PT-2007-7461 · Adobe+4 · Pepper Flash+6

Publicado

1970-01-01

·

Atualizado

2017-01-07

·

CVE-2014-0545

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Pepper Flash for Google Chrome (affected versions not specified) Adobe AIR (affected versions not specified) Adobe Flash Player (affected versions not specified)
Description The issue exists due to the possibility of accessing information related to memory addresses, allowing an attacker to bypass the ASLR (Address Space Layout Randomization) protection mechanism. This can be exploited to gain unauthorized access to sensitive information.
Recommendations For Adobe Pepper Flash for Google Chrome, consider disabling the flash plugin until a patch is available. For Adobe AIR, restrict access to sensitive information and functions that may be exploited through this issue until a fix is provided. For Adobe Flash Player, avoid using versions that are affected by this issue and consider applying configuration changes to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-2010
BDU:2015-00232
BDU:2015-00340
BDU:2015-00341
CVE-2014-0545
MGASA-2014-0335
OPENSUSE-SU-2014_1020-1
OPENSUSE-SU-2014_1029-1
RHSA-2014:1051
RHSA-2014_1051

Produtos afetados

Alt Linux
Air
Flash Player
Pepper Flash
Google Chrome
Red Hat
Suse