Giuseppe Iuculano
2009-Jul-24 09:39 UTC
[Secure-testing-team] Bug#538240: CVE-2009-1862: Adobe Flash Player Remote Code Execution Vulnerability
Package: flashplugin-non-free Severity: grave Tags: security -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for flashplugin-nonfree. CVE-2009-1862[0]: | Unspecified vulnerability in Adobe Reader and Acrobat 9.x through | 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through | 10.0.22.87, allows remote attackers to execute arbitrary code via (1) | a crafted Flash application in a .pdf file or (2) a crafted .swf file, | related to authplay.dll, as exploited in the wild in July 2009. If you fix the vulnerability please also make sure to include the CVE id in your changelog entry. NOTE: The vendor is investigating the issue. Updates for Flash Player v9 and v10 for Windows, Macintosh, and Linux will be released by July 30, 2009 For further information see: [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1862 http://security-tracker.debian.net/tracker/CVE-2009-1862 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkppgWcACgkQNxpp46476arv+gCeKu/UvIyVEWiXACyy2BbfTLFP 138An1br8Tvr2UIgwIDsTIBuNge7PT36 =aUd4 -----END PGP SIGNATURE-----