flash-plugin: critical flaws fixed in APSB11-26
Published Sep 22, 2011
9.3
HIGHCVSS 2.0
EPSS 6.36%
Description
Stack-based buffer overflow in the ActionScript Virtual Machine (AVM) component in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows attackers to execute arbitrary code or cause a denial of service via unspecified vectors.
Affected products
No data.
Configuration 1
- ≤ 10.3.183.7
- 6.0.21.0
- 6.0.79
- 7.0
- 7.0.1
- 7.0.14.0
- 7.0.19.0
- 7.0.24.0
- 7.0.25
- 7.0.53.0
- 7.0.60.0
- 7.0.61.0
- 7.0.63
- 7.0.66.0
- 7.0.67.0
- 7.0.68.0
- 7.0.69.0
- 7.0.70.0
- 7.0.73.0
- 7.1
- 7.1.1
- 7.2
- 8.0
- 8.0.22.0
- 8.0.24.0
- 8.0.33.0
- 8.0.34.0
- 8.0.35.0
- 8.0.39.0
- 8.0.42.0
- 9.0
- 9.0.16
- 9.0.18d60
- 9.0.20
- 9.0.20.0
- 9.0.28
- 9.0.28.0
- 9.0.31
- 9.0.31.0
- 9.0.45.0
- 9.0.47.0
- 9.0.48.0
- 9.0.112.0
- 9.0.114.0
- 9.0.115.0
- 9.0.124.0
- 9.0.125.0
- 9.0.151.0
- 9.0.152.0
- 9.0.155.0
- 9.0.159.0
- 9.0.246.0
- 9.0.260.0
- 9.0.262.0
- 9.0.277.0
- 9.0.283.0
- 9.125.0
- 10.0.0.584
- 10.0.12.10
- 10.0.12.36
- 10.0.15.3
- 10.0.22.87
- 10.0.32.18
- 10.0.42.34
- 10.0.45.2
- 10.1.52.14.1
- 10.1.52.15
- 10.1.53.64
- 10.1.82.76
- 10.1.85.3
- 10.1.92.8
- 10.1.92.10
- 10.1.95.1
- 10.1.95.2
- 10.1.102.64
- 10.2.152
- 10.2.152.32
- 10.2.152.33
- 10.2.154.13
- 10.2.154.25
- 10.2.159.1
- 10.3.181.14
- 10.3.181.16
- 10.3.181.23
- 10.3.181.34
- 10.3.181.36
- 10.3.183.5
Configuration 2
- ≤ 10.3.186.6
- 10.1.92.8
- 10.1.92.10
- 10.1.95.2
- 10.1.105.6
- 10.1.106.16
- 10.2.156.12
- 10.2.157.51
- 10.3.185.21
- 10.3.185.23
- 10.3.185.25
- 10.3.186.3
No data.
Extras for RHEL 4
acroread-0:9.4.6-1.el4
Fixed · RHSA-2011:1434
Red Hat Enterprise Linux 6 Supplementary
acroread-0:9.4.6-1.el6
Fixed · RHSA-2011:1434
Red Hat Enterprise Linux 6 Supplementary
flash-plugin-0:10.3.183.10-1.el6
Fixed · RHSA-2011:1333
Supplementary for Red Hat Enterprise Linux 5
acroread-0:9.4.6-1.el5
Fixed · RHSA-2011:1434
Supplementary for Red Hat Enterprise Linux 5
flash-plugin-0:10.3.183.10-1.el5
Fixed · RHSA-2011:1333
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 4 | acroread-0:9.4.6-1.el4 | Fixed | RHSA-2011:1434 |
| Red Hat Enterprise Linux 6 Supplementary | acroread-0:9.4.6-1.el6 | Fixed | RHSA-2011:1434 |
| Red Hat Enterprise Linux 6 Supplementary | flash-plugin-0:10.3.183.10-1.el6 | Fixed | RHSA-2011:1333 |
| Supplementary for Red Hat Enterprise Linux 5 | acroread-0:9.4.6-1.el5 | Fixed | RHSA-2011:1434 |
| Supplementary for Red Hat Enterprise Linux 5 | flash-plugin-0:10.3.183.10-1.el5 | Fixed | RHSA-2011:1333 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00025.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/48308 third-party-advisoryx_refsource_SECUNIA
- http://www.adobe.com/support/security/bulletins/apsb11-26.html x_refsource_CONFIRMPatchVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1333.html vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2011-2427 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=740388 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2011-2427
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14125 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15950 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2011-2427
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00025.html | vendor-advisoryx_refsource_SUSE | |
| http://secunia.com/advisories/48308 | third-party-advisoryx_refsource_SECUNIA | |
| http://www.adobe.com/support/security/bulletins/apsb11-26.html | x_refsource_CONFIRMPatchVendor Advisory | |
| http://www.redhat.com/support/errata/RHSA-2011-1333.html | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2011-2427 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=740388 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2011-2427 | ||
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14125 | vdb-entrysignaturex_refsource_OVAL | |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15950 | vdb-entrysignaturex_refsource_OVAL | |
| https://www.cve.org/CVERecord?id=CVE-2011-2427 |
Change history (0)
No recorded changes yet.