CVE-2013-0644
published 2013-02-12CVE-2013-0644: Use-after-free vulnerability in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167…
PriorityP348critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
8.53%
94.4th percentile
Use-after-free vulnerability in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x; Adobe AIR before 3.6.0.597; and Adobe AIR SDK before 3.6.0.599 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0649 and CVE-2013-1374.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | < 3.6.0.597 | 3.6.0.597 |
| adobe | air_sdk | < 3.6.0.599 | 3.6.0.599 |
| adobe | flash_player | >= 10.3 < 10.3.183.63 | 10.3.183.63 |
| adobe | flash_player | >= 10.3 < 10.3.183.61 | 10.3.183.61 |
| adobe | flash_player | >= 11.1 < 11.1.111.43 | 11.1.111.43 |
| adobe | flash_player | >= 11.1 < 11.1.115.47 | 11.1.115.47 |
| adobe | flash_player | >= 11.2 < 11.2.202.270 | 11.2.202.270 |
| adobe | flash_player | >= 11.6 < 11.6.602.168 | 11.6.602.168 |
| adobe | flash_player | >= 11.6 < 11.6.602.167 | 11.6.602.167 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g6vv-rc89-v594: Use-after-free vulnerability in Adobe Flash Player before 10
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2013-1374 [CRITICAL] GHSA-g6vv-rc89-v594: Use-after-free vulnerability in Adobe Flash Player before 10
Use-after-free vulnerability in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x; Adobe AIR before 3.6.0.597; and Adobe AIR SDK before 3.6.0.599 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0644 and CVE-2013-0649.
GHSA
GHSA-pj67-8xmg-x946: Use-after-free vulnerability in Adobe Flash Player before 10
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2013-0644 [CRITICAL] GHSA-pj67-8xmg-x946: Use-after-free vulnerability in Adobe Flash Player before 10
Use-after-free vulnerability in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x; Adobe AIR before 3.6.0.597; and Adobe AIR SDK before 3.6.0.599 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0649 and CVE-2013-1374.
GHSA
GHSA-5gj6-6vg2-2m8v: Use-after-free vulnerability in Adobe Flash Player before 10
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2013-0649 [CRITICAL] GHSA-5gj6-6vg2-2m8v: Use-after-free vulnerability in Adobe Flash Player before 10
Use-after-free vulnerability in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x; Adobe AIR before 3.6.0.597; and Adobe AIR SDK before 3.6.0.599 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0644 and CVE-2013-1374.
Red Hat
redis: world-readable ~/.rediscli_history
vendor_redhat·2016-07-28·CVSS 3.3
CVE-2013-7458 [LOW] CWE-732 redis: world-readable ~/.rediscli_history
redis: world-readable ~/.rediscli_history
linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, which allows local users to obtain sensitive information by reading the file.
A permissions flaw was found in Redis, where redis-cli stores its history in ~/.rediscli_history. The file is created with permissions 0644, which could lead to the exposure of sensitive data for users with world-readable home directories.
Statement: Red Hat Product Security has rated this issue as having security impact of Low.
Further, home directories are not world readable on RHEL distributions (by default). This issue is not currently planned to be addressed in future
updates. For additional information, refer to the Issue Severity
Classification: https://access.redhat
Red Hat
flash-plugin: multiple code execution flaws (APSB13-05)
vendor_redhat·2013-02-12·CVSS 10.0
CVE-2013-1374 [CRITICAL] flash-plugin: multiple code execution flaws (APSB13-05)
flash-plugin: multiple code execution flaws (APSB13-05)
Use-after-free vulnerability in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x; Adobe AIR before 3.6.0.597; and Adobe AIR SDK before 3.6.0.599 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0644 and CVE-2013-0649.
Red Hat
flash-plugin: multiple code execution flaws (APSB13-05)
vendor_redhat·2013-02-12·CVSS 10.0
CVE-2013-0644 [CRITICAL] flash-plugin: multiple code execution flaws (APSB13-05)
flash-plugin: multiple code execution flaws (APSB13-05)
Use-after-free vulnerability in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x; Adobe AIR before 3.6.0.597; and Adobe AIR SDK before 3.6.0.599 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0649 and CVE-2013-1374.
