HIGH
flash-plugin: Buffer overflow (arbitrary code execution) via crafted SWF file.
Published Feb 26, 2009
9.3
HIGHCVSS 2.0
EPSS 28.48%
Description
Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to execute arbitrary code via a crafted file, related to a "buffer overflow issue."
Affected products
No data.
OR
- 1.5
- ≤ 10.0.12.36
- 7.0
- 7.0.1
- 7.0.25
- 7.0.63
- 7.0.63
- 7.0.69.0
- 7.0.70.0
- 7.1
- 7.1.1
- 7.2
- 8.0
- 8.0
- 8.0
- 8.0.24.0
- 8.0.34.0
- 8.0.35.0
- 8.0.39.0
- 9.0.16
- 9.0.20
- 9.0.20.0
- 9.0.28
- 9.0.28.0
- 9.0.31.0
- 9.0.45.0
- 9.0.47.0
- 9.0.48.0
- 9.0.112.0
- 9.0.114.0
- 9.0.115.0
- 9.0.124.0
- 10.0.0.584
- 10.0.12.10
- cs3
- cs4
- ≤ 10.0.15.3
- 3.0
No data.
Extras for RHEL 3
flash-plugin-0:9.0.159.0-1.el3.with.oss
Fixed · RHSA-2009:0334
Extras for RHEL 4
flash-plugin-0:9.0.159.0-1.el4
Fixed · RHSA-2009:0334
Supplementary for Red Hat Enterprise Linux 5
flash-plugin-0:10.0.22.87-1.el5
Fixed · RHSA-2009:0332
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 3 | flash-plugin-0:9.0.159.0-1.el3.with.oss | Fixed | RHSA-2009:0334 |
| Extras for RHEL 4 | flash-plugin-0:9.0.159.0-1.el4 | Fixed | RHSA-2009:0334 |
| Supplementary for Red Hat Enterprise Linux 5 | flash-plugin-0:10.0.22.87-1.el5 | Fixed | RHSA-2009:0332 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (26)
- http://isc.sans.org/diary.html?storyid=5929 x_refsource_MISCPatch
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=773 third-party-advisoryx_refsource_IDEFENSE
- http://lists.apple.com/archives/security-announce/2009/May/msg00002.html vendor-advisoryx_refsource_APPLE
- http://rhn.redhat.com/errata/RHSA-2009-0332.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2009-0334.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/34012 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/34226 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/34293 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35074 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200903-23.xml vendor-advisoryx_refsource_GENTOO
- http://securitytracker.com/id?1021750 vdb-entryx_refsource_SECTRACK
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-254909-1 vendor-advisoryx_refsource_SUNALERT
- http://support.apple.com/kb/HT3549 x_refsource_CONFIRM
- http://www.adobe.com/support/security/bulletins/apsb09-01.html x_refsource_CONFIRMPatchVendor Advisory
- http://www.securityfocus.com/bid/33880 vdb-entryx_refsource_BIDPatch
- http://www.us-cert.gov/cas/techalerts/TA09-133A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2009/0513 vdb-entryx_refsource_VUPENPatch
- http://www.vupen.com/english/advisories/2009/0743 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/1297 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2009-0520 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=487142 x_refsource_CONFIRMIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48887 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-0520
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16057 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6593 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2009-0520
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 26, 2009
Updated Aug 7, 2024
Reserved Feb 10, 2009
Link CVE-2009-0520
CISA Vulnrichment
Updated n/a