HPSBMU02948Vendor advisory
http://marc.info/?l=bugtraq&m=139455789818399&w=2 CVE-2012-4167
Adobe Flash Player Integer Overflow Remote Code Execution
Record summary
CVE-2012-4167 has a selected CVSS score of 10.0.
Description
Integer overflow in Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 10.3.183.23 and 11.x before 11.2.202.238 on Linux, before 11.1.111.16 on Android 2.x and 3.x, and before 11.1.115.17 on Android 4.x; Adobe AIR before 3.4.0.2540; and Adobe AIR SDK before 3.4.0.2540 allows attackers to execute arbitrary code via unspecified vectors.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 12, 2013 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Flash PlayerBrowse Adobe / Flash Player | VulnCheck | Version data not supplied | |
References
5RHSA-2012:1203Vendor advisory
http://rhn.redhat.com/errata/RHSA-2012-1203.html GLSA-201209-01Vendor advisory
http://security.gentoo.org/glsa/glsa-201209-01.xml adobe.comConfirmation
http://www.adobe.com/support/security/bulletins/apsb12-19.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-4167