The Adobe Flash Player update addresses vulnerabilities that could cause a crash and potentially allow an attacker to take control of the affected machine. Following are brief descriptions of the three flaws resolved in the update:
The Adobe Shockwave Player update addresses a critical vulnerability (CVE-2013-3348) in the software that could allow an attacker, who successfully exploits this vulnerability, to run malicious code on the affected system. The following details describe the bug fixed in the Shockwave Player update, as well as information about the hotfix for ColdFusion 10 for Mac:
ColdFusion 10 customers are not affected by CVE-2013-3349, as mentioned in Adobe’s security bulletin.
Users of Adobe Flash Player 11.7.700.225 and earlier versions for Macintosh can head over to Adobe’s site and download the 17.2 MB update to Adobe Flash Player 11.8.800.94. Adobe Flash installed with Google Chrome will automatically be updated to the latest Google Chrome version, which will include Adobe Flash Player 11.8.800.97 for Macintosh, Linux and Windows.
Users of Adobe Shockwave Player 12.0.2.122 and earlier versions can download the 13.0 MB update to Adobe Shockwave Player 12.0.3.133 from here. ColdFusion customers can update their installation using the instructions provided in Adobe’s technote located here.