First published: Wed Nov 07 2012(Updated: )
Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Flash Player | >=10.3<10.3.183.43 | |
Macromedia Flash Player | >=11.4<11.5.502.110 | |
Apple iOS and macOS | ||
Microsoft Windows Operating System | ||
Macromedia Flash Player | >=11.2<11.2.202.251 | |
Linux Kernel | ||
Macromedia Flash Player | >=11.1<11.1.111.24 | |
Android | >=2.0<=2.3.7 | |
Android | >=3.0<=3.2.6 | |
Macromedia Flash Player | >=11.1<11.1.115.27 | |
Android | >=4.0<=4.4.4 | |
Adobe | <3.5.0.600 | |
Adobe AIR | <3.5.0.600 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5279 has been classified with a high severity, allowing for potential exploitation.
To fix CVE-2012-5279, update Adobe Flash Player to version 10.3.183.43 or higher for Windows and macOS, and corresponding versions for other platforms.
CVE-2012-5279 affects Adobe Flash Player versions before 10.3.183.43 for Windows and Mac OS X, and versions before 11.x before 11.5.502.110 for other platforms.
Yes, Adobe AIR versions before 3.5.0.600 are affected by CVE-2012-5279 and should be updated.
CVE-2012-5279 impacts Adobe Flash Player and AIR on Windows, Mac OS X, Linux, and Android operating systems.