First published: Tue Sep 12 2006(Updated: )
Buffer overflow in Adobe Flash Player 8.0.24.0 and earlier, Flash Professional 8, Flash MX 2004, and Flex 1.5 allows user-assisted remote attackers to execute arbitrary code via a long, dynamically created string in a SWF movie.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Player for Internet Explorer 11 | <=8.0.24.0 | |
Adobe Flash Player for Internet Explorer 11 | =8 | |
Adobe Flash Player for Internet Explorer 11 | =mx_2004 | |
Adobe Flex SDK | =1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3311 is classified as a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2006-3311, you should update Adobe Flash Player to version 8.0.24.1 or later.
Users of Adobe Flash Player versions 8.0.24.0 and earlier, Flash Professional 8, Flash MX 2004, and Flex 1.5 are affected by CVE-2006-3311.
Yes, CVE-2006-3311 can be exploited by user-assisted remote attackers through a specially crafted SWF movie.
Exploitation of CVE-2006-3311 could allow an attacker to execute arbitrary code on the affected system.