Adobe Flash Player and AIR CVE-2012-5676 Remote Buffer Overflow Vulnerability
BID:56892
Info
Adobe Flash Player and AIR CVE-2012-5676 Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 56892 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2012-5676 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 11 2012 12:00AM |
| Updated: | Mar 19 2015 08:46AM |
| Credit: | Mateusz Jurczyk, Gynvael Coldwind, and Fermin Serna of the Google Security Team |
| Vulnerable: |
SuSE SUSE Linux Enterprise Desktop 11 SP2 SuSE SUSE Linux Enterprise Desktop 10 SP4 SuSE openSUSE 12.1 SuSE openSUSE 11.4 Red Hat Enterprise Linux Workstation Supplementary 6 Red Hat Enterprise Linux Supplementary 5 server Red Hat Enterprise Linux Server Supplementary 6 Red Hat Enterprise Linux Desktop Supplementary 6 Red Hat Enterprise Linux Desktop Supplementary 5 client Google Chrome 17.0.963 79 Google Chrome 17.0.963 65 Google Chrome 16.0.912 75 Google Chrome 15.0.874 102 Google Chrome 2.0.172 .43 Google Chrome 2.0.172 .37 Google Chrome 2.0.172 .33 Google Chrome 2.0.172 .31 Google Chrome 2.0.172 .30 Google Chrome 19.0.1084.52 Google Chrome 19 Google Chrome 18.0.1025.168 Google Chrome 18.0.1025.162 Google Chrome 18.0.1025.151 Google Chrome 18.0.1025.142 Google Chrome 17.0.963.83 Google Chrome 17.0.963.78 Google Chrome 17.0.963.60 Google Chrome 17.0.963.56 Google Chrome 17.0.963.46 Google Chrome 16.0.912.77 Google Chrome 16.0.912.75 Google Chrome 16.0.912.63 Google Chrome 16 Google Chrome 15.0.874.121 Google Chrome 15.0.874.120 Google Chrome 14.0.835.202 Google Chrome 14.0.835.186 Google Chrome 14.0.835.163 Google Chrome 14 Google Chrome 13.0.782.215 Google Chrome 13.0.782.112 Google Chrome 13.0.782.107 Google Chrome 13 Google Chrome 12.0.742.91 Google Chrome 12.0.742.112 Google Chrome 12.0.742.100 Google Chrome 12 Google Chrome 11.0.696.77 Google Chrome 11.0.696.71 Google Chrome 11.0.696.68 Google Chrome 11.0.696.65 Google Chrome 11.0.696.57 Google Chrome 11.0.696.43 Google Chrome 11.0.672.2 Google Chrome 11 Google Chrome 10.0.648.205 Google Chrome 10.0.648.205 Google Chrome 10.0.648.204 Google Chrome 10.0.648.133 Google Chrome 10.0.648.128 Google Chrome 10.0.648.127 Google Chrome 10.0.648.127 Google Chrome 10 Adobe Flash Player for Android 11.1.102.59 Adobe Flash Player for Android 11.0.1.153 Adobe Flash Player 11.2.202.235 Adobe Flash Player 11.2.202.233 Adobe Flash Player 11.2.202.229 Adobe Flash Player 11.2.202.228 Adobe Flash Player 11.2.202.223 Adobe Flash Player 11.1.115.8 Adobe Flash Player 11.1.115.7 Adobe Flash Player 11.1.115.6 Adobe Flash Player 11.1.112.61 Adobe Flash Player 11.1.111.9 Adobe Flash Player 11.1.111.8 Adobe Flash Player 11.1.111.7 Adobe Flash Player 11.1.111.6 Adobe Flash Player 11.1.111.5 Adobe Flash Player 11.1.102.63 Adobe Flash Player 11.1.102.62 Adobe Flash Player 11.1.102.55 Adobe Flash Player 11.1.102.228 Adobe Flash Player 11.0.1.152 Adobe AIR 3.2.0.2080 Adobe AIR 3.2.0.2070 Adobe AIR 3.1.0.4880 Adobe AIR 3.0 |
| Not Vulnerable: | |
Discussion
Adobe Flash Player and AIR CVE-2012-5676 Remote Buffer Overflow Vulnerability
Adobe Flash Player and AIR are prone to a remote buffer-overflow vulnerability due to a failure to properly bounds check user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Adobe Flash Player and AIR are prone to a remote buffer-overflow vulnerability due to a failure to properly bounds check user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Exploit / POC
Adobe Flash Player and AIR CVE-2012-5676 Remote Buffer Overflow Vulnerability
Currently, we are not aware of any publicly available exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Currently, we are not aware of any publicly available exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution / Fix
Adobe Flash Player and AIR CVE-2012-5676 Remote Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Adobe Flash Player and AIR CVE-2012-5676 Remote Buffer Overflow Vulnerability
References:
References:
- Adobe AIR homepage (Adobe)
- Adobe Flash Homepage (Adobe)
- Google Chrome Homepage (Google)
- Internet Explorer Homepage (Microsoft)
- openSUSE-SU-2013:0368-1: critical: update for flash-player (OpenSUSE)
- Adobe Flash Player: Multiple vulnerabilities (Gentoo)
- APSB12-27: Security updates available for Adobe Flash Player (Adobe)
- BSRT-2013-004 Vulnerabilities in Adobe Flash Player version included with the Bl (Blackberry)
- Microsoft Security Advisory (2755801) Update for Vulnerabilities in Adobe Flash (Microsoft)
- Stable Channel Update 23.0.1271.97 (Google)