Tons of vulnerabilities patched in the latest variants of Flash Player and AIR

Nov 11, 2011 08:04 GMT  ·  By

Adobe released the latest variant for Flash Player and Air. The 11.1, respectively the 3.1 versions come with crucial security updates that patch vulnerabilities which could have allowed an attacker to take control of an infected system.

The company recommends that all users who currently rely on the older versions to update in order to prevent any unfortunate situations.

According to the security bulletin issued by Adobe, Flash Player 11.0.1.152 and earlier version for operating systems such as Windows, Linux, Mac and Solaris were affected by the weaknesses fixed in the latest release.

Android users who currently have the 11.0.1.153 variant or previous ones are also advised to download the last release.

The critical flaws identified in the earlier versions may have caused a machine to crash or they might have allowed a cybercriminal to execute arbitrary code.

Memory corruption, heap corruption, buffer and stack overflow vulnerabilities could allow an attacker to execute pieces of malicious code, while in Internet Explorer a flaw may have led to a cross-domain policy bypass.

To fix the issues mentioned above, Adobe had help from a lot of contributors. Among them are Tavis Ormandy and Ben Hawkes of the Google Security Team, an anonymous individual through iDefense's Vulnerability Contributor Program, Bo Qu of Palo Alto Networks, lakehu of Tencent Security Center and Ivan Golenkov and Alexander Gostev of Kaspersky Lab

The updates can be made through the product since it will probably prompt customers to alert them on the availability of a new variant. For users who are having problems in the update process, Adobe released a patched version of Flash Player 10 which can be downloaded from their website.

Adobe Flash Player 11.2.202.18/19 Beta / 11.1.102.55 is available for download here. Adobe AIR 3.2.0.1100 Beta / 3.1.0.4880 is available for download here.