CVE-2013-1378
critical
CVSS v3
—
CVSS v2
10.0
VIR risk
10.0
Description
Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and before 11.1.115.54 on Android 4.x; Adobe AIR before 3.7.0.1530; and Adobe AIR SDK & Compiler before 3.7.0.1530 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-1380.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@adobe.com — http://www.adobe.com/support/security/bulletins/apsb13-11.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| macos | not-affected | | |
| linux-kernel | not-affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| adobe | flash_player | {"endIncluding":"10.3.183.68"} | |
| adobe | flash_player | 6.0.21.0 | |
| adobe | flash_player | 6.0.79 | |
| adobe | flash_player | 7.0 | |
| adobe | flash_player | 7.0.1 | |
| adobe | flash_player | 7.0.14.0 | |
| adobe | flash_player | 7.0.19.0 | |
| adobe | flash_player | 7.0.24.0 | |
| adobe | flash_player | 7.0.25 | |
| adobe | flash_player | 7.0.53.0 | |
| adobe | flash_player | 7.0.60.0 | |
| adobe | flash_player | 7.0.61.0 | |
| adobe | flash_player | 7.0.63 | |
| adobe | flash_player | 7.0.66.0 | |
| adobe | flash_player | 7.0.67.0 | |
| adobe | flash_player | 7.0.68.0 | |
| adobe | flash_player | 7.0.69.0 | |
| adobe | flash_player | 7.0.70.0 | |
| adobe | flash_player | 7.0.73.0 | |
| adobe | flash_player | 7.1 | |
| adobe | flash_player | 7.1.1 | |
| adobe | flash_player | 7.2 | |
| adobe | flash_player | 8.0 | |
| adobe | flash_player | 8.0.22.0 | |
| adobe | flash_player | 8.0.24.0 | |
| adobe | flash_player | 8.0.33.0 | |
| adobe | flash_player | 8.0.34.0 | |
| adobe | flash_player | 8.0.35.0 | |
| adobe | flash_player | 8.0.39.0 | |
| adobe | flash_player | 8.0.42.0 | |
| adobe | flash_player | 9.0 | |
| adobe | flash_player | 9.0.8.0 | |
| adobe | flash_player | 9.0.9.0 | |
| adobe | flash_player | 9.0.16 | |
| adobe | flash_player | 9.0.18d60 | |
| adobe | flash_player | 9.0.20 | |
| adobe | flash_player | 9.0.20.0 | |
| adobe | flash_player | 9.0.28 | |
| adobe | flash_player | 9.0.28.0 | |
| adobe | flash_player | 9.0.31 | |
| adobe | flash_player | 9.0.31.0 | |
| adobe | flash_player | 9.0.45.0 | |
| adobe | flash_player | 9.0.47.0 | |
| adobe | flash_player | 9.0.48.0 | |
| adobe | flash_player | 9.0.112.0 | |
| adobe | flash_player | 9.0.114.0 | |
| adobe | flash_player | 9.0.115.0 | |
| adobe | flash_player | 9.0.124.0 | |
| adobe | flash_player | 9.0.125.0 | |
| adobe | flash_player | 9.0.151.0 | |
| adobe | flash_player | 9.0.152.0 | |
| adobe | flash_player | 9.0.155.0 | |
| adobe | flash_player | 9.0.159.0 | |
| adobe | flash_player | 9.0.246.0 | |
| adobe | flash_player | 9.0.260.0 | |
| adobe | flash_player | 9.0.262.0 | |
| adobe | flash_player | 9.0.277.0 | |
| adobe | flash_player | 9.0.280 | |
| adobe | flash_player | 9.0.283.0 | |
| adobe | flash_player | 9.125.0 | |
| adobe | flash_player | 10.0.0.584 | |
| adobe | flash_player | 10.0.2.54 | |
| adobe | flash_player | 10.0.12.10 | |
| adobe | flash_player | 10.0.12.36 | |
| adobe | flash_player | 10.0.15.3 | |
| adobe | flash_player | 10.0.22.87 | |
| adobe | flash_player | 10.0.32.18 | |
| adobe | flash_player | 10.0.42.34 | |
| adobe | flash_player | 10.0.45.2 | |
| adobe | flash_player | 10.1 | |
| adobe | flash_player | 10.1.52.14 | |
| adobe | flash_player | 10.1.52.14.1 | |
| adobe | flash_player | 10.1.52.15 | |
| adobe | flash_player | 10.1.53.64 | |
| adobe | flash_player | 10.1.82.76 | |
| adobe | flash_player | 10.1.85.3 | |
| adobe | flash_player | 10.1.92.8 | |
| adobe | flash_player | 10.1.92.10 | |
| adobe | flash_player | 10.1.95.1 | |
| adobe | flash_player | 10.1.95.2 | |
| adobe | flash_player | 10.1.102.64 | |
| adobe | flash_player | 10.1.105.6 | |
| adobe | flash_player | 10.1.106.16 | |
| adobe | flash_player | 10.1.106.17 | |
| adobe | flash_player | 10.2.152 | |
| adobe | flash_player | 10.2.152.26 | |
| adobe | flash_player | 10.2.152.32 | |
| adobe | flash_player | 10.2.152.33 | |
| adobe | flash_player | 10.2.153.1 | |
