in Adobe Flash Player 10.3.181.16 and earlier versions for Windows, Macintosh, Linux and Solaris, and Adobe Flash Player 10.3.185.22 and earlier versions for Android. This universal cross-site scripting vulnerability (CVE-2011-2107) could be used to take actions on a user's behalf on any website or webmail provider, if the user visits a malicious website. There are reports that this vulnerability is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an email message.

Adobe recommends users of Adobe Flash Player 10.3.181.16 and earlier versions for Windows, Macintosh, Linux and Solaris update to Adobe Flash Player 10.3.181.22 (10.3.181.23 for ActiveX). Adobe recommends users of Adobe Flash Player 10.3.185.22 and earlier versions for Android update to Adobe Flash Player 10.3.181.23.


Adobe is still investigating the impact to the Authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.3) and earlier 10.x and 9.x versions of Adobe Reader and Acrobat for Windows and Macintosh operating systems. Adobe is not aware of any attacks targeting Adobe Reader or Acrobat in the wild.

Affected software
Recommended player update
Availability

Flash Player 10.3.181.16 and earlier
10.3.181.22
(10.3.181.23 for ActiveX)
Flash Player Download Center

Flash Player 10.3.181.16 and earlier -
network distribution
10.3.181.22
(10.3.181.23 for ActiveX)
Flash Player Licensing

Flash Player 10.3.181.16 and earlier
for Chrome users
10.3.181.22

Google Chrome Releases

Flash Player 10.3.185.22 and earlier for Android 10.3.185.23
Android Marketplace
(browse to on an Android phone) 



Acknowledgments
Adobe would like to thank Google for reporting this issue and for working with Adobe to help protect our customers.

Revisions
June 7, 2011 - Updated with information on Android update.
June 6, 2011 - Updated with Acknowledgment information, corrected Adobe Reader and Acrobat X version number.
June 5, 2011 - Bulletin released.

 


地主 发表时间: 11-06-08 10:38

论坛: 黑客进阶

20CN网络安全小组版权所有
Copyright © 2000-2010 20CN Security Group. All Rights Reserved.
论坛程序编写:NetDemon

粤ICP备05087286号