ID

VAR-201303-0322


CVE

CVE-2013-2555


TITLE

Windows Run on Adobe Flash Player Vulnerable to arbitrary code execution

Trust: 0.8

sources: JVNDB: JVNDB-2013-001829

DESCRIPTION

Integer overflow in Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and before 11.1.115.54 on Android 4.x; Adobe AIR before 3.7.0.1530; and Adobe AIR SDK & Compiler before 3.7.0.1530 allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013. Windows Run on Adobe Flash Player Contains a vulnerability that allows arbitrary code execution. This vulnerability CanSecWest 2013 of Pwn2Own Proven in competition.A third party may be able to execute arbitrary code by using overflow. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the handling of RTMP data. The issue lies in the ability to exchange objects, allowing for an object confusion vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2013:0730-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2013-0730.html Issue date: 2013-04-10 CVE Names: CVE-2013-1378 CVE-2013-1379 CVE-2013-1380 CVE-2013-2555 ===================================================================== 1. Summary: An updated Adobe Flash Player package that fixes multiple security issues is now available for Red Hat Enterprise Linux 5 and 6 Supplementary. The Red Hat Security Response Team has rated this update as having critical security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. These vulnerabilities are detailed in the Adobe Security bulletin APSB13-11, listed in the References section. Specially-crafted SWF content could cause flash-plugin to crash or, potentially, execute arbitrary code when a victim loads a page containing the malicious SWF content. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/knowledge/articles/11258 5. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 5): i386: flash-plugin-11.2.202.280-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.280-1.el5.i386.rpm Red Hat Enterprise Linux Server Supplementary (v. 5): i386: flash-plugin-11.2.202.280-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.280-1.el5.i386.rpm Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-11.2.202.280-2.el6.i686.rpm x86_64: flash-plugin-11.2.202.280-2.el6.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-11.2.202.280-2.el6.i686.rpm x86_64: flash-plugin-11.2.202.280-2.el6.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-11.2.202.280-2.el6.i686.rpm x86_64: flash-plugin-11.2.202.280-2.el6.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://www.redhat.com/security/data/cve/CVE-2013-1378.html https://www.redhat.com/security/data/cve/CVE-2013-1379.html https://www.redhat.com/security/data/cve/CVE-2013-1380.html https://www.redhat.com/security/data/cve/CVE-2013-2555.html https://access.redhat.com/security/updates/classification/#critical http://www.adobe.com/support/security/bulletins/apsb13-11.html 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2013 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFRZSx1XlSAg2UNWIIRAr6FAJ4qywRlQEwJ2ZFS1nM2f18anrHFMgCfVl1B IGrWdeCGaTj3hV9QmXS9xkY= =09w+ -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c04039150 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c04039150 Version: 1 HPSBMU02948 rev.1 - HP Systems Insight Manager (SIM) Running on Linux and Windows, Remote Execution of Arbitrary Code, Denial of Service (DoS), Disclosure of Information NOTICE: The information in this Security Bulletin should be acted upon as soon as possible. Release Date: 2014-03-10 Last Updated: 2014-03-10 Potential Security Impact: Remote execution of arbitrary code, Denial of Service (DoS), disclosure of information Source: Hewlett-Packard Company, HP Software Security Response Team VULNERABILITY SUMMARY Potential security vulnerabilities have been identified with HP Systems Insight Manager (SIM) running on Linux and Windows. The vulnerabilities could be exploited remotely resulting in execution of arbitrary code, Denial of Service (DoS), or disclosure of information. References: CVE-2012-1535 (Execution of Arbitrary Code, Denial of Service (DoS)) CVE-2012-4163 (Execution of Arbitrary Code, Denial of Service (DoS)) CVE-2012-4164 (Execution of Arbitrary Code, Denial of Service (DoS)) CVE-2012-4165 (Execution of Arbitrary Code, Denial of Service (DoS)) CVE-2012-4167 (Execution of Arbitrary Code) CVE-2012-4168 (Disclosure of Information) CVE-2013-0646 (Execution of Arbitrary Code) CVE-2013-0650 (Execution of Arbitrary Code) CVE-2013-1371 (Execution of Arbitrary Code, Denial of Service (DoS)) CVE-2013-1375 (Execution of Arbitrary Code) CVE-2013-1378 (Execution of Arbitrary Code, Denial of Service (DoS)) CVE-2013-1379 (Execution of Arbitrary Code, Denial of Service (DoS)) CVE-2013-1380 (Execution of Arbitrary Code, Denial of Service (DoS)) CVE-2013-2555 (Execution of Arbitrary Code) SSRT100986 SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed. HP