CVE-2011-0611

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.
References
Link Resource
http://blogs.technet.com/b/mmpc/archive/2011/04/12/analysis-of-the-cve-2011-0611-adobe-flash-player-vulnerability-exploitation.aspx Not Applicable
http://bugix-security.blogspot.com/2011/04/cve-2011-0611-adobe-flash-zero-day.html Exploit
http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611-flash-player-zero.html Exploit Issue Tracking
http://googlechromereleases.blogspot.com/2011/04/stable-channel-update.html Release Notes
http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00004.html Mailing List Patch
http://secunia.com/advisories/44119 Broken Link Vendor Advisory
http://secunia.com/advisories/44141 Broken Link Vendor Advisory
http://secunia.com/advisories/44149 Broken Link Vendor Advisory
http://secunia.com/blog/210/ Broken Link Vendor Advisory
http://securityreason.com/securityalert/8204 Third Party Advisory
http://securityreason.com/securityalert/8292 Third Party Advisory
http://www.adobe.com/support/security/advisories/apsa11-02.html Broken Link Vendor Advisory
http://www.adobe.com/support/security/bulletins/apsb11-07.html Broken Link Vendor Advisory
http://www.adobe.com/support/security/bulletins/apsb11-08.html Broken Link Vendor Advisory
http://www.exploit-db.com/exploits/17175 Exploit Third Party Advisory VDB Entry
http://www.kb.cert.org/vuls/id/230057 Broken Link Third Party Advisory US Government Resource
http://www.redhat.com/support/errata/RHSA-2011-0451.html Broken Link Vendor Advisory
http://www.securityfocus.com/bid/47314 Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1025324 Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1025325 Broken Link Third Party Advisory VDB Entry
http://www.vupen.com/english/advisories/2011/0922 Broken Link Vendor Advisory
http://www.vupen.com/english/advisories/2011/0923 Broken Link Vendor Advisory
http://www.vupen.com/english/advisories/2011/0924 Broken Link Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/66681 Third Party Advisory VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14175 Broken Link
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:a:adobe:adobe_air:*:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
OR cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
OR cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*
cpe:2.3:o:google:chrome_os:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 8 (hide)

OR cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:10:sp4:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:11:sp1:*:*:*:*:*:*

History

No history.

Information

Published : 2011-04-13 14:55

Updated : 2024-08-13 18:58


NVD link : CVE-2011-0611

Mitre link : CVE-2011-0611

CVE.ORG link : CVE-2011-0611


JSON object : View

Products Affected

microsoft

  • windows

adobe

  • acrobat_reader
  • adobe_air
  • acrobat
  • flash_player

google

  • chrome_os
  • chrome
  • android

opensuse

  • opensuse

linux

  • linux_kernel

apple

  • mac_os_x

oracle

  • solaris

suse

  • linux_enterprise_desktop
CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')