First published: Tue May 31 2011(Updated: )
Integer overflow in Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code via ActionScript that improperly handles a long array object.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Flash Player | <=10.2.159.1 | |
Macromedia Flash Player | =6.0.21.0 | |
Macromedia Flash Player | =6.0.79 | |
Macromedia Flash Player | =7.0 | |
Macromedia Flash Player | =7.0.1 | |
Macromedia Flash Player | =7.0.14.0 | |
Macromedia Flash Player | =7.0.19.0 | |
Macromedia Flash Player | =7.0.24.0 | |
Macromedia Flash Player | =7.0.25 | |
Macromedia Flash Player | =7.0.53.0 | |
Macromedia Flash Player | =7.0.60.0 | |
Macromedia Flash Player | =7.0.61.0 | |
Macromedia Flash Player | =7.0.63 | |
Macromedia Flash Player | =7.0.66.0 | |
Macromedia Flash Player | =7.0.67.0 | |
Macromedia Flash Player | =7.0.68.0 | |
Macromedia Flash Player | =7.0.69.0 | |
Macromedia Flash Player | =7.0.70.0 | |
Macromedia Flash Player | =7.0.73.0 | |
Macromedia Flash Player | =7.1 | |
Macromedia Flash Player | =7.1.1 | |
Macromedia Flash Player | =7.2 | |
Macromedia Flash Player | =8.0 | |
Macromedia Flash Player | =8.0.22.0 | |
Macromedia Flash Player | =8.0.24.0 | |
Macromedia Flash Player | =8.0.33.0 | |
Macromedia Flash Player | =8.0.34.0 | |
Macromedia Flash Player | =8.0.35.0 | |
Macromedia Flash Player | =8.0.39.0 | |
Macromedia Flash Player | =8.0.42.0 | |
Macromedia Flash Player | =9.0 | |
Macromedia Flash Player | =9.0.16 | |
Macromedia Flash Player | =9.0.18d60 | |
Macromedia Flash Player | =9.0.20 | |
Macromedia Flash Player | =9.0.20.0 | |
Macromedia Flash Player | =9.0.28 | |
Macromedia Flash Player | =9.0.28.0 | |
Macromedia Flash Player | =9.0.31 | |
Macromedia Flash Player | =9.0.31.0 | |
Macromedia Flash Player | =9.0.45.0 | |
Macromedia Flash Player | =9.0.47.0 | |
Macromedia Flash Player | =9.0.48.0 | |
Macromedia Flash Player | =9.0.112.0 | |
Macromedia Flash Player | =9.0.114.0 | |
Macromedia Flash Player | =9.0.115.0 | |
Macromedia Flash Player | =9.0.124.0 | |
Macromedia Flash Player | =9.0.125.0 | |
Macromedia Flash Player | =9.0.151.0 | |
Macromedia Flash Player | =9.0.152.0 | |
Macromedia Flash Player | =9.0.155.0 | |
Macromedia Flash Player | =9.0.159.0 | |
Macromedia Flash Player | =9.0.246.0 | |
Macromedia Flash Player | =9.0.260.0 | |
Macromedia Flash Player | =9.0.262.0 | |
Macromedia Flash Player | =9.0.277.0 | |
Macromedia Flash Player | =9.0.283.0 | |
Macromedia Flash Player | =9.125.0 | |
Macromedia Flash Player | =10.0.0.584 | |
Macromedia Flash Player | =10.0.12.10 | |
Macromedia Flash Player | =10.0.12.36 | |
Macromedia Flash Player | =10.0.15.3 | |
Macromedia Flash Player | =10.0.22.87 | |
Macromedia Flash Player | =10.0.32.18 | |
Macromedia Flash Player | =10.0.42.34 | |
Macromedia Flash Player | =10.0.45.2 | |
Macromedia Flash Player | =10.1.52.14.1 | |
Macromedia Flash Player | =10.1.52.15 | |
Macromedia Flash Player | =10.1.53.64 | |
Macromedia Flash Player | =10.1.82.76 | |
Macromedia Flash Player | =10.1.85.3 | |
Macromedia Flash Player | =10.1.92.8 | |
Macromedia Flash Player | =10.1.92.10 | |
Macromedia Flash Player | =10.1.95.1 | |
Macromedia Flash Player | =10.1.95.2 | |
Macromedia Flash Player | =10.1.102.64 | |
Macromedia Flash Player | =10.2.152 | |
Macromedia Flash Player | =10.2.152.32 | |
Macromedia Flash Player | =10.2.152.33 | |
Macromedia Flash Player | =10.2.154.13 | |
Macromedia Flash Player | =10.2.154.25 | |
Apple iOS and macOS | ||
Linux Kernel | ||
Microsoft Windows Operating System | ||
Oracle Solaris and Zettabyte File System (ZFS) | ||
Macromedia Flash Player | <=10.2.157.51 | |
Macromedia Flash Player | =10.1.105.6 | |
Macromedia Flash Player | =10.1.106.16 | |
Macromedia Flash Player | =10.2.156.12 | |
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0628 is classified as a critical vulnerability, allowing remote code execution due to an integer overflow in Adobe Flash Player.
To fix CVE-2011-0628, upgrade Adobe Flash Player to version 10.3.181.14 or later.
CVE-2011-0628 affects Adobe Flash Player versions before 10.3.181.14 on Windows, Mac OS X, Linux, Solaris, and before 10.3.185.21 on Android.
CVE-2011-0628 can be exploited via malicious ActionScript that improperly handles long array objects, enabling remote attackers to execute arbitrary code.
The best mitigation for CVE-2011-0628 is to ensure that the affected versions of Adobe Flash Player are updated to the latest secure versions.