PT-2014-1367 · Adobe+3 · Pepper Flash+5
Publicado
2014-08-12
·
Atualizado
2017-01-07
·
CVE-2014-0540
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe AIR (affected versions not specified)
Adobe Flash Player (affected versions not specified)
Adobe Pepper Flash for Google Chrome (affected versions not specified)
Description
The issue exists due to the possibility of accessing information related to memory addresses, allowing an attacker to bypass the ASLR (Address Space Layout Randomization) protection mechanism. This can be exploited to gain unauthorized access to sensitive information.
Recommendations
For Adobe AIR, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Adobe Flash Player, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Adobe Pepper Flash for Google Chrome, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Air
Flash Player
Pepper Flash
Red Hat
Suse