PT-2013-4309 · Adobe+2 · Flash Player+2

Published

2013-07-09

·

Updated

2013-08-22

·

CVE-2013-3347

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Flash Player versions prior to 11.7.700.232 Adobe Flash Player versions 11.8.x prior to 11.8.800.94 Adobe Flash Player version 11.2.202.297 and earlier on Linux Adobe Flash Player version 11.1.111.64 and earlier on Android 2.x and 3.x Adobe Flash Player version 11.1.115.69 and earlier on Android 4.x
Description The issue allows attackers to execute arbitrary code via PCM data that is not properly handled during resampling, due to an integer overflow.
Recommendations For Adobe Flash Player on Windows and Mac OS X, update to version 11.7.700.232 or later. For Adobe Flash Player on Linux, update to version 11.2.202.297 or later. For Adobe Flash Player on Android 2.x and 3.x, update to version 11.1.111.64 or later. For Adobe Flash Player on Android 4.x, update to version 11.1.115.69 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3347
MGASA-2013-0207
OPENSUSE-SU-2013_1191-1
OPENSUSE-SU-2013_1192-1
RHSA-2013:1035
RHSA-2013_1035
ZDI-13-177

Affected Products

Flash Player
Red Hat
Suse