Adobe Flash Player and AIR (CVE-2010-2216) Unspecified Memory Corruption Vulnerability
BID:42362
Info
Adobe Flash Player and AIR (CVE-2010-2216) Unspecified Memory Corruption Vulnerability
| Bugtraq ID: | 42362 |
| Class: | Unknown |
| CVE: |
CVE-2010-2216 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 10 2010 12:00AM |
| Updated: | Dec 20 2016 02:05AM |
| Credit: | Will Dormann of CERT |
| Vulnerable: |
SuSE Suse Linux Enterprise Desktop 11 SP1 SuSE Suse Linux Enterprise Desktop 11 SuSE Suse Linux Enterprise Desktop 10 SP3 Sun Solaris 11 Express Sun Solaris 10_x86 Sun Solaris 10_sparc S.u.S.E. openSUSE 11.3 S.u.S.E. openSUSE 11.2 S.u.S.E. openSUSE 11.1 Redhat Enterprise Linux WS Extras 4 Redhat Enterprise Linux WS Extras 3 Redhat Enterprise Linux Supplementary 5 server Redhat Enterprise Linux Extras 4 Redhat Enterprise Linux Extras 3 Redhat Enterprise Linux ES Extras 4 Redhat Enterprise Linux ES Extras 3 Redhat Enterprise Linux Desktop Supplementary 5 client Redhat Enterprise Linux AS Extras 4 Redhat Enterprise Linux AS Extras 3 Redhat Desktop Extras 4 Redhat Desktop Extras 3 Pardus Linux 2009 0 Oracle Solaris Express 11 Oracle Solaris 11 Oracle Solaris 10 HP Systems Insight Manager 6.1 HP Systems Insight Manager 6.0.0.96 HP Systems Insight Manager 6.0 HP Systems Insight Manager 5.3 Update 1 HP Systems Insight Manager 5.3 HP Systems Insight Manager 5.2 SP2 HP Systems Insight Manager 5.1 SP1 HP Systems Insight Manager 5.0 SP6 HP Systems Insight Manager 5.0 SP5 HP Systems Insight Manager 5.0 SP3 HP Systems Insight Manager 5.0 SP2 HP Systems Insight Manager 5.0 SP1 HP Systems Insight Manager 5.0 Google Chrome 5.0.375 99 Google Chrome 5.0.375 86 Google Chrome 5.0.375 125 Gentoo Linux Apple Mac OS X Server 10.6.4 Apple Mac OS X Server 10.6.3 Apple Mac OS X Server 10.6.2 Apple Mac OS X Server 10.6.1 Apple Mac OS X Server 10.5.8 Apple Mac OS X Server 10.5.7 Apple Mac OS X Server 10.5.6 Apple Mac OS X Server 10.5.5 Apple Mac OS X Server 10.5.4 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.5 Apple Mac OS X Server 10.6 Apple Mac OS X Server 10.5 Apple Mac OS X 10.6.4 Apple Mac OS X 10.6.3 Apple Mac OS X 10.6.2 Apple Mac OS X 10.6.1 Apple Mac OS X 10.5.8 Apple Mac OS X 10.5.7 Apple Mac OS X 10.5.6 Apple Mac OS X 10.5.5 Apple Mac OS X 10.5.4 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.5 Apple Mac OS X 10.6 Apple Mac OS X 10.5 Adobe Flash Player 10.1.53 .64 Adobe Flash Player 10.1.51 .66 Adobe Flash Player 10.0.45 2 Adobe Flash Player 10.0.45 2 Adobe Flash Player 10.0.32 18 Adobe Flash Player 10.0.22 .87 Adobe Flash Player 10.0.15 .3 Adobe Flash Player 10.0.12 .36 Adobe Flash Player 10.0.12 .35 Adobe Flash Player 9.0.262 Adobe Flash Player 9.0.246 0 Adobe Flash Player 9.0.152 .0 Adobe Flash Player 9.0.151 .0 Adobe Flash Player 9.0.124 .0 Adobe Flash Player 9.0.48.0 Adobe Flash Player 9.0.47.0 Adobe Flash Player 9.0.45.0 Adobe Flash Player 9.0.31.0 Adobe Flash Player 9.0.28.0 Adobe Flash Player 9.0.277.0 Adobe Flash Player 9.0.260.0 Adobe Flash Player 9.0.246.0 Adobe Flash Player 9.0.159.0 Adobe Flash Player 9.0.115.0 Adobe Flash Player 9 Adobe Flash Player 8.0.35.0 Adobe Flash Player 8.0.34.0 Adobe Flash Player 8 Adobe Flash Player 10.1 Release Candida Adobe Flash Player 10.0.42.34 Adobe Flash Player 10.0.32.18 Adobe Flash Player 10 Adobe AIR 1.5.3 .9130 Adobe AIR 1.5.3 .9120 Adobe AIR 1.5.3 Adobe AIR 1.5.2 Adobe AIR 1.5.1 Adobe AIR 2.0.2.12610 Adobe AIR 1.5 Adobe AIR 1.1 Adobe AIR 1.01 Adobe AIR 1.0 |
| Not Vulnerable: |
HP Systems Insight Manager 6.2 Google Chrome 5.0.375.126 Apple Mac OS X Server 10.6.5 Apple Mac OS X 10.6.5 Adobe Flash Player 9.0.280 Adobe Flash Player 10.1.82.76 Adobe AIR 2.0.3 |
Discussion
Adobe Flash Player and AIR (CVE-2010-2216) Unspecified Memory Corruption Vulnerability
Adobe Flash Player and Adobe AIR are prone to an unspecified memory-corruption vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the application. Failed attacks may cause a denial-of-service condition.
