First published: Wed Dec 11 2013(Updated: )
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Flash Player | >=11.0<11.7.700.257 | |
Macromedia Flash Player | >=11.8<11.8.800.175 | |
Macromedia Flash Player | >=11.9<11.9.900.700 | |
Apple iOS and macOS | ||
Microsoft Windows Operating System | ||
Macromedia Flash Player | >=11.0<11.2.202.332 | |
Linux Kernel | ||
Adobe | <3.9.0.1380 | |
Adobe AIR | <3.9.0.1380 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5332 is considered critical due to its ability to allow attackers to execute arbitrary code.
To fix CVE-2013-5332, upgrade Adobe Flash Player to version 11.7.700.257 or later.
CVE-2013-5332 affects Adobe Flash Player versions before 11.7.700.257 on various platforms including Windows and Mac OS X.
Yes, CVE-2013-5332 can be exploited remotely if a user visits a crafted web page that contains malicious content.
Yes, Adobe AIR versions before 3.9.0.1380 are also vulnerable to CVE-2013-5332.