Systems Insight Manager (SIM) prior to v7.3 for Linux and Windows (CVE-2013-0646, CVE-2013-0650, CVE-2013-1371, CVE-2013-1375, CVE-2013-1378, CVE-2013-1379, CVE-2013-1380, CVE-2013-2555) HP Systems Insight Manager (SIM) prior to v7.2 for Linux and Windows (CVE-2012-4168, CVE-2012-4167, CVE-2012-4165, CVE-2012-4164, CVE-2012-4163, CVE-2012-1535) BACKGROUND CVSS 2.0 Base Metrics =========================================================== Reference Base Vector Base Score CVE-2012-1535 (AV:N/AC:M/Au:N/C:C/I:C/A:C) 9.3 CVE-2012-4163 (AV:N/AC:L/Au:N/C:C/I:C/A:C) 10.0 CVE-2012-4164 (AV:N/AC:L/Au:N/C:C/I:C/A:C) 10.0 CVE-2012-4165 (AV:N/AC:L/Au:N/C:C/I:C/A:C) 10.0 CVE-2012-4167 (AV:N/AC:L/Au:N/C:C/I:C/A:C) 10.0 CVE-2012-4168 (AV:N/AC:M/Au:N/C:P/I:N/A:N) 4.3 CVE-2013-0646 (AV:N/AC:L/Au:N/C:C/I:C/A:C) 10.0 CVE-2013-0650 (AV:N/AC:L/Au:N/C:C/I:C/A:C) 10.0 CVE-2013-1371 (AV:N/AC:L/Au:N/C:C/I:C/A:C) 10.0 CVE-2013-1375 (AV:N/AC:L/Au:N/C:C/I:C/A:C) 10.0 CVE-2013-1378 (AV:N/AC:L/Au:N/C:C/I:C/A:C) 10.0 CVE-2013-1379 (AV:N/AC:L/Au:N/C:C/I:C/A:C) 10.0 CVE-2013-1380 (AV:N/AC:L/Au:N/C:C/I:C/A:C) 10.0 CVE-2013-2555 (AV:N/AC:L/Au:N/C:C/I:C/A:C) 10.0 =========================================================== Information on CVSS is documented in HP Customer Notice: HPSN-2008-002 RESOLUTION HP has made Systems Insight Manager (SIM) v7.3 available for Linux and Windows to resolve the vulnerabilities. Information and downloads for HP SIM can be found at the following locations: http://h18013.www1.hp.com/products/servers/management/hpsim/download.html Insight Management DVD: http://h18013.www1.hp.com/products/servers/management/fpdownload.html HISTORY Version:1 (rev.1) - 10 March 2013 Initial release Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy. Support: For issues about implementing the recommendations of this Security Bulletin, contact normal HP Services support channel. For other issues about the content of this Security Bulletin, send e-mail to security-alert@hp.com. Report: To report a potential security vulnerability with any HP supported product, send Email to: security-alert@hp.com Subscribe: To initiate a subscription to receive future HP Security Bulletin alerts via Email: http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins Security Bulletin Archive: A list of recently released Security Bulletins is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/secBullArchive/ Software Product Category: The Software Product Category is represented in the title by the two characters following HPSB. 3C = 3COM 3P = 3rd Party Software GN = HP General Software HF = HP Hardware and Firmware MP = MPE/iX MU = Multi-Platform Software NS = NonStop Servers OV = OpenVMS PI = Printing and Imaging PV = ProCurve ST = Storage Software TU = Tru64 UNIX UX = HP-UX Copyright 2014 Hewlett-Packard Development Company, L.P. Hewlett-Packard Company shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental,special or consequential damages including downtime cost; lost profits; damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. Hewlett-Packard Company and the names of Hewlett-Packard products referenced herein are trademarks of Hewlett-Packard Company in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners. Background ========== The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Please review the CVE identifiers referenced below for details. Furthermore, a remote attacker may be able to bypass access restrictions. Workaround ========== There is no known workaround at this time. Resolution ========== All Adobe Flash Player users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v ">=www-plugins/adobe-flash-11.2.202.310" References ========== [ 1 ] CVE-2012-5248 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5248 [ 2 ] CVE-2012-5248 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5248 [ 3 ] CVE-2012-5249 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5249 [ 4 ] CVE-2012-5249 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5249 [ 5 ] CVE-2012-5250 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5250 [ 6 ] CVE-2012-5250 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5250 [ 7 ] CVE-2012-5251 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5251 [ 8 ] CVE-2012-5251 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5251 [ 9 ] CVE-2012-5252 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5252 [ 10 ] CVE-2012-5252 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5252 [ 11 ] CVE-2012-5253 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5253 [ 12 ] CVE-2012-5253 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5253 [ 13 ] CVE-2012-5254 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5254 [ 14 ] CVE-2012-5254 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5254 [ 15 ] CVE-2012-5255 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5255 [ 16 ] CVE-2012-5255 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5255 [ 17 ] CVE-2012-5256 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5256 [ 18 ] CVE-2012-5256 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5256 [ 19 ] CVE-2012-5257 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5257 [ 20 ] CVE-2012-5257 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5257 [ 21 ] CVE-2012-5258 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5258 [ 22 ] CVE-2012-5258 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5258 [ 23 ] CVE-2012-5259 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5259 [ 24 ] CVE-2012-5259 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5259 [ 25 ] CVE-2012-5260 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5260 [ 26 ] CVE-2012-5260 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5260 [ 27 ] CVE-2012-5261 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5261 [ 28 ] CVE-2012-5261 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5261 [ 29 ] CVE-2012-5262 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5262 [ 30 ] CVE-2012-5262 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5262 [ 31 ] CVE-2012-5263 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5263 [ 32 ] CVE-2012-5263 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5263 [ 33 ] CVE-2012-5264 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5264 [ 34 ] CVE-2012-5264 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5264 [ 35 ] CVE-2012-5265 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5265 [ 36 ] CVE-2012-5265 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5265 [ 37 ] CVE-2012-5266 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5266 [ 38 ] CVE-2012-5266 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5266 [ 39 ] CVE-2012-5267 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5267 [ 40 ] CVE-2012-5267 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5267 [ 41 ] CVE-2012-5268 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5268 [ 42 ] CVE-2012-5268 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5268 [ 43 ] CVE-2012-5269 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5269 [ 44 ] CVE-2012-5269 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5269 [ 45 ] CVE-2012-5270 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5270 [ 46 ] CVE-2012-5270 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5270 [ 47 ] CVE-2012-5271 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5271 [ 48 ] CVE-2012-5271 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5271 [ 49 ] CVE-2012-5272 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5272 [ 50 ] CVE-2012-5272 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5272 [ 51 ] CVE-2012-5274 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5274 [ 52 ] CVE-2012-5275 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5275 [ 53 ] CVE-2012-5276 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5276 [ 54 ] CVE-2012-5277 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5277 [ 55 ] CVE-2012-5278 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5278 [ 56 ] CVE-2012-5279 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5279 [ 57 ] CVE-2012-5280 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5280 [ 58 ] CVE-2012-5676 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5676 [ 59 ] CVE-2012-5677 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5677 [ 60 ] CVE-2012-5678 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5678 [ 61 ] CVE-2013-0504 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0504 [ 62 ] CVE-2013-0630 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0630 [ 63 ] CVE-2013-0633 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0633 [ 64 ] CVE-2013-0634 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0634 [ 65 ] CVE-2013-0637 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0637 [ 66 ] CVE-2013-0638 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0638 [ 67 ] CVE-2013-0639 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0639 [ 68 ] CVE-2013-0642 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0642 [ 69 ] CVE-2013-0643 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0643 [ 70 ] CVE-2013-0644 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0644 [ 71 ] CVE-2013-0645 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0645 [ 72 ] CVE-2013-0646 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0646 [ 73 ] CVE-2013-0647 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0647 [ 74 ] CVE-2013-0648 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0648 [ 75 ] CVE-2013-0649 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0649 [ 76 ] CVE-2013-0650 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0650 [ 77 ] CVE-2013-1365 