English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Adobe Flash Player Multiple Vulnerabilities


Secunia ID

SA44590

CVE-ID

CVE-2011-0579, CVE-2011-0618, CVE-2011-0619, CVE-2011-0620, CVE-2011-0621, CVE-2011-0622, CVE-2011-0623, CVE-2011-0624, CVE-2011-0625, CVE-2011-0626, CVE-2011-0627, CVE-2011-0628

Release Date

13 May 2011

Last Change

26 May 2011

Criticality

Highly Critical

Solution Status

Vendor Patch

Software

Adobe Flash Player 10.x

Where

From remote

Impact
System access

This covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user.

Exposure of sensitive information

Vulnerabilities where documents or credentials are leaked or can be revealed either locally or from remote.

Description

Multiple vulnerabilities have been reported in Adobe Flash Player, which can be exploited by malicious people to disclose potentially sensitive information and compromise a user's system.

1) An unspecified error can be exploited to disclose certain information.

2) An integer overflow error in the ActionScript Virtual Machine (AVM) when parsing the "method_body_info" structure can be exploited to potentially execute arbitrary code.

3) An unspecified error can be exploited to corrupt memory.

4) A boundary error within certain ActionScript functions can be exploited to cause a heap-based buffer overflow and potentially execute arbitrary code.

5) A third unspecified error can be exploited to corrupt memory.

6) A fourth unspecified error can be exploited to corrupt memory.

7) A boundary error can be exploited to potentially execute arbitrary code.

8) A second boundary error can be exploited to potentially execute arbitrary code.

9) A third boundary error can be exploited to potentially execute arbitrary code.

10) A fourth boundary error can be exploited to potentially execute arbitrary code.

11) An unspecified error can be exploited to corrupt memory.

12) An integer overflow error within an ActionScript method when handling certain parameters can be exploited to corrupt memory and potentially execute arbitrary code.

The vulnerabilities are reported in the following versions:
* Adobe Flash Player 10.2.159.1 and earlier for Windows, Macintosh, Linux and Solaris.
* Adobe Flash Player 10.2.154.28 and earlier for Chrome.
* Adobe Flash Player 10.2.157.51 and earlier for Android.

Solution

Apply updates.

Adobe Flash Player:
Update to version 10.3.181.14.

Adobe Flash Player for Android:
Update to version 10.3.185.21 via the Android Marketplace.

Reported by

1, 11) Reported by the vendor.
2) binaryproof via iDefense
4, 12) Vitaliy Toropov via iDefense

The vendor also credits the following people:
3) Marc Schoenefeld, Red Hat Security Response Team
5) Bo Qu, Palo Alto Networks
6) Honggang Ren, Fortinet's FortiGuard Labs
7) Yamata Li, Palo Alto Networks
8, 9, 10) Tavis Ormandy, Google Security Team
9, 10) Will Dormann, US-CERT

Original Advisory

Adobe (APSB11-12):
http://www.adobe.com/support/security/bulletins/apsb11-12.html

iDefense:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=902
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=903
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=908