CVE-2017-11213: Integer Overflow
Adobe Security Bulletin APSB17-33 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB17-33:
Out-of-bounds Read Remote Code Execution Critical CVE-2017-3112 Out-of-bounds Read Remote Code Execution Critical CVE-2017-3114 Out-of-bounds Read Remote Code Execution Critical CVE-2017-11213 Use after free Remote Code Execution Critical CVE-2017-11215 Use after free Remote Code Execution Critical CVE-2017-11225
External References:
https://helpx.adobe.com/security/products/flash-player/apsb17-33.html
Other sources
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer due to an integer overflow; the computation is part of the abstraction that creates an arbitrarily sized transparent or opaque bitmap image. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-11213?
CVE-2017-11213 is a vulnerability in Adobe Flash Player 27.0.0.183 and earlier versions that allows an attacker to read data past the end of the target buffer due to an integer overflow.
How severe is CVE-2017-11213?
CVE-2017-11213 is classified as a critical vulnerability with a severity rating of 9.8 out of 10.
Which software versions are affected by CVE-2017-11213?
Adobe Flash Player versions up to and including 27.0.0.183 are affected by CVE-2017-11213.
How can I fix CVE-2017-11213?
To fix CVE-2017-11213, update Adobe Flash Player to version 27.0.0.187 or later.
Are Redhat Enterprise Linux Desktop 6.0, Redhat Enterprise Linux Server 6.0, and Redhat Enterprise Linux Workstation 6.0 affected by CVE-2017-11213?
Yes, Redhat Enterprise Linux Desktop 6.0, Redhat Enterprise Linux Server 6.0, and Redhat Enterprise Linux Workstation 6.0 are affected by CVE-2017-11213.