Description: | Summary: Adobe Flash Player/Air is prone to multiple vulnerabilities.
Vulnerability Insight: Multiple flaws exist due to:
- An error occurred while parsing JPEG dimensions contained within an SWF file can be exploited to cause a heap-based buffer overflow.
- An unspecified error may allow injection of data and potentially lead to execution of arbitrary code.
- An unspecified error possibly related to 'getProperty()' can be exploited to corrupt memory and may allow execution of arbitrary code.
- An unspecified error can be exploited to corrupt memory and may allow execution of arbitrary code.
- An integer overflow error when generating ActionScript exception handlers in 'Verifier::parseExceptionHandlers()' can be exploited to corrupt memory.
- Various unspecified errors may potentially allow execution of arbitrary code.
- An error may disclose information about local file names.
Vulnerability Impact: Successful exploitation will allow remote attackers to execute arbitrary code, gain elevated privileges, gain knowledge of certain information and conduct clickjacking attacks.
Affected Software/OS: Adobe AIR version prior to 1.5.3
Adobe Flash Player 10 version prior to 10.0.42.34 on Windows
Solution: Update to Adobe Air 1.5.3 or Adobe Flash Player 10.0.42.34.
CVSS Score: 9.3
CVSS Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
|