English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Adobe Flash Player Multiple Vulnerabilities


Secunia ID

SA46113

CVE-ID

CVE-2011-2426, CVE-2011-2427, CVE-2011-2428, CVE-2011-2429, CVE-2011-2430, CVE-2011-2444

Release Date

22 Sep 2011

Criticality

Highly Critical

Solution Status

Vendor Patch

Software

Adobe Flash Player 10.x

Where

From remote

Impact
System access

This covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user.

Cross-Site Scripting

Cross-Site Scripting vulnerabilities allow a third party to manipulate the content or behaviour of a web application in a user's browser, without compromising the underlying system.

Different Cross-Site Scripting related vulnerabilities are also classified under this category, including "script insertion" and "cross-site request forgery".

Cross-Site Scripting vulnerabilities are often used against specific users of a website to steal their credentials or to conduct spoofing attacks.

Security Bypass

This covers vulnerabilities or security issues where malicious users or people can bypass certain security mechanisms of the application.

The actual impact varies significantly depending on the design and purpose of the affected application.

Description

Multiple vulnerabilities have been reported in Adobe Flash Player, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, and compromise a user's system.

1) Certain unspecified input is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

NOTE: This vulnerability is reportedly being actively exploited in targeted attacks.

2) An error within the ActionScript Virtual Machine 2 (AVM2) when handling a certain function parameters can be exploited to cause a stack-based buffer overflow.

3) An error within the ActionScript Virtual Machine (AVM) can be exploited to cause a stack-based buffer overflow.

4) A logic error can be exploited to corrupt memory.

5) An unspecified error can be exploited to bypass the security control and e.g. disclose certain sensitive information.

6) A logic error when streaming certain media can be exploited to corrupt memory.

The vulnerabilities are reported in the following products:
* Adobe Flash Player versions 10.3.183.7 and prior for Windows, Macintosh, Linux, and Solaris.
* Adobe Flash Player versions 10.3.186.6 and prior for Android.

Solution

Update to a fixed version.

Adobe Flash Player for Windows, Macintosh, Linux, and Solaris:
Update to version 10.3.183.10.

Adobe Flash Player for Android:
Update to version 10.3.186.7 via the Android Marketplace.

Reported by

1) Reported as a 0-day. The vendor additionally credits Google.
2) Bing Liu, Fortinet's FortiGuard Labs.

The vendor credits:
3) Yang Dingning, NCNIPC, Graduate University of Chinese Academy of Sciences.
4) Huzaifa Sidhpurwala, Red Hat Security Response Team.
5) Neil Bergman, Cigital.
6) Zrong, zengrong.net.

Original Advisory

Adobe:
http://www.adobe.com/support/security/bulletins/apsb11-26.html

FortiGuard Labs:
http://www.fortiguard.com/advisory/FGA-2011-32.html