flash-plugin: multiple code execution or security bypass flaws (APSB14-18)
Published Aug 12, 2014
10.0
HIGHCVSS 2.0
EPSS 3.98%
Description
Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2014-0540, CVE-2014-0542, CVE-2014-0544, and CVE-2014-0545.
Affected products
No data.
Configuration 1
- ≤ 13.0.0.231
- 13.0.0.182
- 13.0.0.201
- 13.0.0.206
- 13.0.0.214
- 13.0.0.223
- 14.0.0.125
- 14.0.0.145
Configuration 2
- ≤ 11.2.202.394
- 11.2.202.223
- 11.2.202.228
- 11.2.202.233
- 11.2.202.235
- 11.2.202.236
- 11.2.202.238
- 11.2.202.243
- 11.2.202.251
- 11.2.202.258
- 11.2.202.261
- 11.2.202.262
- 11.2.202.270
- 11.2.202.273
- 11.2.202.275
- 11.2.202.280
- 11.2.202.285
- 11.2.202.291
- 11.2.202.297
- 11.2.202.310
- 11.2.202.332
- 11.2.202.335
- 11.2.202.336
- 11.2.202.341
- 11.2.202.346
- 11.2.202.350
- 11.2.202.356
- 11.2.202.359
- 11.2.202.378
Running on/with
- n/a
Configuration 3
- ≤ 14.0.0.137
- 13.0.0.83
- 13.0.0.111
- 14.0.0.110
Configuration 4
No data.
Supplementary for Red Hat Enterprise Linux 5
flash-plugin-0:11.2.202.400-1.el5
Fixed · RHSA-2014:1051
Supplementary for Red Hat Enterprise Linux 6
flash-plugin-0:11.2.202.400-1.el6
Fixed · RHSA-2014:1051
| Product | Package | State | Advisory |
|---|---|---|---|
| Supplementary for Red Hat Enterprise Linux 5 | flash-plugin-0:11.2.202.400-1.el5 | Fixed | RHSA-2014:1051 |
| Supplementary for Red Hat Enterprise Linux 6 | flash-plugin-0:11.2.202.400-1.el6 | Fixed | RHSA-2014:1051 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- http://helpx.adobe.com/security/products/flash-player/apsb14-18.html x_refsource_CONFIRMPatchVendor Advisory
- http://secunia.com/advisories/60710 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60732 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-201408-05.xml vendor-advisoryx_refsource_GENTOO
- http://www.securitytracker.com/id/1030712 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2014-0543 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1129417 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-0574 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-0543
- https://www.cve.org/CVERecord?id=CVE-2014-0543
| Link | Providers | Tags |
|---|---|---|
| http://helpx.adobe.com/security/products/flash-player/apsb14-18.html | x_refsource_CONFIRMPatchVendor Advisory | |
| http://secunia.com/advisories/60710 | third-party-advisoryx_refsource_SECUNIA | |
| http://secunia.com/advisories/60732 | third-party-advisoryx_refsource_SECUNIA | |
| http://security.gentoo.org/glsa/glsa-201408-05.xml | vendor-advisoryx_refsource_GENTOO | |
| http://www.securitytracker.com/id/1030712 | vdb-entryx_refsource_SECTRACK | |
| https://access.redhat.com/security/cve/CVE-2014-0543 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1129417 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-0574 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2014-0543 | ||
| https://www.cve.org/CVERecord?id=CVE-2014-0543 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data