Vulnerability CVE-2011-0611


Published: 2011-04-13   Modified: 2012-02-13

Description:
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.

See advisories in our WLB2 database:
Topic
Author
Date
High
Adobe Flash Player 10.2.153.1 SWF Memory Corruption Vulnerability
metasploit
18.04.2011
High
Adobe Reader X Atom Type Confusion Vulnerability Exploit
Snake
04.07.2011

Type:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Adobe -> Acrobat 
Adobe -> Acrobat reader 
Adobe -> Adobe air 
Adobe -> Flash player 

 References:
http://blogs.technet.com/b/mmpc/archive/2011/04/12/analysis-of-the-cve-2011-0611-adobe-flash-player-vulnerability-exploitation.aspx
http://bugix-security.blogspot.com/2011/04/cve-2011-0611-adobe-flash-zero-day.html
http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611-flash-player-zero.html
http://googlechromereleases.blogspot.com/2011/04/stable-channel-update.html
http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00004.html
http://securityreason.com/securityalert/8204
http://securityreason.com/securityalert/8292
http://www.adobe.com/support/security/advisories/apsa11-02.html
http://www.adobe.com/support/security/bulletins/apsb11-07.html
http://www.adobe.com/support/security/bulletins/apsb11-08.html
http://www.exploit-db.com/exploits/17175
http://www.kb.cert.org/vuls/id/230057
http://www.redhat.com/support/errata/RHSA-2011-0451.html
http://www.securityfocus.com/bid/47314
http://www.securitytracker.com/id?1025324
http://www.securitytracker.com/id?1025325
http://www.vupen.com/english/advisories/2011/0922
http://www.vupen.com/english/advisories/2011/0923
http://www.vupen.com/english/advisories/2011/0924
https://exchange.xforce.ibmcloud.com/vulnerabilities/66681
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14175

Copyright 2024, cxsecurity.com

 

Back to Top