CVE-2013-2555
published 2013-03-11CVE-2013-2555: Integer overflow in Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280…
PriorityP352critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
8.46%
94.4th percentile
Integer overflow in Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and before 11.1.115.54 on Android 4.x; Adobe AIR before 3.7.0.1530; and Adobe AIR SDK & Compiler before 3.7.0.1530 allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | <= 3.6.0.6090 | — |
| adobe | flash_player | < 10.3.183.75 | 10.3.183.75 |
| adobe | flash_player | <= 11.1.115.48 | — |
| adobe | flash_player | <= 11.1.111.44 | — |
| adobe | flash_player | <= 10.3.183.75 | — |
| adobe | flash_player | 11.0 – 11.6.602.180 | — |
| adobe | flash_player | 11.0 – 11.2.202.275 | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | linux_enterprise_desktop | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
flash-plugin: Remote attackers able to execute arbitrary code via vectors that leverage an 'overflow' (CanSecWest 2013)
vendor_redhat·2013-03-07·CVSS 10.0
CVE-2013-2555 [CRITICAL] flash-plugin: Remote attackers able to execute arbitrary code via vectors that leverage an 'overflow' (CanSecWest 2013)
flash-plugin: Remote attackers able to execute arbitrary code via vectors that leverage an 'overflow' (CanSecWest 2013)
Integer overflow in Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and before 11.1.115.54 on Android 4.x; Adobe AIR before 3.7.0.1530; and Adobe AIR SDK & Compiler before 3.7.0.1530 allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.
Statement: This issue affects the version of flash-plugin as shipped with Red Hat Enterprise Linux 5 and 6. Updates will be released as soon as they are made generally available by Adobe.
GHSA
GHSA-g22h-4p64-r22q: Integer overflow in Adobe Flash Player before 10
ghsa_unreviewed·2022-05-13
CVE-2013-2555 [HIGH] CWE-190 GHSA-g22h-4p64-r22q: Integer overflow in Adobe Flash Player before 10
Integer overflow in Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and before 11.1.115.54 on Android 4.x; Adobe AIR before 3.7.0.1530; and Adobe AIR SDK & Compiler before 3.7.0.1530 allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1378 CVE-2013-1379 CVE-2013-1380 flash-plugin: multiple code execution flaws (APSB13-11)
bugzilla·2013-04-09·CVSS 10.0
CVE-2013-1378 [CRITICAL] CVE-2013-1378 CVE-2013-1379 CVE-2013-1380 flash-plugin: multiple code execution flaws (APSB13-11)
CVE-2013-1378 CVE-2013-1379 CVE-2013-1380 flash-plugin: multiple code execution flaws (APSB13-11)
Adobe security bulletin APSB13-11 describes multiple security flaws that could cause Adobe Flash Player to crash and potentially allow an attacker to take control of the affected system:
These updates resolve an integer overflow vulnerability that could lead to code execution (CVE-2013-2555, tracked via bug #920186)
These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2013-1378, CVE-2013-1380).
These updates resolve a memory corruption vulnerability caused by Flash Player improperly initializing certain pointer arrays, which could lead to code execution (CVE-2013-1379).
External References:
http://www.adobe.com/support/security/bulletins/apsb13-
Bugzilla
CVE-2013-2555 flash-plugin: Remote attackers able to execute arbitrary code via vectors that leverage an 'overflow' (CanSecWest 2013)
bugzilla·2013-03-11·CVSS 10.0
CVE-2013-2555 [CRITICAL] CVE-2013-2555 flash-plugin: Remote attackers able to execute arbitrary code via vectors that leverage an 'overflow' (CanSecWest 2013)
CVE-2013-2555 flash-plugin: Remote attackers able to execute arbitrary code via vectors that leverage an 'overflow' (CanSecWest 2013)
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-2555 to the following vulnerability:
Adobe Flash Player 11.6.602.171 on Windows allows remote attackers to execute arbitrary code via vectors that leverage an "overflow," as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2555
[2] http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157
[3] http://twitter.com/VUPEN/statuses/309713355466227713
[4] http://twitter.com/thezdi/statuses/309756927301283840
Discussion:
Statement:
This issue affects the version of flash-plugin
http://archives.neohapsis.com/archives/bugtraq/2013-04/0197.htmlhttp://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-04/msg00019.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00081.htmlhttp://marc.info/?l=bugtraq&m=139455789818399&w=2http://rhn.redhat.com/errata/RHSA-2013-0730.htmlhttp://twitter.com/VUPEN/statuses/309713355466227713http://twitter.com/thezdi/statuses/309756927301283840http://www.adobe.com/support/security/bulletins/apsb13-11.htmlhttp://archives.neohapsis.com/archives/bugtraq/2013-04/0197.htmlhttp://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-04/msg00019.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00081.htmlhttp://marc.info/?l=bugtraq&m=139455789818399&w=2http://rhn.redhat.com/errata/RHSA-2013-0730.htmlhttp://twitter.com/VUPEN/statuses/309713355466227713http://twitter.com/thezdi/statuses/309756927301283840http://www.adobe.com/support/security/bulletins/apsb13-11.html
2013-03-11
Published