HomeSecurityAdobe fixes 35 new critical vulnerabilities in Flash & AIR

Adobe patches 35 new critical vulnerabilities in Flash & AIR

AdobeAdobe has announced its monthly security update – it fixes 35 vulnerabilities in Flash  and AIR, including some critical ones, that could allow hackers to execute code on vulnerable systems.

The company explained in the security advisory on August 11 that the specific vulnerabilities range on a severity scale from 1, the highest severity rating for Adobe, to 3.

They include use-after-free, type confusion, heap buffer overflow, integer overflow, and memory corruption bugs - each of which can lead to code execution. Although no one has yet identified an exploit for the above bugs, after the vulnerabilities were made public and their severity was announced, Adobe believes they will not remain unexploited for long.

The APSB15-19 update affects Windows, Mac, Linux, Android, and iOS.

In fact, there's even one for the new Edge browser, with a hole in Flash Player for Microsoft Edge and Internet Explorer 11 on Windows 10 also receiving a high ranking on the severity scale.

AIR is less significantly affected, with vulnerabilities affecting the AIR Desktop Runtime, AIR SDK & Compiler, all rated 3.

The software giant acknowledged the help of researchers from Fortinet , Google 's Project Zero , Qihoo 360 , and Alibaba in identifying the vulnerabilities fixed in this update.

This is in stark contrast to the noise Oracle has been making in recent days. A blog post by YAE's Mary Ann Davidson warned researchers not to try to find hackable vulnerabilities in their system software as reverse engineering is a violation of license agreements.

"We will not provide any credit for any advisory that may be issued, you can't really expect us to thank you for breaking the license," she wrote in her post.

The announcement was hastily deleted by Oracle , and a statement from VP Edward Screven attempted to bridge the gap that emerged in the community, claiming that the company “has a robust product security assurance program and works with third-party researchers and customers to jointly ensure that applications built with Oracle are secure.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS