Adobe released two security bulletins for today's patch tuesday kickoff: APSB12-02 [1]: Security update for Adobe Shockwave Player This patch fixes a total of 9 vulnerabilities that affect Shockwave Player 11.6.3.633 and earlier on Windows and OS X. After the update is applied, you should be at version 11.6.4.634. Adobe rates these vulnerabilities critical as some of them allow the execution of arbitrary code. RoboHelp is not as commonly installed as other Adobe products. This patch fixes one vulnerability that is considered important. The vulnerability introduces a cross site scripting flaw in output generated by RoboHelp. I am not that familiar with the product, but even though Adobe doesn't specify it, it sounds like it may be necessary to re-create RoboHelp output after the update is applied to avoid the XSS issue in content generated with older versions.
[1] http://www.adobe.com/support/security/bulletins/apsb12-02.html ------ |
Johannes 4068 Posts ISC Handler Feb 14th 2012 |
Thread locked Subscribe |
Feb 14th 2012 9 years ago |
Sign Up for Free or Log In to start participating in the conversation!