First published: Wed Mar 13 2013(Updated: )
Integer overflow in Adobe Flash Player before 10.3.183.68 and 11.x before 11.6.602.180 on Windows and Mac OS X, before 10.3.183.68 and 11.x before 11.2.202.275 on Linux, before 11.1.111.44 on Android 2.x and 3.x, and before 11.1.115.48 on Android 4.x; Adobe AIR before 3.6.0.6090; Adobe AIR SDK before 3.6.0.6090; and Adobe AIR SDK & Compiler before 3.6.0.6090 allows attackers to execute arbitrary code via unspecified vectors.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | <=11.6.602.171 | |
Adobe Acrobat Reader | =11.0 | |
Adobe Acrobat Reader | =11.0.1.152 | |
Adobe Acrobat Reader | =11.0.1.152 | |
Adobe Acrobat Reader | =11.0.1.153 | |
Adobe Acrobat Reader | =11.1 | |
Adobe Acrobat Reader | =11.1.102.55 | |
Adobe Acrobat Reader | =11.1.102.55 | |
Adobe Acrobat Reader | =11.1.102.59 | |
Adobe Acrobat Reader | =11.1.102.62 | |
Adobe Acrobat Reader | =11.1.102.63 | |
Adobe Acrobat Reader | =11.1.111.5 | |
Adobe Acrobat Reader | =11.1.111.6 | |
Adobe Acrobat Reader | =11.1.111.7 | |
Adobe Acrobat Reader | =11.1.111.8 | |
Adobe Acrobat Reader | =11.1.115.7 | |
Adobe Acrobat Reader | =11.1.115.34 | |
Adobe Acrobat Reader | =11.1.115.36 | |
Adobe Acrobat Reader | =11.2.202.223 | |
Adobe Acrobat Reader | =11.2.202.228 | |
Adobe Acrobat Reader | =11.2.202.233 | |
Adobe Acrobat Reader | =11.2.202.235 | |
Adobe Acrobat Reader | =11.2.202.236 | |
Adobe Acrobat Reader | =11.2.202.238 | |
Adobe Acrobat Reader | =11.2.202.243 | |
Adobe Acrobat Reader | =11.2.202.251 | |
Adobe Acrobat Reader | =11.2.202.258 | |
Adobe Acrobat Reader | =11.2.202.261 | |
Adobe Acrobat Reader | =11.2.202.262 | |
Adobe Acrobat Reader | =11.2.202.270 | |
Adobe Acrobat Reader | =11.2.202.273 | |
Adobe Acrobat Reader | =11.3.300.257 | |
Adobe Acrobat Reader | =11.3.300.262 | |
Adobe Acrobat Reader | =11.3.300.265 | |
Adobe Acrobat Reader | =11.3.300.268 | |
Adobe Acrobat Reader | =11.3.300.270 | |
Adobe Acrobat Reader | =11.3.300.271 | |
Adobe Acrobat Reader | =11.3.300.273 | |
Adobe Acrobat Reader | =11.4.402.265 | |
Adobe Acrobat Reader | =11.4.402.278 | |
Adobe Acrobat Reader | =11.4.402.287 | |
Adobe Acrobat Reader | =11.5.502.110 | |
Adobe Acrobat Reader | =11.5.502.135 | |
Adobe Acrobat Reader | =11.5.502.136 | |
Adobe Acrobat Reader | =11.5.502.146 | |
Adobe Acrobat Reader | =11.5.502.149 | |
Adobe Acrobat Reader | =11.6.602.167 | |
Adobe Acrobat Reader | =11.6.602.168 | |
Apple iOS and macOS | ||
Microsoft Windows | ||
Adobe Acrobat Reader | <=11.2.202.273 | |
Adobe Flash Player | <=11.1.111.43 | |
Linux Kernel | ||
Adobe Flash Player | =10.1.106.17 | |
Adobe Flash Player | =10.2.157.51 | |
Adobe Flash Player | =10.3.186.7 | |
Adobe Flash Player | =11.0.1.153 | |
Adobe Flash Player | =11.1.102.59 | |
Adobe Flash Player | =11.1.111.5 | |
Adobe Flash Player | =11.1.111.6 | |
Adobe Flash Player | =11.1.111.7 | |
Adobe Flash Player | =11.1.111.8 | |
Adobe Flash Player | =11.1.111.9 | |
Adobe Flash Player | =11.1.111.10 | |
Adobe Flash Player | =11.1.111.16 | |
Adobe Flash Player | =11.1.111.19 | |
Adobe Flash Player | =11.1.111.24 | |
Adobe Flash Player | =11.1.111.29 | |
Adobe Flash Player | =11.1.111.31 | |
Adobe Flash Player | =11.1.111.32 | |
