Information disclosure in Adobe Flash Player - CVE-2011-0579

 

Information disclosure in Adobe Flash Player - CVE-2011-0579

Published: December 27, 2016 / Updated: January 9, 2017


Vulnerability identifier: #VU2855
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-0579
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The weakness exists due to design flaw. A remote attacker can create a specially crafted Web site, trick the victim into visiting it and gain access to important data.

Successful exploitation of the vulnerability results in information disclosure on the vulnerable system.

Affected software

Adobe Flash Player
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation

How to mitigate CVE-2011-0579

Update Adobe Flash Player 10.x for Windows, Macintosh, Linux and Solaris to 10.3.181.14.
http://www.adobe.com/go/getflash
http://www.adobe.com/licensing/distribution
http://googlechromereleases.blogspot.com/2011/04/stable-channel-update.html
http://www.adobe.com/support/flashplayer/downloads.html#fp10
Update Adobe Flash Player 10.x for Android to 10.3.185.21.
market://details?id=com.adobe.flashplayer


External References

Related Security Bulletins