MEDIUM · 4.3

CVE-2008-5362

The DefineConstantPool action in the ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, accepts an untrusted input value fo...

Vulnerability Description

The DefineConstantPool action in the ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, accepts an untrusted input value for a "constant count," which allows remote attackers to read sensitive data from process memory via a crafted PDF file.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
AdobeAir< 1.5
AdobeFlash Player>= 9.0.16.0, < 9.0.151.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-5362?

CVE-2008-5362 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The DefineConstantPool action in the ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, accepts an untrusted input value fo...

How severe is CVE-2008-5362?

CVE-2008-5362 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-5362?

Check the references section above for vendor advisories and patch information. Affected products include: Adobe Air, Adobe Flash Player.