CVE-2013-0643
Summary
The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, which makes it easier for remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.
Impact & exploitability
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products we track (1)
Recommendation
This vulnerability is being actively exploited in the wild — patch affected products urgently. Open any affected product above for its exact safe version.
Official patch: http://www.adobe.com/support/security/bulletins/apsb13-08.html ↗
Additional information
- NVD record
- http://www.adobe.com/support/security/bulletins/apsb13-08.htmlPatch
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00026.html
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00035.html
- http://rhn.redhat.com/errata/RHSA-2013-0574.htmlAdvisory