Very few technical details are currently available. We will update this BID as more information emerges.
This issue affects the following:
Adobe Flash Player prior to 10.1.82.76
Adobe AIR prior to 2.0.3
Adobe Flash Player prior to 9.0.280
NOTE: This issue was previously covered in BID 42341 (Adobe Flash Player 10.1.53.64 and AIR 2.0.2.12610 Multiple Remote Vulnerabilities) but has been given its own record to better document it.
Adobe Flash Player and Adobe AIR are prone to an unspecified memory-corruption vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the application. Failed attacks may cause a denial-of-service condition.
Very few technical details are currently available. We will update this BID as more information emerges.
This issue affects the following:
Adobe Flash Player prior to 10.1.82.76
Adobe AIR prior to 2.0.3
Adobe Flash Player prior to 9.0.280
NOTE: This issue was previously covered in BID 42341 (Adobe Flash Player 10.1.53.64 and AIR 2.0.2.12610 Multiple Remote Vulnerabilities) but has been given its own record to better document it.
Exploit / POC
Adobe Flash Player and AIR (CVE-2010-2216) Unspecified Memory Corruption Vulnerability
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Adobe Flash Player and AIR (CVE-2010-2216) Unspecified Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references for more information.
Apple Mac OS X Server 10.6
Apple Mac OS X 10.6
S.u.S.E. openSUSE 11.3
S.u.S.E. openSUSE 11.1
Apple Mac OS X Server 10.6.1
Apple Mac OS X 10.6.1
Apple Mac OS X Server 10.6.2
Apple Mac OS X 10.6.3
Apple Mac OS X 10.6.4
Apple Mac OS X Server 10.6.4
Solution:
Updates are available. Please see the references for more information.
Apple Mac OS X Server 10.6
-
Apple MacOSXServUpdCombo10.6.5.dmg
For Mac OS X Server v10.6 - v10.6.3
http://www.apple.com/support/downloads/
Apple Mac OS X 10.6
-
Apple MacOSXUpdCombo10.6.5.dmg
For Mac OS X v10.6 - v10.6.3
http://www.apple.com/support/downloads/
S.u.S.E. openSUSE 11.3
-
SuSE flash-player-10.1.82.76-0.1.1.i586.rpm
http://download.opensuse.org/update/11.3/rpm/i586/flash-player-10.1.82 .76-0.1.1.i586.rpm
S.u.S.E. openSUSE 11.1
-
SuSE flash-player-10.1.82.76-0.1.1.i586.rpm
http://download.opensuse.org/update/11.3/rpm/i586/flash-player-10.1.82 .76-0.1.1.i586.rpm
Apple Mac OS X Server 10.6.1
-
Apple MacOSXServUpdCombo10.6.5.dmg
For Mac OS X Server v10.6 - v10.6.3
http://www.apple.com/support/downloads/
Apple Mac OS X 10.6.1
-
Apple MacOSXUpdCombo10.6.5.dmg
For Mac OS X v10.6 - v10.6.3
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.6.2
-
Apple MacOSXServUpdCombo10.6.5.dmg
For Mac OS X Server v10.6 - v10.6.3
http://www.apple.com/support/downloads/
Apple Mac OS X 10.6.3
-
Apple MacOSXUpdCombo10.6.5.dmg
For Mac OS X v10.6 - v10.6.3
http://www.apple.com/support/downloads/
Apple Mac OS X 10.6.4
-
Apple MacOSXUpd10.6.5.dmg
For Mac OS X v10.6.4
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.6.4
-
Apple MacOSXServerUpd10.6.5.dmg
For Mac OS X Server v10.6.4
http://www.apple.com/support/downloads/
References
Adobe Flash Player and AIR (CVE-2010-2216) Unspecified Memory Corruption Vulnerability
References:
References:
- Adobe Flash Homepage (Adobe)
- Adobe Security Advisory APSB10-16 (Adobe)
- Stable Channel Update 5.0.375.126 (Google)
- HPSBMA02592 SSRT100300 rev.1 - HP Systems Insight Manager (SIM) for HP-UX, Linux (HP)
- Multiple Vulnerabilities in Adobe Flash Player (Sun)
- Multiple Vulnerabilities in Adobe Flash Player (Oracle)