Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted SWF content, as exploited in the wild in August 2012 with SWF content in a Word document.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.adobe.com/support/security/bulletins/apsb12-18.html | patch vendor advisory not applicable |
http://rhn.redhat.com/errata/RHSA-2012-1203.html | third party advisory vendor advisory |
http://security.gentoo.org/glsa/glsa-201209-01.xml | third party advisory vendor advisory |
http://marc.info/?l=bugtraq&m=139455789818399&w=2 | vendor advisory mailing list |
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00012.html | vendor advisory mailing list third party advisory |
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00010.html | vendor advisory mailing list third party advisory |