HTTP: Adobe Flash Player OP_inclocal and OP_declocal Memory Corruption

This signature detects attempts to exploit a known flaw in Adobe Flash Player. A remote, unauthenticated attacker could exploit this vulnerability by enticing a target user to open a Flash file with an affected version of Adobe Flash Player. Successful exploitation would result in execution of arbitrary code in the security context of the affected application.

Extended Description

Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than other Flash Player memory corruption CVEs listed in APSB12-22.

Affected Products

Adobe adobe_air_sdk

References

CVE: CVE-2012-5271

Short Name
HTTP:STC:ADOBE:FLASH-OP
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Adobe CVE-2012-5271 Corruption Flash Memory OP_declocal OP_inclocal Player and
Release Date
10/25/2012
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
Vendors

Adobe

CVSS Score

10.0

Found a potential security threat?