Adobe.Flash.Player.Invalid.Object

NameAdobe.Flash.Player.Invalid.Object.Reference.Code.Execution
Release DateMay 22, 2009
SeverityCritical
ImpactSystem Compromise
DescriptionThis indicates an attack attempt against a remote code-execution vulnerability in the Adobe Flash Player.

The vulnerability is caused by an error when the vulnerable software handles a specially crafted SWF file. It allows a remote attacker to execute arbitrary code.
Affected ProductsAdobe Flash Player version 10.0.15.3 for Linux and prior
Adobe Flash Player version 10.0.12.36 and prior
Recommended ActionsUpgrade to Adobe Flash Player version 10.0.22.87 or 9.0.159.0:

http://www.adobe.com/go/getflash
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0520
Reference/shttp://www.securityfocus.com/bid/33880 (BugTraq)
http://www.vupen.com/english/advisories/2009/0513 (FrSIRT)
Reference: VID-17425