CVE-2012-5677
Adobe Flash Player loadPCMFromByteArray Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Integer overflow in Adobe Flash Player before 10.3.183.48 and 11.x before 11.5.502.135 on Windows, before 10.3.183.48 and 11.x before 11.5.502.136 on Mac OS X, before 10.3.183.48 and 11.x before 11.2.202.258 on Linux, before 11.1.111.29 on Android 2.x and 3.x, and before 11.1.115.34 on Android 4.x; Adobe AIR before 3.5.0.880 on Windows and before 3.5.0.890 on Mac OS X; and Adobe AIR SDK before 3.5.0.880 on Windows and before 3.5.0.890 on Mac OS X allows attackers to execute arbitrary code via unspecified vectors.
Desbordamiento de entero en Adobe Flash Player antes de v10.3.183.48 y v11.x antes de v11.5.502.135 en Windows, antes de v10.3.183.48 y v11.x antes de v11.5.502.136 en Mac OS X, antes de v10.3.183.48 y v11.x antes de v11.2.202.258 en Linux, antes de v11.1.111.29 en Android v2.x y v3.x, y antes de v11.1.115.34 en Android v4.x; Adobe AIR antes de v3.5.0.880 en Windows y antes de v3.5.0.890 en Mac OS X; y Adobe AIR SDK antes de v3.5.0.880 en Windows y antes de v3.5.0.890 en Mac OS X permite a atacantes remotos ejecutar código de su elección a través de vectores no especificados.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Flash Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the loadPCMFromByteArray function in the flash.media.Sound object. When this function is called with a high number of 'samples' an integer overflow occurs during the calculation of a buffer size. This can lead to memory corruption that can result in remote code execution under the context of the current user.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-10-29 CVE Reserved
- 2012-12-12 CVE Published
- 2024-08-06 CVE Updated
- 2024-11-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-189: Numeric Errors
CAPEC
References (5)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.adobe.com/support/security/bulletins/apsb12-27.html | 2018-12-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | >= 10.3 < 10.3.183.48 Search vendor "Adobe" for product "Flash Player" and version " >= 10.3 < 10.3.183.48" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | >= 11.5 < 11.5.502.135 Search vendor "Adobe" for product "Flash Player" and version " >= 11.5 < 11.5.502.135" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | >= 10.3 < 10.3.183.48 Search vendor "Adobe" for product "Flash Player" and version " >= 10.3 < 10.3.183.48" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | >= 11.2 < 11.2.202.258 Search vendor "Adobe" for product "Flash Player" and version " >= 11.2 < 11.2.202.258" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | >= 11.1 < 11.1.111.29 Search vendor "Adobe" for product "Flash Player" and version " >= 11.1 < 11.1.111.29" | - |
Affected
| in | Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | >= 2.0 <= 2.3.7 Search vendor "Google" for product "Android" and version " >= 2.0 <= 2.3.7" | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | >= 11.1 < 11.1.111.29 Search vendor "Adobe" for product "Flash Player" and version " >= 11.1 < 11.1.111.29" | - |
Affected
| in | Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | >= 3.0 <= 3.2.6 Search vendor "Google" for product "Android" and version " >= 3.0 <= 3.2.6" | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | >= 11.1 < 11.1.115.34 Search vendor "Adobe" for product "Flash Player" and version " >= 11.1 < 11.1.115.34" | - |
Affected
| in | Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | >= 4.0 <= 4.4.4 Search vendor "Google" for product "Android" and version " >= 4.0 <= 4.4.4" | - |
Safe
|
Adobe Search vendor "Adobe" | Air Search vendor "Adobe" for product "Air" | < 3.5.0.880 Search vendor "Adobe" for product "Air" and version " < 3.5.0.880" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | >= 10.3 < 10.3.183.48 Search vendor "Adobe" for product "Flash Player" and version " >= 10.3 < 10.3.183.48" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Flash Player Search vendor "Adobe" for product "Flash Player" | >= 11.5 < 11.5.502.136 Search vendor "Adobe" for product "Flash Player" and version " >= 11.5 < 11.5.502.136" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Air Search vendor "Adobe" for product "Air" | < 3.5.0.890 Search vendor "Adobe" for product "Air" and version " < 3.5.0.890" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Air Sdk Search vendor "Adobe" for product "Air Sdk" | < 3.5.0.880 Search vendor "Adobe" for product "Air Sdk" and version " < 3.5.0.880" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Adobe Search vendor "Adobe" | Air Sdk Search vendor "Adobe" for product "Air Sdk" | < 3.5.0.890 Search vendor "Adobe" for product "Air Sdk" and version " < 3.5.0.890" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | - | - |
Safe
|