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1365 [ 78 ] CVE-2013-1366 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1366 [ 79 ] CVE-2013-1367 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1367 [ 80 ] CVE-2013-1368 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1368 [ 81 ] CVE-2013-1369 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1369 [ 82 ] CVE-2013-1370 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1370 [ 83 ] CVE-2013-1371 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1371 [ 84 ] CVE-2013-1372 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1372 [ 85 ] CVE-2013-1373 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1373 [ 86 ] CVE-2013-1374 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1374 [ 87 ] CVE-2013-1375 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1375 [ 88 ] CVE-2013-1378 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1378 [ 89 ] CVE-2013-1379 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1379 [ 90 ] CVE-2013-1380 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1380 [ 91 ] CVE-2013-2555 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2555 [ 92 ] CVE-2013-2728 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2728 [ 93 ] CVE-2013-3343 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3343 [ 94 ] CVE-2013-3344 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3344 [ 95 ] CVE-2013-3345 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3345 [ 96 ] CVE-2013-3347 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3347 [ 97 ] CVE-2013-3361 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3361 [ 98 ] CVE-2013-3362 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3362 [ 99 ] CVE-2013-3363 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3363 [ 100 ] CVE-2013-5324 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-5324 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-201309-06.xml Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2013 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . BACKGROUND --------------------- Adobe Flash Player is a cross-platform browser-based application runtime that delivers viewing of expressive applications, content, and videos across screens and browsers. It is installed on 98% of computers. II. The vulnerability is caused by an object confusion error when processing malformed Real Time Messaging Protocol (RTMP) data received during the initial phase of communication with a server, which could be exploited by remote attackers to compromise a vulnerable system via a malicious web page. III. Binary Analysis & Exploits/PoCs --------------------------------------- In-depth technical analysis of the vulnerability and a fully functional remote code execution exploit are available through the VUPEN BAE (Binary Analysis & Exploits) portal: http://www.vupen.com/english/services/ba-index.php VUPEN Binary Analysis & Exploits Service provides private exploits and in-depth technical analysis of the most significant public vulnerabilities based on disassembly, reverse engineering, protocol analysis, and code audit. The service allows governments and major corporations to evaluate risks, and protect infrastructures and assets against new threats. The service also allows security vendors (IPS, IDS, AntiVirus) to supplement their internal research efforts and quickly develop both vulnerability-based and exploit-based signatures to proactively protect their customers from attacks and emerging threats. V. VUPEN Threat Protection Program ----------------------------------- Governments and major corporations which are members of the VUPEN Threat Protection Program (TPP) have been proactively alerted about the vulnerability when it was discovered by VUPEN in advance of its public disclosure, and have received a detailed attack detection guidance to protect national and critical infrastructures against potential 0-day attacks exploiting this vulnerability: http://www.vupen.com/english/services/tpp-index.php VI. VII. CREDIT -------------- This vulnerability was discovered by Nicolas Joly of VUPEN Security VIII. ABOUT VUPEN Security --------------------------- VUPEN is the leading provider of defensive and offensive cybersecurity intelligence and advanced vulnerability research. VUPEN solutions enable corporations and governments to manage risks, and protect critical networks and infrastructures against known and unknown vulnerabilities. VUPEN solutions include: * VUPEN Binary Analysis & Exploits Service (BAE) : http://www.vupen.com/english/services/ba-index.php * VUPEN Threat Protection Program (TPP) : http://www.vupen.com/english/services/tpp-index.php IX. DISCLOSURE TIMELINE ----------------------------- 2012-02-15 - Vulnerability Discovered by VUPEN 2013-03-06 - Vulnerability Exploited At Pwn2Own 2013 and Reported to Adobe 2013-04-17 - Public disclosure

