Adobe patches critical vulnerabilities

By

Shockwave, Flash and Photoshop vulnerable to system hijacking, denial of service.

Adobe announced security updates for five products with four rated as a critical severity.

Adobe patches critical vulnerabilities
Rykerstribe, CC2.0

Shockwave Player, Flash Media Server, Flash Player and Photoshop CS5 all contained patches for  "critical severities", while an update rated "important" was released for RoboHelp.

The holes could allow attackers to run malicious code via Shockwave, cause a denial of service through Flash Media Server, trigger a crash and potential exploit using Flash Player, and hijack a system through a malicious .GIF file that targeted unpatched Photoshop CS5 installations.

Adobe said that the important vulnerability identified in RoboHelp 9 (versions 9.0.1.232 and earlier), RoboHelp 8, RoboHelp Server 9 and RoboHelp Server 8 could allow a specially crafted URL to create a cross-site scripting attack on RoboHelp installations.

This article originally appeared at scmagazineuk.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Phishing attack nets enormous npm supply chain compromise

Phishing attack nets enormous npm supply chain compromise

Service NSW centralises security, networking in mammoth CloudOps overhaul

Service NSW centralises security, networking in mammoth CloudOps overhaul

VicRoads to phase out passwords in favour of passkeys

VicRoads to phase out passwords in favour of passkeys

Apple adds "mercenary spyware" protection to new A19 chip

Apple adds "mercenary spyware" protection to new A19 chip

Log In

  |  Forgot your password?