English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Adobe Flash Player Multiple Vulnerabilities


Secunia ID

SA45583

CVE-ID

CVE-2011-2130, CVE-2011-2134, CVE-2011-2135, CVE-2011-2136, CVE-2011-2137, CVE-2011-2138, CVE-2011-2139, CVE-2011-2140, CVE-2011-2414, CVE-2011-2415, CVE-2011-2416, CVE-2011-2417, CVE-2011-2424, CVE-2011-2425

Release Date

10 Aug 2011

Last Change

17 Feb 2012

Criticality

Highly Critical

Solution Status

Vendor Patch

Software

Adobe AIR 2.x
Adobe Flash Player 10.x

Where

From remote

Impact
System access

This covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user.

Exposure of sensitive information

Vulnerabilities where documents or credentials are leaked or can be revealed either locally or from remote.

Description

Multiple vulnerabilities have been reported in Adobe Flash Player, which can be exploited by malicious people to disclose sensitive information and compromise a user's system.

1) An unspecified error can be exploited to cause a buffer overflow and potentially execute arbitrary code.

2) An unspecified error can be exploited to cause a buffer overflow and potentially execute arbitrary code.

3) An error exists within a certain ActionScript function in the "flash.display" class when parsing certain parameters and can be exploited to corrupt memory and potentially execute arbitrary code.

4) An integer overflow error within a certain ActionScript function can be exploited to corrupt memory and potentially execute arbitrary code.

5) An unspecified error can be exploited to cause a buffer overflow and potentially execute arbitrary code.

6) An integer overflow error when handling the "scroll" method of the ActionScript Bitmap class can be exploited to corrupt memory.

7) An unspecified error can be exploited to disclose certain information from another domain.

8) A boundary error when processing the H.264/AVC Decoder Configuration record can be exploited to cause a stack-based buffer overflow via a specially crafted Sequence Parameter Set NAL unit.

9) An unspecified error can be exploited to cause a buffer overflow and potentially execute arbitrary code.

10) An error within the "Setslot()" method when parsing a certain field from an SWF file can be exploited to cause a buffer overflow and potentially execute arbitrary code.

11) An integer overflow error within a certain ActionScript function can be exploited to corrupt memory and potentially execute arbitrary code.

12) An unspecified error can be exploited to corrupt memory and potentially execute arbitrary code.

13) An error within the "Bitmapdata" class when parsing a certain field from an SWF file can be exploited to corrupt memory and potentially execute arbitrary code.

14) 80 unspecified errors of various types when parsing SWF file content may be exploited to corrupt memory.

The vulnerabilities are reported in the following products:
* Adobe Flash Player versions 10.3.181.36 and prior for Windows, Macintosh, Linux, and Solaris
* Adobe Flash Player versions 10.3.185.25 and prior for Android
* Adobe AIR versions 2.7 and prior for Windows, Macintosh, and Android

Solution

Update to a fixed version.

Adobe Flash Player Windows, Macintosh, Linux and Solaris:
Update to version 10.3.183.5

Adobe Flash Player for Android:
Update to version 10.3.186.3

Adobe AIR for Windows and Macintosh:
Update to version 2.7.1

AIR for Android:
Update to version 2.7.1.1961

Reported by

1) Reported by the vendor
3) Wushi, Team 509 via iDefense Labs
4, 11) Vitaliy Toropov via iDefense Labs
6) An anonymous person via ZDI
8) An anonymous person via ZDI
10) Bo Qu, Palo Alto Networks and Honggang Ren, FortiGuard Labs
13) Honggang Ren, FortiGuard Labs
14) Tavis Ormandy, Google Security Team

The vendor credits:
2) Yang Dingning, NCNIPC, Graduate University of Chinese Academy of Sciences
5) Alexander Zaitsev, Positive Technologies
7) Brandon Hardy
9) Bo Qu, Palo Alto Networks
12) Marc Schoenefeld (Dr. rer. nat.), Red Hat Security Response Team

Original Advisory

Adobe (APSB11-21):
http://www.adobe.com/support/security/bulletins/apsb11-21.html

iDefense:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=935
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=936
http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?loc=en_US&id=960

FortiGuard Labs:
http://www.fortiguard.com/advisory/FGA-2011-25.html

Google:
http://googleonlinesecurity.blogspot.com/2011/08/fuzzing-at-scale.html

ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-11-253/
http://www.zerodayinitiative.com/advisories/ZDI-11-276/