CVE-2011-0611

EUVD-2011-0629
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.
Type Confusion
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA-ADPADP
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
adobeflash_player
𝑥
< 10.2.154.27
adobeflash_player
𝑥
≤ 10.2.156.12
adobeacrobat_reader
9.0 ≤
𝑥
< 9.4.4
adobeacrobat_reader
10.0 ≤
𝑥
≤ 10.0.1
adobeadobe_air
𝑥
< 2.6.19140
adobeacrobat_reader
9.0 ≤
𝑥
< 9.4.4
adobeacrobat_reader
10.0 ≤
𝑥
< 10.0.3
adobeacrobat
9.0 ≤
𝑥
< 9.4
adobeacrobat
10.0 ≤
𝑥
< 10.0.3
googlechrome
𝑥
< 10.0.648.205
opensuseopensuse
11.2
opensuseopensuse
11.3
opensuseopensuse
11.4
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
acroread
dapper
ignored
hardy
not-affected
karmic
not-affected
lucid
not-affected
maverick
not-affected
natty
not-affected
adobe-flashplugin
dapper
dne
hardy
Fixed 10.2.159.1-0hardy1
released
karmic
Fixed 10.2.159.1-0karmic1
released
lucid
Fixed 10.2.159.1-0lucid1
released
maverick
Fixed 10.2.159.1-0maverick1
released
natty
Fixed 10.2.159.1-0natty1
released
adobeair
dapper
dne
hardy
ignored
lucid
Fixed 1:2.6.0.19140-0lucid1
released
maverick
Fixed 1:2.6.0.19140-0maverick1
released
natty
Fixed 1:2.6.0.19140-0natty1
released
flashplugin-nonfree
dapper
ignored
hardy
Fixed 10.2.159.1ubuntu0.8.04.1
released
karmic
Fixed 10.2.159.1ubuntu0.9.10.1
released
lucid
Fixed 10.2.159.1ubuntu0.10.04.1
released
maverick
Fixed 10.2.159.1ubuntu0.10.10.1
released
natty
Fixed 10.2.159.1ubuntu1
released
References