CERT-In Advisory
CIAD-2012-0047
Multiple Vulnerabilities in Adobe Flash Player/AIR
Original Issue Date: October 15, 2012
Severity Rating: High
Systems Affected
- Adobe Flash Player 11.4.402.278 and earlier versions for Windows
- Adobe Flash Player 11.4.402.265 and earlier versions for Macintosh
- Adobe Flash Player 11.2.202.238 and earlier versions for Linux
- Adobe Flash Player 11.1.115.17 and earlier versions for Android 4.x
- Adobe Flash Player 11.1.111.16 and earlier versions for Android 3.x and 2.x
- Adobe AIR 3.4.0.2540 and earlier versions for Windows and Macintosh
- Adobe AIR 3.4.0.2540 SDK (includes AIR for iOS) and earlier versions
- Adobe AIR 3.4.0.2540 and earlier versions for Android
Overview
Multiple vulnerabilities have been reported in Adobe Flash Player and Adobe AIR, which could allow a remote attacker to execute arbitrary code on the target system with the privileges of the target user.
Description
Multiple buffer overflow and memory corruption vulnerabilities exist in Adobe products, which could be exploited by remote attackers to execute arbitrary code on the target system.
Failed exploitation attempts will likely cause denial of service conditions.
Solution
Apply appropriate updates as mentioned in the Adobe Security Bulletin
APSB12-22
Vendor Information
Adobe
http://www.adobe.com/support/security/bulletins/apsb12-22.html
References
Adobe
http://www.adobe.com/support/security/bulletins/apsb12-22.html
Secunia
http://secunia.com/advisories/50876/
SecurityTracker
http://securitytracker.com/id/1027624
Security Focus
http://www.securityfocus.com/bid/55827/
CVE Name
CVE-2012-5248
CVE-2012-5249
CVE-2012-5250
CVE-2012-5251
CVE-2012-5252
CVE-2012-5253
CVE-2012-5254
CVE-2012-5255
CVE-2012-5256
CVE-2012-5257
CVE-2012-5258
CVE-2012-5259
CVE-2012-5260
CVE-2012-5261
CVE-2012-5262
CVE-2012-5263
CVE-2012-5264
CVE-2012-5265
CVE-2012-5266
CVE-2012-5267
CVE-2012-5268
CVE-2012-5269
CVE-2012-5270
CVE-2012-5271
CVE-2012-5272
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|