Adobe Flash Player / AIR Memory Corruption Vulnerability
RISK: High Risk
TYPE: Clients - Audio & Video
Multiple vulnerabilities have been identified in Adobe Flash Player and Adobe AIR. A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create specially crafted content that, when loaded by the target user, will trigger a memory corruption error and execute arbitrary code on the target system. The code will run with the privileges of the target user.
Impact
- Remote Code Execution
System / Technologies affected
- Adobe Flash Player versions prior to 11.7.700.202 for Windows and Mac, 11.2.202.285 for Linux, 11.1.111.54 for Android 2.x and 3.x, 11.1.115.58 for Android 4.x, 11.7.700.202 for Google Chrome, 11.7.700.202 for IE10
- Adobe AIR versions 3.7.0.1530 and prior for Windows and Macintosh
- Adobe AIR versions 3.7.0.1660 and prior for Android
- Adobe AIR SDK & Compiler versions 3.7.0.1530 and prior
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix.
http://www.adobe.com/support/security/bulletins/apsb13-14.html
Vulnerability Identifier
- CVE-2013-2728
- CVE-2013-3324
- CVE-2013-3325
- CVE-2013-3326
- CVE-2013-3327
- CVE-2013-3328
- CVE-2013-3329
- CVE-2013-3330
- CVE-2013-3331
- CVE-2013-3332
- CVE-2013-3333
- CVE-2013-3334
- CVE-2013-3335
Source
Related Link
Share with