PT-2012-1743 · Adobe+2 · Flash+2

Published

2012-03-08

·

Updated

2018-01-05

·

CVE-2011-3845

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apple Safari version 5.1.2
Description The issue is related to a use-after-free vulnerability that occurs when a plug-in with a blocking function is installed. This allows remote attackers to execute arbitrary code via a crafted web page that is accessed during user interaction with the plug-in. The vulnerability is caused by improper coordination between an API call and the plug-in unloading functionality. This has been demonstrated with the Adobe Flash and RealPlayer plug-ins.
Recommendations For Apple Safari version 5.1.2, consider disabling the use of plug-ins, especially those with blocking functions, until a patch is available. Restrict access to potentially vulnerable API calls to minimize the risk of exploitation. Avoid using the affected Safari version for sensitive tasks until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-3845

Affected Products

Flash
Realplayer
Safari