Уязвимость выполнения произвольного кода и проведения DoS атак в Adobe Flash Player и AIR на различных платформах
Описание
Класс NetStream в Adobe Flash Player и AIR имеет уязвимость, которая позволяет злоумышленникам выполнять произвольный код или вызывать DoS атаки через повреждение памяти с использованием неуказанных методов.
Затронутые версии ПО
- Adobe Flash Player до версии 10.3.183.18 и 11.x (до 11.2.202.228) на Windows, Mac OS X и Linux
- Adobe Flash Player до версии 10.3.183.18 и 11.x (до 11.2.202.223) на Solaris
- Adobe Flash Player до версии 11.1.111.8 на Android 2.x и 3.x
- Adobe AIR до версии 3.2.0.2070
Тип уязвимости
- Выполнение произвольного кода
- DoS атака через повреждение памяти
Ссылки
- Broken Link
- Broken Link
- Broken Link
- Broken Link
- Broken Link
- Third Party Advisory
- Broken LinkPatchVendor Advisory
- Third Party AdvisoryVDB Entry
- http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdfThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Broken Link
- Broken Link
- Broken Link
- Broken Link
- Broken Link
- Third Party Advisory
- Broken LinkPatchVendor Advisory
- Third Party AdvisoryVDB Entry
- http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdfThird Party Advisory
Уязвимые конфигурации
Одновременно
Одно из
Одно из
Одновременно
Одновременно
Одно из
Одно из
EPSS
9.3 Critical
CVSS2
Дефекты
Связанные уязвимости
The NetStream class in Adobe Flash Player before 10.3.183.18 and 11.x before 11.2.202.228 on Windows, Mac OS X, and Linux; Flash Player before 10.3.183.18 and 11.x before 11.2.202.223 on Solaris; Flash Player before 11.1.111.8 on Android 2.x and 3.x; and AIR before 3.2.0.2070 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
The NetStream class in Adobe Flash Player before 10.3.183.18 and 11.x before 11.2.202.228 on Windows, Mac OS X, and Linux; Flash Player before 10.3.183.18 and 11.x before 11.2.202.223 on Solaris; Flash Player before 11.1.111.8 on Android 2.x and 3.x; and AIR before 3.2.0.2070 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
The NetStream class in Adobe Flash Player before 10.3.183.18 and 11.x before 11.2.202.228 on Windows, Mac OS X, and Linux; Flash Player before 10.3.183.18 and 11.x before 11.2.202.223 on Solaris; Flash Player before 11.1.111.8 on Android 2.x and 3.x; and AIR before 3.2.0.2070 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
EPSS
9.3 Critical
CVSS2