Trust: 2.97

sources: NVD: CVE-2013-2555 // JVNDB: JVNDB-2013-001829 // ZDI: ZDI-13-288 // BID: 58396 // VULHUB: VHN-62557 // PACKETSTORM: 121221 // PACKETSTORM: 125655 // PACKETSTORM: 123225 // PACKETSTORM: 121356

AFFECTED PRODUCTS

vendor:adobemodel:flash playerscope:lteversion:11.1.115.48

Trust: 1.0

vendor:redhatmodel:enterprise linux desktopscope:eqversion:6.0

Trust: 1.0

vendor:redhatmodel:enterprise linux eusscope:eqversion:5.9

Trust: 1.0

vendor:redhatmodel:enterprise linux eusscope:eqversion:6.4

Trust: 1.0

vendor:opensusemodel:opensusescope:eqversion:12.1

Trust: 1.0

vendor:redhatmodel:enterprise linux serverscope:eqversion:6.0

Trust: 1.0

vendor:susemodel:linux enterprise desktopscope:eqversion:11

Trust: 1.0

vendor:redhatmodel:enterprise linux server ausscope:eqversion:5.9

Trust: 1.0

vendor:opensusemodel:opensusescope:eqversion:12.3

Trust: 1.0

vendor:redhatmodel:enterprise linux server ausscope:eqversion:6.4

Trust: 1.0

vendor:adobemodel:flash playerscope:lteversion:10.3.183.75

Trust: 1.0

vendor:opensusemodel:opensusescope:eqversion:11.4

Trust: 1.0

vendor:adobemodel:flash playerscope:lteversion:11.1.111.44

Trust: 1.0

vendor:adobemodel:flash playerscope:lteversion:11.2.202.275

Trust: 1.0

vendor:adobemodel:airscope:lteversion:3.6.0.6090

Trust: 1.0

vendor:redhatmodel:enterprise linux workstationscope:eqversion:6.0

Trust: 1.0

vendor:adobemodel:flash playerscope:lteversion:11.6.602.180

Trust: 1.0

vendor:adobemodel:flash playerscope:gteversion:11.0

Trust: 1.0

vendor:adobemodel:flash playerscope:ltversion:10.3.183.75

Trust: 1.0

vendor:opensusemodel:opensusescope:eqversion:12.2

Trust: 1.0

vendor:adobemodel:flash playerscope:eqversion:11.0.1.152

Trust: 0.9

vendor:adobemodel:airscope:ltversion:3.7.0.1530 (windows

Trust: 0.8

vendor:adobemodel:airscope:eqversion:macintosh

Trust: 0.8

vendor:adobemodel:airscope:eqversion:and android)

Trust: 0.8

vendor:adobemodel:air sdkscope:ltversion:(sdk & compiler) 3.7.0.1530

Trust: 0.8

vendor:adobemodel:flash playerscope:ltversion:11.1.111.50 (android 2.x and 3.x)

Trust: 0.8

vendor:adobemodel:flash playerscope:ltversion:11.1.115.54 (android 4.x)

Trust: 0.8

vendor:adobemodel:flash playerscope:ltversion:11.2.202.280 (linux)

Trust: 0.8

vendor:adobemodel:flash playerscope:ltversion:11.7.700.169 (windows and macintosh)

Trust: 0.8

vendor:adobemodel:flashscope: - version: -

Trust: 0.7

vendor:adobemodel:airscope:eqversion:3.4.0.2540

Trust: 0.6

vendor:adobemodel:flash playerscope:eqversion:11.0

Trust: 0.6

vendor:adobemodel:flash playerscope:eqversion:11.0.1.153

Trust: 0.6

vendor:adobemodel:airscope:eqversion:3.5.0.600

Trust: 0.6

vendor:adobemodel:airscope:eqversion:3.1.0.4880

Trust: 0.6

vendor:adobemodel:airscope:eqversion:3.4.0.2710

Trust: 0.6

vendor:adobemodel:airscope:eqversion:3.5.0.1060

Trust: 0.6

vendor:adobemodel:airscope:eqversion:3.3.0.3670

Trust: 0.6

vendor:adobemodel:airscope:eqversion:3.0.0.4080

Trust: 0.6

vendor:googlemodel:chromescope:eqversion:17.0.963.83

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:11.0.696.57

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.186.3

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:12.0.742.100

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.152.21

Trust: 0.3

vendor:susemodel:linux enterprise desktop sp4scope:eqversion:10

Trust: 0.3

vendor:hpmodel:systems insight managerscope:eqversion:7.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.102.55

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.154.25

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:18.0.1025.168

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.60.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.14.0

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:11.0.696.43

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.95.1

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.156.12

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.95.2

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:16.0.912.75

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:17.0.963.60

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.155.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.152.33

Trust: 0.3

vendor:adobemodel:flash player for androidscope:eqversion:11.1.102.59

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.185.22

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.51.66

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.154.13

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:13

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.115.6

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.154.27

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:19.0.1084.52

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.53.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.153.1

