First published: Sat Mar 12 2016(Updated: )
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0993 and CVE-2016-1010.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | <=20.0.0.306 | |
Apple iOS and macOS | ||
Chrome OS | ||
Linux Kernel | ||
Microsoft Windows | ||
Adobe AIR SDK | <=20.0.0.233 | |
Android | ||
Adobe AIR | <=20.0.0.260 | |
Samsung X14J eu | =t-ms14jakucb-1102.5 | |
iOS | ||
Adobe Acrobat Reader | <=11.2.202.569 | |
Adobe Flash Player | <=20.2.2.306 | |
Adobe Acrobat Reader | <=20.0.0.306 | |
Microsoft Windows 10 | ||
Adobe Acrobat Reader | <=20.0.0.306 | |
Microsoft Windows 8.1 | ||
Adobe AIR | <=20.0.0.260 | |
Adobe AIR SDK & Compiler | <=20.0.0.260 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0963 has a critical severity rating due to its potential to allow arbitrary code execution.
To fix CVE-2016-0963, update Adobe Flash Player to version 21.0.0.182 or later, and Adobe AIR to version 21.0.0.176 or later.
Adobe Flash Player versions before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 are affected by CVE-2016-0963.
Yes, Adobe AIR versions prior to 21.0.0.176 are vulnerable to CVE-2016-0963.
CVE-2016-0963 affects Windows, OS X, and Linux based systems running the vulnerable Adobe Flash Player and Adobe AIR versions.