PT-2013-4309 · Adobe+2 · Flash Player+2
Published
2013-07-09
·
Updated
2013-08-22
·
CVE-2013-3347
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Flash Player versions prior to 11.7.700.232
Adobe Flash Player versions 11.8.x prior to 11.8.800.94
Adobe Flash Player version 11.2.202.297 and earlier on Linux
Adobe Flash Player version 11.1.111.64 and earlier on Android 2.x and 3.x
Adobe Flash Player version 11.1.115.69 and earlier on Android 4.x
Description
The issue allows attackers to execute arbitrary code via PCM data that is not properly handled during resampling, due to an integer overflow.
Recommendations
For Adobe Flash Player on Windows and Mac OS X, update to version 11.7.700.232 or later.
For Adobe Flash Player on Linux, update to version 11.2.202.297 or later.
For Adobe Flash Player on Android 2.x and 3.x, update to version 11.1.111.64 or later.
For Adobe Flash Player on Android 4.x, update to version 11.1.115.69 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flash Player
Red Hat
Suse