First published: Tue Dec 08 2009(Updated: )
Adobe Flash Player 10.x before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/flash-plugin | <0:10.0.42.34-1.el5 | 0:10.0.42.34-1.el5 |
Adobe | =1.0 | |
Adobe | =1.5.1 | |
Macromedia Flash Player | =10.0.12.36 | |
Macromedia Flash Player | =10.0.0.584 | |
Macromedia Flash Player | =10.0.22.87 | |
Macromedia Flash Player | =10.0.32.18 | |
Adobe | <=1.5.2 | |
Adobe | =1.0.1 | |
Adobe | =1.1 | |
Macromedia Flash Player | =10.0.12.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3797 has a critical severity level due to its potential for allowing attackers to execute arbitrary code.
To fix CVE-2009-3797, upgrade Adobe Flash Player to version 10.0.42.34 or later, and Adobe AIR to version 1.5.3 or later.
CVE-2009-3797 affects Adobe Flash Player versions before 10.0.42.34 and Adobe AIR versions before 1.5.3.
CVE-2009-3797 is a memory corruption vulnerability that can be exploited to execute arbitrary code.
Users of Adobe Flash Player 10.x before 10.0.42.34 and Adobe AIR before 1.5.3 are at risk from CVE-2009-3797.