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.262.0

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:10.0.648.204

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:10.0.648.128

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.111.9

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.111.6

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.181.22

Trust: 0.3

vendor:hpmodel:systems insight managerscope:eqversion:6.1

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.102.63

Trust: 0.3

vendor:hpmodel:systems insight managerscope:eqversion:6.0.0.96

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:6.0.79

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.157.51

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.181.26

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.181.14

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.2.202.228

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.92.8

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:10.0.648.127

Trust: 0.3

vendor:susemodel:linux enterprise desktop sp2scope:eqversion:11

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.52.15

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:11.0.696.65

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.112.61

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.152.32

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.154.24

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.181.16

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:18.0.1025.142

Trust: 0.3

vendor:susemodel:opensusescope:eqversion:11.4

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.111.8

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.111.5

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.154.18

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:16.0.91275

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:17.0.96379

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.181.23

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.52.14.1

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.0.32.18

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:12.0.742.112

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.183.7

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:11.0.696.71

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.283.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.102.62

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.185.21

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.111.7

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.2.202.235

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.53.64

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.102.228

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.152

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:12.0.742.91

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:17.0.963.78

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.185.25

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:6.0.21.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.2.202.233

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.181.34

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.185.23

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:17.0.963.56

Trust: 0.3

vendor:hpmodel:systems insight managerscope:eqversion:6.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.61.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.186.2

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:13.0.782.107

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:15.0.874.120

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:14

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:11.0.696.77

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.186.7

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.0.22.87

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:16

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.85.3

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:17.0.96365

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.82.76

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.73.0

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:19

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.2.202.229

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.115.8

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:11.0.696.68

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.183.10

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:11.0.672.2

Trust: 0.3

vendor:hpmodel:systems insight managerscope:eqversion:6.3

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:15.0.874.121

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:12

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:14.0.835.163

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:10

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:16.0.912.77

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:18.0.1025.151

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:18.0.1025.162

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:13.0.782.112

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:11

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.115.7

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.159.1

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.105.6

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.19.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.24.0

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:15.0.874102

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.0.42.34

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:10.0.648.133

Trust: 0.3

vendor:hpmodel:systems insight managerscope:eqversion:6.2

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:13.0.782.215

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.183.4

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:10.0.648.205

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:14.0.835.186

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.2.202.223

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.154.28

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.67.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.183.5

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.92.10

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:17.0.963.46

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.106.16

Trust: 0.3

vendor:adobemodel:flash player for androidscope:eqversion:11.0.1.153

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:16.0.912.63

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.102.65

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:14.0.835.202

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.186.6

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.102.64

Trust: 0.3

sources: ZDI: ZDI-13-288 // BID: 58396 // JVNDB: JVNDB-2013-001829 // CNNVD: CNNVD-201303-175 // NVD: CVE-2013-2555

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-2555
value: HIGH

Trust: 1.0

NVD: CVE-2013-2555
value: HIGH

Trust: 0.8

ZDI: CVE-2013-2555
value: MEDIUM

Trust: 0.7

CNNVD: CNNVD-201303-175
value: CRITICAL

Trust: 0.6

VULHUB: VHN-62557
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2013-2555
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

ZDI: CVE-2013-2555
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.7

VULHUB: VHN-62557
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: ZDI: ZDI-13-288 // VULHUB: VHN-62557 // JVNDB: JVNDB-2013-001829 // CNNVD: CNNVD-201303-175 // NVD: CVE-2013-2555

PROBLEMTYPE DATA

problemtype:CWE-190

Trust: 1.1

problemtype:CWE-189

Trust: 0.9

sources: VULHUB: VHN-62557 // JVNDB: JVNDB-2013-001829 // NVD: CVE-2013-2555

THREAT TYPE

remote

Trust: 0.7

sources: PACKETSTORM: 121356 // CNNVD: CNNVD-201303-175

TYPE

input validation error

Trust: 0.6

sources: CNNVD: CNNVD-201303-175

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-001829

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-62557

PATCH

title:APSB13-11url:http://www.adobe.com/support/security/bulletins/apsb13-11.html

Trust: 1.5

title:APSB13-11 (cq04091730)url:http://helpx.adobe.com/jp/flash-player/kb/cq04091730.html

