CVE-2012-5054

Publication date 24 September 2012

Last updated 21 August 2024


Ubuntu priority

Cvss 3 Severity Score

8.8 · High

Score breakdown

Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments.

Read the notes from the security team

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
flashplugin-nonfree 12.04 LTS precise
Fixed 11.2.202.238ubuntu0.12.04.1
11.10 oneiric
Fixed 11.2.202.238ubuntu0.11.10.1
11.04 natty
Fixed 11.2.202.238ubuntu0.11.04.1
10.04 LTS lucid
Fixed 11.2.202.238ubuntu0.10.04.1
8.04 LTS hardy Ignored end of life

Notes


seth-arnold

“Users of Adobe Flash Player 11.2.202.236 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.238.” 11.3 and higher are for Windows and Mac OS X only.

Severity score breakdown

Parameter Value
Base score 8.8 · High
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H