Adobe Flash Player Remote Code Execution Vulnerability
Last Update Date:
21 Feb 2014 11:56
Release Date:
21 Feb 2014
4234
Views
RISK: Extremely High Risk
TYPE: Clients - Audio & Video
A vulnerability was identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create a specially crafted file that, when loaded by the target user, will execute arbitrary code on the target system.
- A stack overflow may occur.
- A memory leak may occur, allowing a remote user to bypass memory address layout randomization.
- A double free memory error may occur. This vulnerability is being actively exploited.
Impact
- Remote Code Execution
System / Technologies affected
- Adobe Flash Player 12.0.0.44 and earlier versions for Windows and Macintosh
- Adobe Flash Player 11.2.202.336 and earlier versions for Linux
- Adobe AIR 4.0.0.1390 and earlier versions for Android
- Adobe AIR 3.9.0.1390 SDK and earlier versions
- Adobe AIR 3.9.0.1390 SDK & Compiler and earlier versions
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix (12.0.0.70 for Windows and Mac, 11.2.202.341 for Linux).
The vendor's advisory is available at:
http://helpx.adobe.com/security/products/flash-player/apsb14-07.html
Vulnerability Identifier
Source
Related Link
Share with