Home→Descriptions→SA44590
| Secunia ID | |
| CVE-ID |
CVE-2011-0579, CVE-2011-0618, CVE-2011-0619, CVE-2011-0620, CVE-2011-0621, CVE-2011-0622, CVE-2011-0623, CVE-2011-0624, CVE-2011-0625, CVE-2011-0626, CVE-2011-0627, CVE-2011-0628 |
| Release Date |
13 May 2011 |
| Last Change |
26 May 2011 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Software |
Adobe Flash Player 10.x |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. Exposure of sensitive informationVulnerabilities where documents or credentials are leaked or can be revealed either locally or from remote. |
| Description |
Multiple vulnerabilities have been reported in Adobe Flash Player, which can be exploited by malicious people to disclose potentially sensitive information and compromise a user's system. 1) An unspecified error can be exploited to disclose certain information. 2) An integer overflow error in the ActionScript Virtual Machine (AVM) when parsing the "method_body_info" structure can be exploited to potentially execute arbitrary code. 3) An unspecified error can be exploited to corrupt memory. 4) A boundary error within certain ActionScript functions can be exploited to cause a heap-based buffer overflow and potentially execute arbitrary code. 5) A third unspecified error can be exploited to corrupt memory. 6) A fourth unspecified error can be exploited to corrupt memory. 7) A boundary error can be exploited to potentially execute arbitrary code. 8) A second boundary error can be exploited to potentially execute arbitrary code. 9) A third boundary error can be exploited to potentially execute arbitrary code. 10) A fourth boundary error can be exploited to potentially execute arbitrary code. 11) An unspecified error can be exploited to corrupt memory. 12) An integer overflow error within an ActionScript method when handling certain parameters can be exploited to corrupt memory and potentially execute arbitrary code. The vulnerabilities are reported in the following versions: |
| Solution |
Apply updates. Adobe Flash Player: Adobe Flash Player for Android: |
| Reported by |
1, 11) Reported by the vendor. The vendor also credits the following people: |
| Original Advisory |
Adobe (APSB11-12): iDefense: |