CERT-In Advisory
CIAD-2012-0042
Multiple Vulnerabilities in Adobe Flash Player
Original Issue Date: August 24, 2012
Severity Rating: High
Systems Affected
- Adobe Flash Player 11.3.300.271 and earlier versions for Windows, Macintosh and Linux operating systems
- Adobe Flash Player 11.1.115.11 and earlier versions for Android 4.x
- Adobe Flash Player 11.1.111.10 and earlier versions for Android 3.x and 2.x
- Adobe AIR 3.3.0.3670 and earlier versions for Windows and Macintosh
- Adobe AIR 3.3.0.3690 SDK (includes AIR for iOS) and earlier versions
- Adobe AIR 3.3.0.3650 and earlier versions for Android
Overview
Multiple vulnerabilities have been reported in Adobe Flash Player that could allow an attacker to take control of the affected system.
Description
1. Memory corruption vulnerabilities
(
CVE-2012-4163
CVE-2012-4164
CVE-2012-4165
CVE-2012-4166
)
A remote user can create specially crafted content that, when loaded by the target user, will trigger a memory corruption error and execute arbitrary code or cause a denial of service on the target system.
2. Integer overflow vulnerability
(
CVE-2012-4167
)
A remote user can create specially crafted content that, when loaded by the target user, will trigger a integer overflow and execute arbitrary code on the target system.
3. Cross-domain information disclosure vulnerability
(
CVE-2012-4168
)
A remote attacker could read content from a different domain via a crafted web site.
Solution
Apply appropriate updates as mentioned in the Adobe Security Bulletin
APSB12-19 .
Vendor Information
Adobe
http://www.adobe.com/support/security/bulletins/apsb12-19.html
References
Secunia
http://secunia.com/advisories/50354/
SecurityTracker
http://www.securitytracker.com/id/1027422
CVE Name
CVE-2012-4163
CVE-2012-4164
CVE-2012-4165
CVE-2012-4166
CVE-2012-4167
CVE-2012-4168
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|