CVE-2012-5254: Buffer Overflow
Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than other Flash Player buffer overflow CVEs listed in APSB12-22.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5254?
CVE-2012-5254 has a severity rating of critical due to the potential for remote code execution.
How do I fix CVE-2012-5254?
To fix CVE-2012-5254, update Adobe Flash Player to version 10.3.183.29 or later, or 11.x to version 11.4.402.287 or later.
Which software versions are affected by CVE-2012-5254?
CVE-2012-5254 affects Adobe Flash Player versions prior to 10.3.183.29 and 11.x before 11.4.402.287 on Windows, Mac OS X, and Linux.
What types of attacks can exploit CVE-2012-5254?
CVE-2012-5254 can be exploited through specially crafted Flash content that leads to a buffer overflow, allowing an attacker to execute arbitrary code.
Is there a workaround for CVE-2012-5254?
While the best mitigation is to update, users can reduce risk by disabling Flash Player in their web browsers until a patch is applied.