Adobe released security updates for Adobe Reader X (10.1.2)
and earlier versions for Windows and Macintosh, Adobe Reader
9.4.6 and earlier 9.x versions for Linux, and Adobe Acrobat
X (10.1.2) and earlier versions for Windows and Macintosh.
These updates address vulnerabilities in the software that
could cause the application to crash and potentially allow
an attacker to take control of the affected system.
Adobe recommends users of Adobe Reader X (10.1.2) and
earlier versions for Windows and Macintosh update to Adobe
Reader X (10.1.3). For users of Adobe Reader 9.5 and earlier
versions for Windows and Macintosh, who cannot update to
Adobe Reader X (10.1.3), Adobe has made available the update
Adobe Reader 9.5.1. Adobe recommends users of Adobe Reader
9.4.6 and earlier versions for Linux update to Adobe Reader
9.5.1. Adobe recommends users of Adobe Acrobat X (10.1.2)
for Windows and Macintosh update to Adobe Acrobat X
(10.1.3). Adobe recommends users of Adobe Acrobat 9.5 and
earlier versions for Windows and Macintosh update to Adobe
Acrobat 9.5.1.
Adobe released security updates for Adobe Flash Player
11.2.202.233 and earlier versions for Windows, Macintosh and
Linux, Adobe Flash Player 11.1.115.7 and earlier versions
for Android 4.x, and Adobe Flash Player 11.1.111.8 and
earlier versions for Android 3.x and 2.x. These updates
address an object confusion vulnerability (CVE-2012-0779)
that could cause the application to crash and potentially
allow an attacker to take control of the affected system.
There are reports that the vulnerability is being exploited
in the wild in active targeted attacks designed to trick the
user into clicking on a malicious file delivered in an email
message. The exploit targets Flash Player on Internet
Explorer for Windows only.
Adobe recommends users of Adobe Flash Player 11.2.202.233
and earlier versions for Windows, Macintosh and Linux update
to Adobe Flash Player 11.2.202.235. Flash Player installed
with Google Chrome was updated automatically, so no user
action is required. Users of Adobe Flash Player 11.1.115.7
and earlier versions on Android 4.x devices should update to
Adobe Flash Player 11.1.115.8. Users of Adobe Flash Player
11.1.111.8 and earlier versions for Android 3.x and earlier
versions should update to Flash Player 11.1.111.9.
MFSA 2012-33 Potential site identity spoofing when loading
RSS and Atom feeds
MFSA 2012-32 HTTP Redirections and remote content can be
read by javascript errors
MFSA 2012-31 Off-by-one error in OpenType Sanitizer
MFSA 2012-30 Crash with WebGL content using textImage2D
MFSA 2012-29 Potential XSS through ISO-2022-KR/ISO-2022-CN
decoding issues
MFSA 2012-28 Ambiguous IPv6 in Origin headers may bypass
webserver access restrictions
MFSA 2012-27 Page load short-circuit can lead to XSS
MFSA 2012-26 WebGL.drawElements may read illegal video
memory due to FindMaxUshortElement error
MFSA 2012-25 Potential memory corruption during font
rendering using cairo-dwrite
MFSA 2012-24 Potential XSS via multibyte content processing
errors
MFSA 2012-23 Invalid frees causes heap corruption in
gfxImageSurface
MFSA 2012-22 use-after-free in IDBKeyRange
MFSA 2012-21 Multiple security flaws fixed in FreeType
v2.4.9
MFSA 2012-20 Miscellaneous memory safety hazards (rv:12.0/
rv:10.0.4)
For the protection of our customers, Apple does not
disclose, discuss, or confirm security issues until a full
investigation has occurred and any necessary patches or
releases are available. To learn more about Apple Product
Security, see the Apple Product Security website.
For information about the Apple Product Security PGP Key,
see "How to use the Apple Product Security PGP Key."
Where possible, CVE IDs are used to reference the
vulnerabilities for further information.
To learn about other Security Updates, see "Apple Security
Updates."
Adobe
Reader
Adobe Flash Player/Plugin
Adobe Air
Adobe Shockwave
Firefox
Oracle Java Runtime Apple
QuickTime
Apple
iTunes
Microsoft Silverlight
Skype
Google Chrome
CCleaner
Optional
Software
7 Zip Advanced SystemCare Auslogics Disk Defrag Audacity Defraggler Dropbox Evernote Feed Demon File Zilla Foxit Reader Google Earth Imgburn IrFanView KeePass Malwarebytes Media Player Classic MSE Antivirus NotePad++ Opera Paint.Net Picasa Pidgin PowerISO Real Player Recuva Revo Uninstaller Safari Speccy Spybot S & D Thunderbird uTorrent VLC Player Winrar Wireshark Yahoo Messenger