CVE-2013-0643: Adobe Flash Player Incorrect Default Permissions Vulnerability
Adobe Flash Player contains an incorrect default permissions vulnerability in the Firefox sandbox that allows a remote attacker to execute arbitrary code via crafted SWF content.
Other sources
The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, which makes it easier for remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adobe Flash Player (Windows and Mac OS X)to a version that resolves this vulnerability.Fixed in 10.3.183.67 - Upgrade
Upgrade
Adobe Flash Player (Windows and Mac OS X)to a version that resolves this vulnerability.Fixed in 11.6.602.171 - Upgrade
Upgrade
Adobe Flash Player (Linux)to a version that resolves this vulnerability.Fixed in 10.3.183.67 - Upgrade
Upgrade
Adobe Flash Player (Linux)to a version that resolves this vulnerability.Fixed in 11.2.202.273 - Remove
Remove
Adobe Flash Playerfrom your environment.Discontinue utilization of the product; uninstall/remove Adobe Flash Player from affected systems.
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0643?
CVE-2013-0643 is considered a critical vulnerability as it allows remote attackers to execute arbitrary code.
How do I fix CVE-2013-0643?
To fix CVE-2013-0643, update Adobe Flash Player to version 10.3.183.67 or later for versions below 11.x and to version 11.6.602.171 or later for 11.x.
What software is affected by CVE-2013-0643?
CVE-2013-0643 affects various versions of Adobe Flash Player prior to the specified safe versions on multiple operating systems.
Can CVE-2013-0643 be exploited through the web?
Yes, CVE-2013-0643 can be exploited through the web using crafted SWF content.
Is macOS vulnerable to CVE-2013-0643?
No, macOS installations are not vulnerable to CVE-2013-0643.