Уязвимость выполнения произвольного кода в Adobe Flash Player и Adobe AIR из-за целочисленного переполнения
Описание
Уязвимость в Adobe Flash Player и Adobe AIR позволяет злоумышленникам выполнять произвольный код на затронутых устройствах. Эта проблема вызвана целочисленным переполнением и была продемонстрирована компанией VUPEN на конкурсе Pwn2Own в ходе конференции CanSecWest 2013.
Затронутые версии ПО
- Adobe Flash Player:
- до 10.3.183.75 и 11.x до 11.7.700.169 на Windows и Mac OS X
- до 10.3.183.75 и 11.x до 11.2.202.280 на Linux
- до 11.1.111.50 на Android 2.x и 3.x
- до 11.1.115.54 на Android 4.x
- Adobe AIR: до 3.7.0.1530
- Adobe AIR SDK & Compiler: до 3.7.0.1530
Тип уязвимости
Удалённое выполнение кода
Ссылки
- Broken Link
- Permissions Required
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Broken Link
- Third Party Advisory
- Vendor Advisory
- Broken Link
- Permissions Required
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Broken Link
- Third Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Одновременно
Одновременно
Одновременно
Одно из
Одновременно
Одновременно
Одно из
Одно из
Одно из
Одновременно
Одно из
Одновременно
EPSS
10 Critical
CVSS2
Дефекты
Связанные уязвимости
Integer overflow in Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and before 11.1.115.54 on Android 4.x; Adobe AIR before 3.7.0.1530; and Adobe AIR SDK & Compiler before 3.7.0.1530 allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.
Integer overflow in Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and before 11.1.115.54 on Android 4.x; Adobe AIR before 3.7.0.1530; and Adobe AIR SDK & Compiler before 3.7.0.1530 allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.
Integer overflow in Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and before 11.1.115.54 on Android 4.x; Adobe AIR before 3.7.0.1530; and Adobe AIR SDK & Compiler before 3.7.0.1530 allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.
EPSS
10 Critical
CVSS2