Trust: 0.8

title:openSUSE-SU-2013:0675url:http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00019.html

Trust: 0.8

title:SUSE-SU-2013:0670url:http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00016.html

Trust: 0.8

title:openSUSE-SU-2013:0672url:http://lists.opensuse.org/opensuse-updates/2013-04/msg00081.html

Trust: 0.8

title:RHSA-2013:0730url:http://rhn.redhat.com/errata/RHSA-2013-0730.html

Trust: 0.8

title:Adobe Flash Player - ダウンロードurl:http://www.adobe.com/jp/support/flashplayer/downloads.html

Trust: 0.8

title:アドビ システムズ社 Adobe Flash Player の脆弱性に関するお知らせurl:http://www.fmworld.net/biz/common/adobe/20130411f.html

Trust: 0.8

sources: ZDI: ZDI-13-288 // JVNDB: JVNDB-2013-001829

EXTERNAL IDS

db:NVDid:CVE-2013-2555

Trust: 3.9

db:JVNDBid:JVNDB-2013-001829

Trust: 0.8

db:ZDI_CANid:ZDI-CAN-1826

Trust: 0.7

db:ZDIid:ZDI-13-288

Trust: 0.7

db:CNNVDid:CNNVD-201303-175

Trust: 0.7

db:BIDid:58396

Trust: 0.4

db:PACKETSTORMid:121356

Trust: 0.2

db:SEEBUGid:SSVID-60734

Trust: 0.1

db:VULHUBid:VHN-62557

Trust: 0.1

db:PACKETSTORMid:121221

Trust: 0.1

db:PACKETSTORMid:125655

Trust: 0.1

db:PACKETSTORMid:123225

Trust: 0.1

sources: ZDI: ZDI-13-288 // VULHUB: VHN-62557 // BID: 58396 // JVNDB: JVNDB-2013-001829 // PACKETSTORM: 121221 // PACKETSTORM: 125655 // PACKETSTORM: 123225 // PACKETSTORM: 121356 // CNNVD: CNNVD-201303-175 // NVD: CVE-2013-2555

REFERENCES

url:http://www.adobe.com/support/security/bulletins/apsb13-11.html

Trust: 2.6

url:http://h30499.www3.hp.com/t5/hp-security-research-blog/pwn2own-2013/ba-p/5981157

Trust: 2.5

url:http://rhn.redhat.com/errata/rhsa-2013-0730.html

Trust: 1.8

url:http://archives.neohapsis.com/archives/bugtraq/2013-04/0197.html

Trust: 1.7

url:http://twitter.com/vupen/statuses/309713355466227713

Trust: 1.7

url:http://twitter.com/thezdi/statuses/309756927301283840

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00016.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-updates/2013-04/msg00081.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00019.html

Trust: 1.7

url:http://marc.info/?l=bugtraq&m=139455789818399&w=2

Trust: 1.6

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-2555

Trust: 0.8

url:http://www.ipa.go.jp/security/ciadr/vul/20130410-adobeflashplayer.html

Trust: 0.8

url:https://www.jpcert.or.jp/at/2013/at130020.txt

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-2555

Trust: 0.8

url:http://www.npa.go.jp/cyberpolice/topics/?seq=11224

Trust: 0.8

url:http://www.adobe.com/products/flash/

Trust: 0.3

url:http://www.adobe.com

Trust: 0.3

url:http://www.gentoo.org/security/en/glsa/glsa-200903-23.xml

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2013-2555

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2013-1379

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2013-1380

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2013-1378

Trust: 0.2

url:http://marc.info/?l=bugtraq&amp;m=139455789818399&amp;w=2

Trust: 0.1

url:https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2013-2555.html

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2013-1378.html

Trust: 0.1

url:https://access.redhat.com/security/team/contact/

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2013-1379.html

Trust: 0.1

url:https://access.redhat.com/security/team/key/#package

Trust: 0.1

url:https://access.redhat.com/security/updates/classification/#critical

Trust: 0.1

url:http://bugzilla.redhat.com/):

