漏洞描述
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0559.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
code.google.comhttps://code.google.com/p/google-security-research/issues/detail?id=46↗www.securityfocus.comhttp://www.securityfocus.com/bid/69696↗lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00006.html↗security.gentoo.orghttp://security.gentoo.org/glsa/glsa-201409-05.xml↗exchange.xforce.ibmcloud.comhttps://exchange.xforce.ibmcloud.com/vulnerabilities/95826↗www.securitytracker.comhttp://www.securitytracker.com/id/1030822↗secunia.comhttp://secunia.com/advisories/61089↗helpx.adobe.comhttp://helpx.adobe.com/security/products/flash-player/apsb14-21.html↗lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00021.html↗packetstormsecurity.comhttp://packetstormsecurity.com/files/131516/Adobe-Flash-Player-copyPixelsToByteArray-Integer-Overflow.html↗www.osvdb.orghttp://www.osvdb.org/111110↗lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00016.html↗