First published: Mon Dec 08 2008(Updated: )
The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not validate character elements during retrieval from the dictionary data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe AIR | <1.5 | |
Adobe Flash Player for Internet Explorer 11 | >=9.0.16.0<9.0.151.0 | |
Adobe Flash Player for Internet Explorer 11 | >=10<10.0.12.36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5363 has been classified with moderate severity as it can lead to a denial of service.
To fix CVE-2008-5363, update Adobe Flash Player to version 10.0.12.36 or later, or version 9.0.151.0 or later.
CVE-2008-5363 affects Adobe Flash Player 9.x up to 9.0.151.0, Flash Player 10.x up to 10.0.12.36, and Adobe AIR before version 1.5.
Yes, CVE-2008-5363 can be exploited remotely, allowing attackers to cause a denial of service.
The main impact of CVE-2008-5363 is a denial of service due to a NULL pointer dereference.