Adobe has released new critical updates for its Flash Player, Reader, and Acrobat products . The update was issued by the company to address and fix 52 vulnerabilities that Adobe said had not been publicly exploited.
According to the security bulletin issued by the company, the updated version of Flash for Windows, Mac OS X and Linuxfixes holes that could be exploited by a hacker remotely to control a user's computer.
[blockquote]" Adobe has released new security updates for Flash Player on Windows, Macintosh, and Linux. These updates address vulnerabilities that could allow hackers to gain access to and control your PC. Users are encouraged to update their products by installing the new versions,"
the company said.
The company's versions affected by the security holes are as follows:
- Flash Player0.0.169 and older versions
- Flash Player0.0.281 and older 13.x versions
- Flash Player2.202.457 and older 11.x versions
- AIR Desktop Runtime 17.0.0.144 and earlier versions
- AIR SDK and SDK & Compiler0.0.144 and earlier versions
The update fixes a heap overflow, an integer overflow bug, three type confusion, four memory corruption , and a use-after-free that could allow an attacker to execute code remotely and gain control of the system. The remaining bugs include two memory leaks that lead to Address Space Layout Randomization (ASLR) bypass, a security bypass vulnerability that could lead to data leakage, and three more vulnerabilities that allow an attacker to write data to a system file with the same permissions as the user.
The company's bulletin for updates to Reader and Acrobat states that the affected versions are:
- Reader XI (11.0.10) and earlier versions 11.x
- Reader X (10.1.13) and earlier versions 10.x
- Acrobat XI (11.0.10) and earlier 11.x versions
- Acrobat X (10.1.13) and earlier versions 10.x
As the company explained in the security bulletin, “these updates resolve various methods for bypassing restrictions on Javascript API execution.

