Vulnerability Description
Buffer overflow in Adobe Flash Player 8.0.24.0 and earlier, Flash Professional 8, Flash MX 2004, and Flex 1.5 allows user-assisted remote attackers to execute arbitrary code via a long, dynamically created string in a SWF movie.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Flash Player | <= 8.0.24.0 |
| Adobe | Flex Sdk | 1.5 |
References
- http://lists.apple.com/archives/security-announce/2006/Sep/msg00002.html
- http://secunia.com/advisories/21865PatchVendor Advisory
- http://secunia.com/advisories/21901
- http://secunia.com/advisories/22054
- http://secunia.com/advisories/22187
- http://secunia.com/advisories/22268
- http://secunia.com/advisories/22882
- http://security.gentoo.org/glsa/glsa-200610-02.xml
- http://securityreason.com/securityalert/1546
- http://securitytracker.com/id?1016829
- http://www.adobe.com/support/security/bulletins/apsb06-11.htmlPatch
- http://www.computerterrorism.com/research/ct12-09-2006.htmExploitPatchVendor Advisory
- http://www.kb.cert.org/vuls/id/451380US Government Resource
- http://www.novell.com/linux/security/advisories/2006_53_flashplayer.html
- http://www.redhat.com/support/errata/RHSA-2006-0674.html
FAQ
What is CVE-2006-3311?
CVE-2006-3311 is a vulnerability with a CVSS score of 5.1 (MEDIUM). Buffer overflow in Adobe Flash Player 8.0.24.0 and earlier, Flash Professional 8, Flash MX 2004, and Flex 1.5 allows user-assisted remote attackers to execute arbitrary code via a long, dynamically cr...
How severe is CVE-2006-3311?
CVE-2006-3311 has been rated MEDIUM with a CVSS base score of 5.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-3311?
Check the references section above for vendor advisories and patch information. Affected products include: Adobe Flash Player, Adobe Flex Sdk.