Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-0611

Опубликовано: 13 апр. 2011
Источник: ubuntu
Приоритет: medium
CVSS2: 9.3
CVSS3: 8.8

Описание

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.

РелизСтатусПримечание
dapper

ignored

devel

DNE

hardy

not-affected

karmic

not-affected

lucid

not-affected

maverick

not-affected

natty

not-affected

upstream

not-affected

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

released

10.2.159.1-0hardy1
karmic

released

10.2.159.1-0karmic1
lucid

released

10.2.159.1-0lucid1
maverick

released

10.2.159.1-0maverick1
natty

released

10.2.159.1-0natty1
upstream

released

10.2.159.1

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

ignored

end of life
lucid

released

1:2.6.0.19140-0lucid1
maverick

released

1:2.6.0.19140-0maverick1
natty

released

1:2.6.0.19140-0natty1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

hardy

released

10.2.159.1ubuntu0.8.04.1
karmic

released

10.2.159.1ubuntu0.9.10.1
lucid

released

10.2.159.1ubuntu0.10.04.1
maverick

released

10.2.159.1ubuntu0.10.10.1
natty

released

10.2.159.1ubuntu1
upstream

released

10.2.159.1

Показывать по

9.3 Critical

CVSS2

8.8 High

CVSS3

Связанные уязвимости

redhat
больше 14 лет назад

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.

CVSS3: 8.8
nvd
больше 14 лет назад

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.

CVSS3: 8.8
github
больше 3 лет назад

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.

CVSS3: 8.8
fstec
больше 14 лет назад

Уязвимость библиотеки Authplay.dll (AuthPlayLib.bundle) программной платформы Flash Player, программ просмотра и редактирования PDF-файлов Adobe Reader и Adobe Acrobat, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

9.3 Critical

CVSS2

8.8 High

CVSS3