First published: Wed Feb 05 2014(Updated: )
Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | ||
Adobe Acrobat Reader | >=11.0<11.2.202.336 | |
Linux Kernel | ||
Adobe Acrobat Reader | >=11.0<11.7.700.261 | |
Adobe Acrobat Reader | >=11.8<12.0.0.44 | |
Apple iOS and macOS | ||
Microsoft Windows | ||
All of | ||
Adobe Acrobat Reader | <11.2.202.336 | |
Linux Kernel | ||
All of | ||
Any of | ||
Adobe Acrobat Reader | <11.7.700.261 | |
Adobe Acrobat Reader | >=11.8.800.94<12.0.0.44 | |
Any of | ||
Apple iOS and macOS | ||
Microsoft Windows | ||
All of | ||
Google Chrome | <32.0.1700.107 | |
Any of | ||
Apple iOS and macOS | ||
Chrome OS | ||
Linux Kernel | ||
Microsoft Windows | ||
redhat enterprise Linux desktop | =5.0 | |
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux eus | =6.5 | |
redhat enterprise Linux server | =5.0 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux server aus | =6.5 | |
redhat enterprise Linux workstation | =5.0 | |
redhat enterprise Linux workstation | =6.0 | |
openSUSE | =11.4 | |
openSUSE | =12.3 | |
openSUSE | =13.1 | |
SUSE Linux Enterprise Desktop with Beagle | =11-sp2 | |
SUSE Linux Enterprise Desktop with Beagle | =11-sp3 |
The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0497 has a critical severity rating as it allows remote code execution through an integer underflow vulnerability in Adobe Flash Player.
Adobe Flash Player versions before 11.7.700.261, between 11.8.x and 12.0.x prior to 12.0.0.44 on Windows and Mac, and before 11.2.202.336 on Linux are affected by CVE-2014-0497.
To remediate CVE-2014-0497, update Adobe Flash Player to the latest version available.
Yes, CVE-2014-0497 can be exploited remotely, allowing attackers to execute arbitrary code.
CVE-2014-0497 impacts Adobe Flash Player on Windows, Mac OS X, and Linux platforms.