RETIRED: Adobe Flash Player 10.1.53.64 and AIR 2.0.2.12610 Multiple Remote Vulnerabilities
BID:42341
Info
RETIRED: Adobe Flash Player 10.1.53.64 and AIR 2.0.2.12610 Multiple Remote Vulnerabilities
| Bugtraq ID: | 42341 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 10 2010 12:00AM |
| Updated: | Aug 11 2010 01:34PM |
| Credit: | Will Dormann of CERT, Lenovo Security Technologies (Beijing), Inc and Jöran Benke |
| Vulnerable: |
Adobe Flash Player 10.1.53 .64 Adobe Flash Player 10.1.51 .66 Adobe Flash Player 10.0.45 2 Adobe Flash Player 10.0.45 2 Adobe Flash Player 10.0.32 18 Adobe Flash Player 10.0.22 .87 Adobe Flash Player 10.0.15 .3 Adobe Flash Player 10.0.12 .36 Adobe Flash Player 10.0.12 .35 Adobe Flash Player 9.0.262 Adobe Flash Player 9.0.246 0 Adobe Flash Player 9.0.152 .0 Adobe Flash Player 9.0.151 .0 Adobe Flash Player 9.0.124 .0 Adobe Flash Player 9.0.48.0 Adobe Flash Player 9.0.47.0 Adobe Flash Player 9.0.45.0 Adobe Flash Player 9.0.31.0 Adobe Flash Player 9.0.28.0 Adobe Flash Player 9.0.260.0 Adobe Flash Player 9.0.246.0 Adobe Flash Player 9.0.159.0 Adobe Flash Player 9.0.115.0 Adobe Flash Player 9 Adobe Flash Player 8.0.35.0 Adobe Flash Player 8.0.34.0 Adobe Flash Player 8 Adobe Flash Player 7.0.70.0 Adobe Flash Player 7.0.69.0 Adobe Flash Player 7 Adobe Flash Player 10.1 Release Candida Adobe Flash Player 10.0.42.34 Adobe Flash Player 10.0.32.18 Adobe Flash Player 10 Adobe AIR 1.5.3 .9130 Adobe AIR 1.5.3 .9120 Adobe AIR 1.5.3 Adobe AIR 1.5.2 Adobe AIR 1.5.1 Adobe AIR 2.0.2.12610 Adobe AIR 1.5 Adobe AIR 1.1 Adobe AIR 1.01 Adobe AIR 1.0 |
| Not Vulnerable: |
Adobe Flash Player 9.0.280 Adobe Flash Player 10.1.82.76 Adobe AIR 2.0.3 |
Discussion
RETIRED: Adobe Flash Player 10.1.53.64 and AIR 2.0.2.12610 Multiple Remote Vulnerabilities
Adobe Flash Player and AIR are prone to multiple remote vulnerabilities.
An attacker can exploit these issues to execute arbitrary code, cause denial-of-service conditions, or perform click-jacking attacks. Other attacks are also possible.
This BID is being retired. The following individual records exist to better document the issues:
42364 Adobe Flash Player and AIR (CVE-2010-2213) Multiple Unspecified Memory Corruption Vulnerabilities
42358 Adobe Flash Player and AIR (CVE-2010-2214) Unspecified Memory Corruption Vulnerability
42361 Adobe Flash Player and AIR (CVE-2010-2215) Unspecified Clickjacking Vulnerability
42362 Adobe Flash Player and AIR (CVE-2010-2216) Unspecified Memory Corruption Vulnerability
42363 Adobe Flash Player and AIR (CVE-2010-0209) Unspecified Memory Corruption Vulnerability
Adobe Flash Player and AIR are prone to multiple remote vulnerabilities.
An attacker can exploit these issues to execute arbitrary code, cause denial-of-service conditions, or perform click-jacking attacks. Other attacks are also possible.
This BID is being retired. The following individual records exist to better document the issues:
42364 Adobe Flash Player and AIR (CVE-2010-2213) Multiple Unspecified Memory Corruption Vulnerabilities
42358 Adobe Flash Player and AIR (CVE-2010-2214) Unspecified Memory Corruption Vulnerability
42361 Adobe Flash Player and AIR (CVE-2010-2215) Unspecified Clickjacking Vulnerability
42362 Adobe Flash Player and AIR (CVE-2010-2216) Unspecified Memory Corruption Vulnerability
42363 Adobe Flash Player and AIR (CVE-2010-0209) Unspecified Memory Corruption Vulnerability
Exploit / POC
RETIRED: Adobe Flash Player 10.1.53.64 and AIR 2.0.2.12610 Multiple Remote Vulnerabilities
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Some of these issues may be trivial to exploit and will not require specific exploit code.
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Some of these issues may be trivial to exploit and will not require specific exploit code.
Solution / Fix
RETIRED: Adobe Flash Player 10.1.53.64 and AIR 2.0.2.12610 Multiple Remote Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
RETIRED: Adobe Flash Player 10.1.53.64 and AIR 2.0.2.12610 Multiple Remote Vulnerabilities
References:
References:
- Adobe AIR homepage (Adobe)
- Adobe Flash Homepage (Adobe)
- Adobe Security Advisory APSB10-16 (Adobe)