FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2011-0611

This CVE name corresponds to:

Entered Topic
2011-04-17 linux-flashplugin -- remote code execution vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2011-0611
Phase Assigned(20110120)

Description

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.

References

Source Reference
EXPLOIT-DB 17175
MISC http://bugix-security.blogspot.com/2011/04/cve-2011-0611-adobe-flash-zero-day.html
MISC http://secunia.com/blog/210/
MISC http://blogs.technet.com/b/mmpc/archive/2011/04/12/analysis-of-the-cve-2011-0611-adobe-flash-player-vulnerability-exploitation.aspx
MISC http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611-flash-player-zero.html
CONFIRM http://www.adobe.com/support/security/advisories/apsa11-02.html
CONFIRM http://googlechromereleases.blogspot.com/2011/04/stable-channel-update.html
CONFIRM http://www.adobe.com/support/security/bulletins/apsb11-07.html
CONFIRM http://www.adobe.com/support/security/bulletins/apsb11-08.html
REDHAT RHSA-2011:0451
SUSE SUSE-SA:2011:018
CERT-VN VU#230057
BID 47314
OVAL oval:org.mitre.oval:def:14175
SECTRACK 1025324
SECTRACK 1025325
SECUNIA 44141
SECUNIA 44149
SECUNIA 44119
SREASON 8204
SREASON 8292
VUPEN ADV-2011-0922
VUPEN ADV-2011-0923
VUPEN ADV-2011-0924
XF adobe-flash-swf-doc-ce(66681)