Vulnerability CVE-2014-0497: Information

Description

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.

Severity: CRITICAL (10.0)

Published: Feb. 5, 2014
Modified: Dec. 13, 2018
Error type identifier: CWE-189

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
adobe-flash-playerp911-alt2532-alt1110ALT-PU-2014-1155-1113546Fixed
adobe-flash-playerc9f211-alt2532-alt117ALT-PU-2014-1155-1113546Fixed
adobe-flash-playerc711-alt2711-alt29ALT-PU-2014-1289-1116412Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
http://helpx.adobe.com/security/products/flash-player/apsb14-04.html
  • Patch
  • Vendor Advisory
RHSA-2014:0137
  • Third Party Advisory
openSUSE-SU-2014:0197
  • Mailing List
  • Third Party Advisory
SUSE-SU-2014:0221
  • Mailing List
  • Third Party Advisory
openSUSE-SU-2014:0203
  • Mailing List
  • Third Party Advisory
102849
  • Broken Link
33212
  • Third Party Advisory
  • VDB Entry
adobe-flash-cve20140497-code-exec(90884)
  • Third Party Advisory
  • VDB Entry
1029715
  • Third Party Advisory
  • VDB Entry
65327
  • Third Party Advisory
  • VDB Entry
56839
  • Third Party Advisory
56799
  • Third Party Advisory
56780
  • Third Party Advisory
56737
  • Third Party Advisory
56437
  • Third Party Advisory
http://googlechromereleases.blogspot.com/2014/02/stable-channel-update.html
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

      Configuration 2

      cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*

      cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*