CVE-2014-0557
published 2014-09-10CVE-2014-0557: Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on…
PriorityP342critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.07%
91.4th percentile
Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors.
Affected
53 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_air | <= 14.0.0.178 | — |
| adobe | adobe_air | <= 14.0.0.179 | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air | — | — |
| adobe | adobe_air_sdk | <= 14.0.0.178 | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | adobe_air_sdk | — | — |
| adobe | flash_player | <= 11.2.202.400 | — |
| adobe | flash_player | <= 13.0.0.241 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jwr6-x473-7g7f: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17
CVE-2014-0557 [HIGH] GHSA-jwr6-x473-7g7f: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors.
OSV
CVE-2014-0557: Adobe Flash Player before 13
osv·2014-09-10·CVSS 10.0
CVE-2014-0557 [CRITICAL] CVE-2014-0557: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors.
Red Hat
flash-plugin: multiple code execution or security bypass flaws (APSB14-21)
vendor_redhat·2014-09-09·CVSS 10.0
CVE-2014-0557 [CRITICAL] flash-plugin: multiple code execution or security bypass flaws (APSB14-21)
flash-plugin: multiple code execution or security bypass flaws (APSB14-21)
Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0547 CVE-2014-0549 CVE-2014-0550 CVE-2014-0551 CVE-2014-0552 CVE-2014-0553 CVE-2014-0554 CVE-2014-0555 CVE-2014-0556 CVE-2014-0557 CVE-2014-0559 flash-plugin: multiple code execution or secur
bugzilla·2014-09-09·CVSS 10.0
CVE-2014-0547 [CRITICAL] CVE-2014-0547 CVE-2014-0549 CVE-2014-0550 CVE-2014-0551 CVE-2014-0552 CVE-2014-0553 CVE-2014-0554 CVE-2014-0555 CVE-2014-0556 CVE-2014-0557 CVE-2014-0559 flash-plugin: multiple code execution or secur
CVE-2014-0547 CVE-2014-0549 CVE-2014-0550 CVE-2014-0551 CVE-2014-0552 CVE-2014-0553 CVE-2014-0554 CVE-2014-0555 CVE-2014-0556 CVE-2014-0557 CVE-2014-0559 flash-plugin: multiple code execution or security bypass flaws (APSB14-21)
Adobe has released Flash Player 11.2.202.406 for Linux to correct the following flaws:
* These updates resolve memory leakage vulnerabilities that could be used to bypass memory address randomization (CVE-2014-0557).
* These updates resolve a security bypass vulnerability (CVE-2014-0554).
* These updates resolve a use-after-free vulnerability that could lead to code execution (CVE-2014-0553).
* These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2014-0547, CVE-2014-0549, CVE-2014-0550, CVE-2014-0551, CVE-2014-0552, CV
Bugzilla
CVE-2014-2672 kernel: ath9k: tid->sched race in ath_tx_aggr_sleep()
bugzilla·2014-04-01·CVSS 7.1
CVE-2014-2672 [HIGH] CVE-2014-2672 kernel: ath9k: tid->sched race in ath_tx_aggr_sleep()
CVE-2014-2672 kernel: ath9k: tid->sched race in ath_tx_aggr_sleep()
We check tid->sched without a lock taken on ath_tx_aggr_sleep(). That is race condition which can result of doing list_del(&tid->list) twice (second time with poisoned list node) and causing a crash.
Upstream fixes:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=21f8aaee0c62708654988ce092838aa7df4d25d8
References:
http://seclists.org/oss-sec/2014/q1/701
Discussion:
Statement:
This issued does not affect Red Hat Enterprise Linux 5 because we do not provide support for Atheros 9k wireless network adapters.
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1083253]
---
This issue has been addressed in following products:
MRG for RHEL-6 v.2
Via RHSA-2014:0557 http
http://helpx.adobe.com/security/products/flash-player/apsb14-21.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00021.htmlhttp://secunia.com/advisories/61089http://security.gentoo.org/glsa/glsa-201409-05.xmlhttp://www.securityfocus.com/bid/69701http://www.securitytracker.com/id/1030822https://exchange.xforce.ibmcloud.com/vulnerabilities/95827http://helpx.adobe.com/security/products/flash-player/apsb14-21.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00021.htmlhttp://secunia.com/advisories/61089http://security.gentoo.org/glsa/glsa-201409-05.xmlhttp://www.securityfocus.com/bid/69701http://www.securitytracker.com/id/1030822https://exchange.xforce.ibmcloud.com/vulnerabilities/95827
2014-09-10
Published