CERT-In Vulnerability Note
CIVN-2013-0206
Memory Corruption Vulnerabilities in Adobe Flash Player and Adobe AIR
Original Issue Date:November 14, 2013
Severity Rating: HIGH
Systems Affected
- Adobe Flash Player 11.9.900.117 and earlier versions for Windows and Macintosh
- Adobe Flash Player 11.2.202.310 and earlier versions for Linux
- Adobe AIR 3.9.0.1030 and earlier versions for Windows and Macintosh
- Adobe AIR 3.9.0.1060 and earlier versions for Android
- Adobe AIR 3.9.0.1030 SDK and earlier versions
- Adobe AIR 3.9.0.1030 SDK & Compiler and earlier versions
Overview
Memory corruption vulnerabilities has been reported in Adobe Flash Player and Adobe AIR due to unspecified errors during processing of flash content by the affected software which could allow a remote attackers to execute arbitrary code on the affected system.
Description
Remote memory corruption vulnerabilities exists in Adobe Flash player and Adobe AIR which could leads to arbitrary code execution. An unauthenticated remote attacker could exploit this vulnerability by enticing targeted user to visit malicious link which contains crafted flash content.
Upon loading this crafted flash content, a memory corruption error may occur which could allow remote attacker to execute arbitrary code on the target system with the privileges of currently logged in user.
Solution
Apply appropriate updates as mentioned in
APSB13-26
Vendor Information
Adobe
https://www.adobe.com/support/security/bulletins/apsb13-26.html
References
Adobe
https://www.adobe.com/support/security/bulletins/apsb13-26.html
Microsoft
http://technet.microsoft.com/en-us/security/advisory/2755801
Secunia
http://secunia.com/advisories/55527/
OSVDB
http://osvdb.org/show/osvdb/99655
http://osvdb.org/show/osvdb/99656
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=31734
Securelist
http://www.securelist.com/en/advisories/55534
CVE Name
CVE-2013-5329
CVE-2013-5330
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|