Lucene search

K
ubuntucveUbuntu.comUB:CVE-2011-0611
HistoryApr 13, 2011 - 12:00 a.m.

CVE-2011-0611

2011-04-1300:00:00
ubuntu.com
ubuntu.com
12

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.961

Percentile

99.5%

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and
Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140;
and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4
and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x
before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x
before 10.0.3 on Windows and Mac OS X allow remote attackers to execute
arbitrary code or cause a denial of service (application crash) via crafted
Flash content; as demonstrated by a Microsoft Office document with an
embedded .swf file that has a size inconsistency in a β€œgroup of included
constants,” object type confusion, ActionScript that adds custom functions
to prototypes, and Date objects; and as exploited in the wild in April
2011.

Notes

Author Note
mdeslaur adobe reader for Unix isn’t affected
OSVersionArchitecturePackageVersionFilename
ubuntu8.04noarchadobe-flashplugin<Β 10.2.159.1-0hardy1UNKNOWN
ubuntu9.10noarchadobe-flashplugin<Β 10.2.159.1-0karmic1UNKNOWN
ubuntu10.04noarchadobe-flashplugin<Β 10.2.159.1-0lucid1UNKNOWN
ubuntu10.10noarchadobe-flashplugin<Β 10.2.159.1-0maverick1UNKNOWN
ubuntu11.04noarchadobe-flashplugin<Β 10.2.159.1-0natty1UNKNOWN
ubuntu10.04noarchadobeair<Β 1:2.6.0.19140-0lucid1UNKNOWN
ubuntu10.10noarchadobeair<Β 1:2.6.0.19140-0maverick1UNKNOWN
ubuntu11.04noarchadobeair<Β 1:2.6.0.19140-0natty1UNKNOWN
ubuntu8.04noarchflashplugin-nonfree<Β 10.2.159.1ubuntu0.8.04.1UNKNOWN
ubuntu9.10noarchflashplugin-nonfree<Β 10.2.159.1ubuntu0.9.10.1UNKNOWN
Rows per page:
1-10 of 131

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.961

Percentile

99.5%