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2013-1380.html

Trust: 0.1

url:https://access.redhat.com/knowledge/articles/11258

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-4167

Trust: 0.1

url:http://h18013.www1.hp.com/products/servers/management/hpsim/download.html

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0650

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-4165

Trust: 0.1

url:http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-1371

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-4164

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-4168

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-1375

Trust: 0.1

url:http://h18013.www1.hp.com/products/servers/management/fpdownload.html

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-1535

Trust: 0.1

url:https://h20564.www2.hp.com/portal/site/hpsc/public/kb/

Trust: 0.1

url:https://h20564.www2.hp.com/portal/site/hpsc/public/kb/secbullarchive/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0646

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-4163

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0650

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-1379

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-5254

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-5257

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5265

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-3363

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-3347

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5277

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-5251

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5267

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-5324

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0648

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5257

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5264

Trust: 0.1

url:http://creativecommons.org/licenses/by-sa/2.5

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0630

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-3343

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-5256

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5249

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5280

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-5248

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5269

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5261

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5259

Trust: 0.1

url:http://security.gentoo.org/glsa/glsa-201309-06.xml

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-1374

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5260

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-3362

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5279

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5255

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-5250

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0646

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0647

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-1370

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-5260

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-5249

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5276

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-5253

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-5258

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-1367

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-1366

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-1372

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5271

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-5261

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0637

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5252

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-3344

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5278

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5274

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0634

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-5259

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5268

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5263

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5253

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5254

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0639

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0645

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-3345

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5256

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-1368

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0643

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5275

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5266

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-2555

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5262

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-1371

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0642

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-1365

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5258

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5251

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-1369

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-2728

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-1378

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0504

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5250

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0638

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5248

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5676

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5272

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5677

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0644

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-1380

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0633

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-3361

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-5255

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5678

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-1375

Trust: 0.1

url:http://security.gentoo.org/

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-5270

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0649

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-5252

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-1373

Trust: 0.1

url:https://bugs.gentoo.org.

Trust: 0.1

url:http://www.vupen.com/english/research.php

Trust: 0.1

url:http://www.vupen.com/english/services/ba-index.php

Trust: 0.1

url:http://www.vupen.com

Trust: 0.1

url:http://twitter.com/vupen

Trust: 0.1

url:http://www.vupen.com/english/services/tpp-index.php

Trust: 0.1

sources: ZDI: ZDI-13-288 // VULHUB: VHN-62557 // BID: 58396 // JVNDB: JVNDB-2013-001829 // PACKETSTORM: 121221 // PACKETSTORM: 125655 // PACKETSTORM: 123225 // PACKETSTORM: 121356 // CNNVD: CNNVD-201303-175 // NVD: CVE-2013-2555

CREDITS

VUPEN Security [ http://www.vupen.com ]

Trust: 0.7

sources: ZDI: ZDI-13-288

SOURCES

db:ZDIid:ZDI-13-288
db:VULHUBid:VHN-62557
db:BIDid:58396
db:JVNDBid:JVNDB-2013-001829
db:PACKETSTORMid:121221
db:PACKETSTORMid:125655
db:PACKETSTORMid:123225
db:PACKETSTORMid:121356
db:CNNVDid:CNNVD-201303-175
db:NVDid:CVE-2013-2555

LAST UPDATE DATE

2024-11-23T21:21:59.470000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-13-288date:2015-09-18T00:00:00
db:VULHUBid:VHN-62557date:2020-08-17T00:00:00
db:BIDid:58396date:2014-03-12T12:53:00
db:JVNDBid:JVNDB-2013-001829date:2013-10-24T00:00:00
db:CNNVDid:CNNVD-201303-175date:2022-07-01T00:00:00
db:NVDid:CVE-2013-2555date:2024-11-21T01:51:56.017

SOURCES RELEASE DATE

db:ZDIid:ZDI-13-288date:2015-09-18T00:00:00
db:VULHUBid:VHN-62557date:2013-03-11T00:00:00
db:BIDid:58396date:2013-03-08T00:00:00
db:JVNDBid:JVNDB-2013-001829date:2013-03-15T00:00:00
db:PACKETSTORMid:121221date:2013-04-11T01:40:40
db:PACKETSTORMid:125655date:2014-03-11T21:32:37
db:PACKETSTORMid:123225date:2013-09-14T15:19:13
db:PACKETSTORMid:121356date:2013-04-19T18:22:22
db:CNNVDid:CNNVD-201303-175date:2013-03-13T00:00:00
db:NVDid:CVE-2013-2555date:2013-03-11T10:55:01.117