First published: Wed Sep 11 2013(Updated: )
Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x and 3.x, and before 11.1.115.81 on Android 4.x; Adobe AIR before 3.8.0.1430; and Adobe AIR SDK & Compiler before 3.8.0.1430 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3361, CVE-2013-3362, and CVE-2013-3363.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Player for Internet Explorer 11 | >=11.0<11.7.700.242 | |
Adobe Flash Player for Internet Explorer 11 | >=11.8<11.8.800.168 | |
macOS Yosemite | ||
Microsoft Windows | ||
Adobe Flash Player for Internet Explorer 11 | >=11.0<11.2.202.310 | |
Linux Kernel | ||
Adobe Flash Player for Internet Explorer 11 | >=11.0<11.1.111.73 | |
Google Android | >=2.0<=2.3.7 | |
Google Android | >=3.0<=3.2.6 | |
Adobe Flash Player for Internet Explorer 11 | >=11.0<11.1.115.81 | |
Google Android | >=4.0<=4.4.4 | |
Adobe AIR | <3.8.0.1430 | |
Adobe AIR SDK and Compiler | <3.8.0.1430 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5324 has been rated as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2013-5324, users should upgrade to Adobe Flash Player version 11.7.700.242 or later.
Adobe Flash Player versions prior to 11.7.700.242 on Windows and Mac OS X, and earlier than version 11.2.202.310 on Linux are affected by CVE-2013-5324.
Yes, versions of Adobe Flash Player prior to 11.1.111.73 on Android 2.x and 3.x, and earlier than 11.1.115.81 on Android 4.x are vulnerable.
Yes, Adobe AIR versions before 3.8.0.1430 are also impacted by CVE-2013-5324.