| adobe | flash_player | 10.2.154.13 | |
| adobe | flash_player | 10.2.154.25 | |
| adobe | flash_player | 10.2.156.12 | |
| adobe | flash_player | 10.2.157.51 | |
| adobe | flash_player | 10.2.159.1 | |
| adobe | flash_player | 10.3.181.14 | |
| adobe | flash_player | 10.3.181.16 | |
| adobe | flash_player | 10.3.181.22 | |
| adobe | flash_player | 10.3.181.23 | |
| adobe | flash_player | 10.3.181.26 | |
| adobe | flash_player | 10.3.181.34 | |
| adobe | flash_player | 10.3.183.5 | |
| adobe | flash_player | 10.3.183.7 | |
| adobe | flash_player | 10.3.183.10 | |
| adobe | flash_player | 10.3.183.11 | |
| adobe | flash_player | 10.3.183.15 | |
| adobe | flash_player | 10.3.183.16 | |
| adobe | flash_player | 10.3.183.18 | |
| adobe | flash_player | 10.3.183.19 | |
| adobe | flash_player | 10.3.183.20 | |
| adobe | flash_player | 10.3.183.23 | |
| adobe | flash_player | 10.3.183.25 | |
| adobe | flash_player | 10.3.183.29 | |
| adobe | flash_player | 10.3.183.43 | |
| adobe | flash_player | 10.3.183.48 | |
| adobe | flash_player | 10.3.183.50 | |
| adobe | flash_player | 10.3.183.51 | |
| adobe | flash_player | 10.3.183.61 | |
| adobe | flash_player | 10.3.183.63 | |
| adobe | flash_player | 10.3.183.67 | |
| adobe | flash_player | 11.0 | |
| adobe | flash_player | 11.0.1.152 | |
| adobe | flash_player | 11.0.1.153 | |
| adobe | flash_player | 11.1 | |
| adobe | flash_player | 11.1.102.55 | |
| adobe | flash_player | 11.1.102.59 | |
| adobe | flash_player | 11.1.102.62 | |
| adobe | flash_player | 11.1.102.63 | |
| adobe | flash_player | 11.1.111.8 | |
| adobe | flash_player | 11.1.115.7 | |
| adobe | flash_player | 11.1.115.34 | |
| adobe | flash_player | 11.2.202.223 | |
| adobe | flash_player | 11.2.202.228 | |
| adobe | flash_player | 11.2.202.233 | |
| adobe | flash_player | 11.2.202.235 | |
| adobe | flash_player | 11.2.202.236 | |
| adobe | flash_player | 11.2.202.238 | |
| adobe | flash_player | 11.2.202.243 | |
| adobe | flash_player | 11.2.202.251 | |
| adobe | flash_player | 11.2.202.258 | |
| adobe | flash_player | 11.2.202.261 | |
| adobe | flash_player | 11.2.202.262 | |
| adobe | flash_player | 11.2.202.270 | |
| adobe | flash_player | 11.2.202.273 | |
| adobe | flash_player | 11.3.300.257 | |
| adobe | flash_player | 11.3.300.262 | |
| adobe | flash_player | 11.3.300.265 | |
| adobe | flash_player | 11.3.300.268 | |
| adobe | flash_player | 11.3.300.270 | |
| adobe | flash_player | 11.3.300.271 | |
| adobe | flash_player | 11.3.300.273 | |
| adobe | flash_player | 11.4.402.265 | |
| adobe | flash_player | 11.4.402.278 | |
| adobe | flash_player | 11.4.402.287 | |
| adobe | flash_player | 11.5.502.110 | |
| adobe | flash_player | 11.5.502.135 | |
| adobe | flash_player | 11.5.502.136 | |
| adobe | flash_player | 11.5.502.146 | |
| adobe | flash_player | 11.5.502.149 | |
| adobe | flash_player | 11.6.602.167 | |
| adobe | flash_player | 11.6.602.168 | |
| adobe | flash_player | 11.6.602.171 | |
| adobe | flash_player | 11.6.602.180 | |
| adobe | flash_player | 11.2.202.275 | |
| adobe | adobe_air | {"endIncluding":"3.6.0.6090"} | |
| adobe | adobe_air | 3.6.0.597 | |
| adobe | adobe_air_sdk | {"endIncluding":"3.6.0.6090"} | |
| adobe | adobe_air_sdk | 3.6.0.599 | |
References
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00016.html
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00019.html
- http://lists.opensuse.org/opensuse-updates/2013-04/msg00081.html
- http://marc.info/?l=bugtraq&m=139455789818399&w=2
- http://rhn.redhat.com/errata/RHSA-2013-0730.html
- http://www.adobe.com/support/security/bulletins/apsb13-11.html
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00016.html
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00019.html
- http://lists.opensuse.org/opensuse-updates/2013-04/msg00081.html
- http://marc.info/?l=bugtraq&m=139455789818399&w=2
- http://rhn.redhat.com/errata/RHSA-2013-0730.html
- http://www.adobe.com/support/security/bulletins/apsb13-11.html
CWEs
CWE-119
Verify integrity in audit chain (admin only). AS-IS.