Red Hat
flash-plugin: multiple code execution flaws (APSB13-05)
vendor_redhat·2013-02-12·CVSS 10.0
CVE-2013-0649 [CRITICAL] flash-plugin: multiple code execution flaws (APSB13-05)
flash-plugin: multiple code execution flaws (APSB13-05)
Use-after-free vulnerability in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x; Adobe AIR before 3.6.0.597; and Adobe AIR SDK before 3.6.0.599 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0644 and CVE-2013-1374.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-7458 redis: world-readable ~/.rediscli_history
bugzilla·2016-08-03·CVSS 3.3
CVE-2013-7458 [LOW] CVE-2013-7458 redis: world-readable ~/.rediscli_history
CVE-2013-7458 redis: world-readable ~/.rediscli_history
redis-cli stores its history in ~/.rediscli_history, this file is created with permissions 0644, which could lead to exposure of sensitive data if for users with world readable home directories.
CVE request:
http://seclists.org/oss-sec/2016/q3/180
Upstream issue:
https://github.com/antirez/redis/issues/3284
Discussion:
Created redis tracking bugs for this issue:
Affects: fedora-all [bug 1363671]
Affects: epel-all [bug 1363672]
---
Fixed upstream in Redis 3.2.3 Released Tue Aug 02 10:55:24 CEST 2016
http://download.redis.io/redis-stable/00-RELEASENOTES
Redis-cli created the history file with insecure permissions, allowing reading from the file. This was actually a bug in linenoise which is now fixed. The applied fix is from
Bugzilla
flash-plugin: multiple code execution flaws (APSB13-05)
bugzilla·2013-02-12·CVSS 10.0
CVE-2013-1372 [CRITICAL] flash-plugin: multiple code execution flaws (APSB13-05)
flash-plugin: multiple code execution flaws (APSB13-05)
Adobe security bulletin APSB13-05 describes multiple security flaws that could cause Adobe Flash Player to crash and potentially allow an attacker to take control of the affected system:
This update resolves buffer overflow vulnerabilities that could lead to code execution (CVE-2013-1372, CVE-2013-0645, CVE-2013-1373, CVE-2013-1369, CVE-2013-1370, CVE-2013-1366, CVE-2013-1365, CVE-2013-1368, CVE-2013-0642, CVE-2013-1367).
This update resolves use-after-free vulnerabilities that could lead to code execution (CVE-2013-0649, CVE-2013-1374, CVE-2013-0644).
This update resolves an integer overflow vulnerability that could lead to code execution (CVE-2013-0639).
This update resolves memory corruption vulnerabilities that could lead to
Bugzilla
CVE-2013-0266 OpenStack packstack: puppetlabs-cinder / manifests / base.pp weak file permissions
bugzilla·2013-02-07·CVSS 2.1
CVE-2013-0266 [LOW] CVE-2013-0266 OpenStack packstack: puppetlabs-cinder / manifests / base.pp weak file permissions
CVE-2013-0266 OpenStack packstack: puppetlabs-cinder / manifests / base.pp weak file permissions
Derek Higgins ([email protected]) reports:
puppetlabs-cinder / manifests / base.pp as used in OpenStack packstack uses
unsafe file permissions (mode 0644) for various config files (cinder.conf and
api-paste.ini) which can result in authorization credentials being exposed to
local attackers.
External references:
https://github.com/puppetlabs/puppetlabs-cinder/blob/master/manifests/base.pp#L31
mode => '0644',
Discussion:
Fix for this issue:
https://github.com/puppetlabs/puppetlabs-cinder/commit/7da792fbd40c0e6eae1ee093aa00e0b177bd2ebc
---
This covers cinder.conf but I think api-paste.ini should also be included. It contains the cinder auth credentials for keystone.
---
Acknowledgements:
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-02/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-02/msg00011.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0254.htmlhttp://www.adobe.com/support/security/bulletins/apsb13-05.htmlhttp://www.us-cert.gov/cas/techalerts/TA13-043A.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-02/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-02/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-02/msg00011.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0254.htmlhttp://www.adobe.com/support/security/bulletins/apsb13-05.htmlhttp://www.us-cert.gov/cas/techalerts/TA13-043A.html
2013-02-12
Published