CERT-In Advisory
CIAD-2014-0054
Multiple Vulnerabilities in Adobe Flash Player and Adobe AIR
Original Issue Date: September 10, 2014
Severity Rating: High
Systems Affected
- Adobe Flash Player 14.0.0.179 and earlier versions
- Adobe Flash Player 13.0.0.241 and earlier 13.x versions
- Adobe Flash Player 11.2.202.400 and earlier versions for Linux
- Adobe AIR desktop runtime 14.0.0.178 and earlier versions
- Adobe AIR SDK 14.0.0.178 and earlier versions
- Adobe AIR SDK & Compiler 14.0.0.178 and earlier versions
- Adobe AIR 14.0.0.179 and earlier versions for Android
Overview
Multiple vulnerabilities have been reported in Adobe Flash Player and Adobe AIR which could allow an unauthenticated remote attacker to execute arbitrary code, bypass security restrictions or bypass memory address randomization to take complete control of the affected system.
Description
1. Memory leakage vulnerability
(
CVE-2014-0557
)
Memory leakage vulnerability has been reported in Adobe Flash Player and Adobe AIR. This vulnerability is caused due to multiple Adobe products does not properly restrict discovery of memory addresses. A remote attacker could exploit this vulnerability via unspecified vectors. Successful exploitation of this vulnerability could allow remote attackers to bypass the ASLR protection mechanism.
2. Security Bypass vulnerability
(
CVE-2014-0554
)
This vulnerability exists due to unspecified errors in Adobe Flash player and Adobe AIR. Attackers could exploit this vulnerability via unspecified vectors. Successful exploitation of this vulnerability could allow attackers to bypass intended access restrictions and gain access to sensitive information.
3. Use-After-Free Vulnerability
(
CVE-2014-0553
)
Use-After-Free Vulnerability has been reported in Adobe Flash Player and Adobe AIR. Attackers could exploit this vulnerability via unspecified vectors. Successful exploitation of this vulnerability could allow attackers to execute arbitrary code on the targeted system.
4. Memory Corruption Vulnerability
(
CVE-2014-0547
CVE-2014-0549
CVE-2014-0550
CVE-2014-0551
CVE-2014-0552
CVE-2014-0555
)
These vulnerabilities are caused due to memory corruption errors in Adobe Flash Player and Adobe AIR. A remote attacker could exploit these vulnerabilities by enticing a user to visit a malicious webpage containing specially crafted flash content. Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary code or cause a denial of service condition (memory corruption) on the affected system.
5. Same Origin Policy Bypass vulnerability
(
CVE-2014-0548
)
This vulnerability is caused due to unspecified vectors in Adobe Flash Player and Adobe AIR. Successful exploitation of these vulnerabilities could allow remote attackers to bypass same origin policy security restrictions.
6. Heap-based Buffer Overflow Vulnerability
(
CVE-2014-0556
CVE-2014-0549
)
Heap-based buffer overflow vulnerabilities have been reported in Adobe Flash Player and Adobe AIR. Successful exploitation of these vulnerabilities could allow remote attackers to execute arbitrary code on the affected system via unspecified vectors.
Solution
Apply appropriate patches as mentioned in Adobe Security Bulletin
APSB14-21
Vendor Information
Adobe
http://helpx.adobe.com/security/products/flash-player/apsb14-21.html
References
SecurityTracker
http://www.securitytracker.com/id/1030822
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=35659
http://www.scip.ch/en/?vuldb.67473
RedHat
https://bugzilla.redhat.com/show_bug.cgi?id=1139847
CVE Name
CVE-2014-0557
CVE-2014-0553
CVE-2014-0547
CVE-2014-0549
CVE-2014-0550
CVE-2014-0551
CVE-2014-0552
CVE-2014-0555
CVE-2014-0548
CVE-2014-0559
CVE-2014-0556
CVE-2014-0554
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|