Android | =2.0 | |
Android | =2.0.1 | |
Android | =2.1 | |
Android | =2.2 | |
Android | =2.2-rev1 | |
Android | =2.2.1 | |
Android | =2.2.2 | |
Android | =2.2.3 | |
Android | =2.3 | |
Android | =2.3-rev1 | |
Android | =2.3.1 | |
Android | =2.3.2 | |
Android | =2.3.3 | |
Android | =2.3.4 | |
Android | =2.3.5 | |
Android | =2.3.6 | |
Android | =2.3.7 | |
Android | =3.0 | |
Android | =3.1 | |
Android | =3.2 | |
Android | =3.2.1 | |
Android | =3.2.2 | |
Android | =3.2.4 | |
Android | =3.2.6 | |
Android | =4.0 | |
Android | =4.0.1 | |
Android | =4.0.2 | |
Android | =4.0.3 | |
Android | =4.0.4 | |
Android | =4.1 | |
Android | =4.2 | |
Adobe AIR SDK | <=3.6.0.599 | |
Adobe AIR SDK | <=3.6.0.597 | |
Adobe AIR SDK | =3.0.0.4080 | |
Adobe AIR SDK | =3.1.0.488 | |
Adobe AIR SDK | =3.2.0.2070 | |
Adobe AIR SDK | =3.3.0.3650 | |
Adobe AIR SDK | =3.3.0.3690 | |
Adobe AIR SDK | =3.4.0.2540 | |
Adobe AIR SDK | =3.4.0.2710 | |
Adobe AIR SDK | =3.5.0.600 | |
Adobe AIR SDK | =3.5.0.880 | |
Adobe AIR SDK | =3.5.0.890 | |
Adobe AIR SDK | =3.5.0.1060 | |
Adobe AIR SDK | ||
Adobe AIR SDK | <=3.6.0.597 | |
Adobe AIR SDK | =1.0 | |
Adobe AIR SDK | =1.0.1 | |
Adobe AIR SDK | =1.0.8.4990 | |
Adobe AIR SDK | =1.0.4990 | |
Adobe AIR SDK | =1.1 | |
Adobe AIR SDK | =1.1.0.5790 | |
Adobe AIR SDK | =1.5 | |
Adobe AIR SDK | =1.5.0.7220 | |
Adobe AIR SDK | =1.5.1 | |
Adobe AIR SDK | =1.5.1.8210 | |
Adobe AIR SDK | =1.5.2 | |
Adobe AIR SDK | =1.5.3 | |
Adobe AIR SDK | =1.5.3.9120 | |
Adobe AIR SDK | =1.5.3.9130 | |
Adobe AIR SDK | =2.0.2 | |
Adobe AIR SDK | =2.0.2.12610 | |
Adobe AIR SDK | =2.0.3 | |
Adobe AIR SDK | =2.0.3.13070 | |
Adobe AIR SDK | =2.0.4 | |
Adobe AIR SDK | =2.5.0.16600 | |
Adobe AIR SDK | =2.5.1.17730 | |
Adobe AIR SDK | =2.6 | |
Adobe AIR SDK | =2.6.0.19120 | |
Adobe AIR SDK | =2.6.0.19140 | |
Adobe AIR SDK | =2.7 | |
Adobe AIR SDK | =2.7.0.1948 | |
Adobe AIR SDK | =2.7.0.1953 | |
Adobe AIR SDK | =2.7.0.19480 | |
Adobe AIR SDK | =2.7.0.19530 | |
Adobe AIR SDK | =2.7.1 | |
Adobe AIR SDK | =2.7.1.19610 | |
Adobe AIR SDK | =3.0.0.408 | |
Adobe AIR SDK | =3.0.0.4080 | |
Adobe AIR SDK | =3.1.0.485 | |
Adobe AIR SDK | =3.1.0.488 | |
Adobe AIR SDK | =3.1.0.4880 | |
Adobe AIR SDK | =3.2.0.207 | |
Adobe AIR SDK | =3.2.0.2070 | |
Adobe AIR SDK | =3.3.0.3670 | |
Adobe AIR SDK | =3.4.0.2540 | |
Adobe AIR SDK | =3.4.0.2710 | |
Adobe AIR SDK | =3.5.0.600 | |
Adobe AIR SDK | =3.5.0.880 | |
Adobe AIR SDK | =3.5.0.890 | |
Adobe AIR SDK | =3.5.0.1060 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0646 is classified as a critical vulnerability due to its potential for exploitation and the risk it poses to user systems.
To resolve CVE-2013-0646, you should update Adobe Flash Player to versions 10.3.183.68 or later, as well as ensure Adobe AIR is updated to version 3.6.0.6090 or higher.
CVE-2013-0646 affects Adobe Flash Player versions prior to 10.3.183.68 and 11.x before 11.6.602.180, as well as Adobe AIR prior to 3.6.0.6090.
Vulnerable systems include Windows, Mac OS X, Linux platforms, and Android devices running specific versions of Adobe Flash Player.
Mitigating risks without updating is highly discouraged as the vulnerability can lead to serious exploitation; applying patches is the best defense.