First published: Wed Jul 10 2013(Updated: )
Integer overflow in Adobe Flash Player before 11.7.700.232 and 11.8.x before 11.8.800.94 on Windows and Mac OS X, before 11.2.202.297 on Linux, before 11.1.111.64 on Android 2.x and 3.x, and before 11.1.115.69 on Android 4.x allows attackers to execute arbitrary code via PCM data that is not properly handled during resampling.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Flash Player | <=11.7.700.224 | |
Macromedia Flash Player | =11.0 | |
Macromedia Flash Player | =11.0.1.152 | |
Macromedia Flash Player | =11.0.1.153 | |
Macromedia Flash Player | =11.1 | |
Macromedia Flash Player | =11.1.102.55 | |
Macromedia Flash Player | =11.1.102.59 | |
Macromedia Flash Player | =11.1.102.62 | |
Macromedia Flash Player | =11.1.102.63 | |
Macromedia Flash Player | =11.1.111.8 | |
Macromedia Flash Player | =11.1.111.44 | |
Macromedia Flash Player | =11.1.111.50 | |
Macromedia Flash Player | =11.1.111.54 | |
Macromedia Flash Player | =11.1.115.7 | |
Macromedia Flash Player | =11.1.115.34 | |
Macromedia Flash Player | =11.1.115.48 | |
Macromedia Flash Player | =11.1.115.54 | |
Macromedia Flash Player | =11.1.115.58 | |
Macromedia Flash Player | =11.2.202.223 | |
Macromedia Flash Player | =11.2.202.228 | |
Macromedia Flash Player | =11.2.202.233 | |
Macromedia Flash Player | =11.2.202.235 | |
Macromedia Flash Player | =11.2.202.236 | |
Macromedia Flash Player | =11.2.202.238 | |
Macromedia Flash Player | =11.2.202.243 | |
Macromedia Flash Player | =11.2.202.251 | |
Macromedia Flash Player | =11.2.202.258 | |
Macromedia Flash Player | =11.2.202.261 | |
Macromedia Flash Player | =11.2.202.262 | |
Macromedia Flash Player | =11.2.202.270 | |
Macromedia Flash Player | =11.2.202.273 | |
Macromedia Flash Player | =11.2.202.275 | |
Macromedia Flash Player | =11.2.202.280 | |
Macromedia Flash Player | =11.2.202.285 | |
Macromedia Flash Player | =11.3.300.257 | |
Macromedia Flash Player | =11.3.300.262 | |
Macromedia Flash Player | =11.3.300.265 | |
Macromedia Flash Player | =11.3.300.268 | |
Macromedia Flash Player | =11.3.300.270 | |
Macromedia Flash Player | =11.3.300.271 | |
Macromedia Flash Player | =11.3.300.273 | |
Macromedia Flash Player | =11.4.402.265 | |
Macromedia Flash Player | =11.4.402.278 | |
Macromedia Flash Player | =11.4.402.287 | |
Macromedia Flash Player | =11.5.502.110 | |
Macromedia Flash Player | =11.5.502.135 | |
Macromedia Flash Player | =11.5.502.136 | |
Macromedia Flash Player | =11.5.502.146 | |
Macromedia Flash Player | =11.5.502.149 | |
Macromedia Flash Player | =11.6.602.167 | |
Macromedia Flash Player | =11.6.602.168 | |
Macromedia Flash Player | =11.6.602.171 | |
Macromedia Flash Player | =11.6.602.180 | |
Macromedia Flash Player | =11.7.700.169 | |
Macromedia Flash Player | =11.7.700.202 | |
Microsoft Windows Operating System | ||
Macromedia Flash Player | <=11.7.700.225 | |
Macromedia Flash Player | =11.7.700.224 | |
Apple iOS and macOS | ||
Macromedia Flash Player | <=11.2.202.291 | |
Linux Kernel | ||
Macromedia Flash Player | <=11.1.115.59 | |
Android | =2.0 | |
Android | =2.0.1 | |
Android | =2.1 | |
Android | =2.2 | |
Android | =2.2-rev1 | |
Android | =2.2.1 | |
Android | =2.2.2 | |
Android | =2.2.3 | |
Android | =2.3 | |
Android | =2.3-rev1 | |
Android | =2.3.1 | |
Android | =2.3.2 | |
Android | =2.3.3 | |
Android | =2.3.4 | |
Android | =2.3.5 | |
Android | =2.3.6 | |
Android | =2.3.7 | |
Android | =3.0 | |
Android | =3.1 | |
Android | =3.2 | |
Android | =3.2.1 | |
Android | =3.2.2 | |
Android | =3.2.4 | |
Android | =3.2.6 | |
Macromedia Flash Player | <=11.1.115.63 | |
Android | =4.0 | |
Android | =4.0.1 | |
Android | =4.0.2 | |
Android | =4.0.3 | |
Android | =4.0.4 | |
Android | =4.1 | |
Android | =4.1.2 | |
Android | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3347 is rated as critical, allowing attackers to execute arbitrary code.
To fix CVE-2013-3347, update Adobe Flash Player to version 11.7.700.232 or later.
CVE-2013-3347 affects Adobe Flash Player versions prior to 11.7.700.232 on Windows and Mac OS X, and various versions on Linux and Android.
Yes, CVE-2013-3347 can be exploited remotely via malicious PCM data.
Exploiting CVE-2013-3347 can lead to arbitrary code execution, potentially compromising the affected system.