CVE-2010-3654 Information

Share on:

Description

Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows Mac OS X Linux and Solaris and 10.1.95.1 on Android and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted SWF content as exploited in the wild in October 2010.

Reference

http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_adobe_flash1 http://contagiodump.blogspot.com/2010/10/potential-new-adobe-flash-player-zero.html http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00002.html http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00001.html http://secunia.com/advisories/41917 http://secunia.com/advisories/42030 http://secunia.com/advisories/42183 http://secunia.com/advisories/42401 http://secunia.com/advisories/42926 http://secunia.com/advisories/43025 http://secunia.com/advisories/43026 http://security.gentoo.org/glsa/glsa-201101-08.xml http://security.gentoo.org/glsa/glsa-201101-09.xml http://securityreason.com/securityalert/8210 http://support.apple.com/kb/HT4435 http://www.adobe.com/support/security/advisories/apsa10-05.html http://www.adobe.com/support/security/bulletins/apsb10-26.html http://www.adobe.com/support/security/bulletins/apsb10-28.html http://www.kb.cert.org/vuls/id/298081 http://www.redhat.com/support/errata/RHSA-2010-0829.html http://www.redhat.com/support/errata/RHSA-2010-0834.html http://www.redhat.com/support/errata/RHSA-2010-0867.html http://www.redhat.com/support/errata/RHSA-2010-0934.html http://www.securityfocus.com/bid/44504 http://www.securitytracker.com/id?1024659 http://www.securitytracker.com/id?1024660 http://www.turbolinux.co.jp/security/2011/TLSA-2011-2j.txt http://www.vupen.com/english/advisories/2010/2903 http://www.vupen.com/english/advisories/2010/2906 http://www.vupen.com/english/advisories/2010/2918 http://www.vupen.com/english/advisories/2010/3111 http://www.vupen.com/english/advisories/2011/0173 http://www.vupen.com/english/advisories/2011/0191 http://www.vupen.com/english/advisories/2011/0192 http://www.vupen.com/english/advisories/2011/0344 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A13294