Back

HIGH

flash-plugin: arbitrary code execution via unspecified vulnerability

Published Dec 7, 2011

Description

Unspecified vulnerability in Adobe Flash Player 11.1.102.55 on Windows and Mac OS X allows remote attackers to execute arbitrary code via a crafted SWF file, as demonstrated by the first of two vulnerabilities exploited by the Intevydis vd_adobe_fp module in VulnDisco Step Ahead (SA). NOTE: as of 20111207, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

Affected products

Remediation

Red Hat statement

We do not currently plan to fix this issue due to the lack of further information about the flaw and its impact. If more information becomes available at a future date, we may revisit the issue.

Metrics

Weaknesses (0)

No CWE recorded.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 7, 2011
Updated Aug 7, 2024
Reserved Dec 7, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Dec 6, 2011