Vulnerability Description
The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not validate character elements during retrieval from the dictionary data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Air | < 1.5 |
| Adobe | Flash Player | >= 9.0.16.0, < 9.0.151.0 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/33390Third Party Advisory
- http://secunia.com/advisories/34226Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200903-23.xmlThird Party Advisory
- http://securityreason.com/securityalert/4692Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1Broken Link
- http://support.avaya.com/elmodocs2/security/ASA-2009-020.htmThird Party Advisory
- http://www.adobe.com/support/security/bulletins/apsb08-22.htmlPatchVendor Advisory
- http://www.isecpartners.com/advisories/2008-01-flash.txtThird Party Advisory
- http://www.securityfocus.com/archive/1/498561/100/0/threadedThird Party AdvisoryVDB Entry
- http://secunia.com/advisories/33390Third Party Advisory
- http://secunia.com/advisories/34226Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200903-23.xmlThird Party Advisory
- http://securityreason.com/securityalert/4692Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-248586-1Broken Link
- http://support.avaya.com/elmodocs2/security/ASA-2009-020.htmThird Party Advisory
FAQ
What is CVE-2008-5363?
CVE-2008-5363 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not validate character elements during retrieval from the dicti...
How severe is CVE-2008-5363?
CVE-2008-5363 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-5363?
Check the references section above for vendor advisories and patch information. Affected products include: Adobe Air, Adobe Flash Player.