CVE-2008-5363
Last modified
CVE-2008-5363 is a vulnerability of currently unknown severity. The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not validate character elements during retrieval from the dictionary data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF file.. EPSS estimates a 3.72% chance of exploitation in the next 30 days.
Description
The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not validate character elements during retrieval from the dictionary data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Air | < 1.5 |
| Adobe | Flash Player | >= 9.0.16.0, < 9.0.151.0 |
| Adobe | Flash Player | >= 10, < 10.0.12.36 |
References
- http://secunia.com/advisories/33390Third Party Advisory
- http://secunia.com/advisories/34226Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200903-23.xmlThird Party Advisory
- http://securityreason.com/securityalert/4692Third Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2009-020.htmThird Party Advisory
- http://www.adobe.com/support/security/bulletins/apsb08-22.htmlPatch, Vendor Advisory
- http://www.isecpartners.com/advisories/2008-01-flash.txtThird Party Advisory
- http://www.securityfocus.com/archive/1/498561/100/0/threadedThird Party Advisory, VDB Entry
- http://secunia.com/advisories/33390Third Party Advisory
- http://secunia.com/advisories/34226Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200903-23.xmlThird Party Advisory
- http://securityreason.com/securityalert/4692Third Party Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2009-020.htmThird Party Advisory
- http://www.adobe.com/support/security/bulletins/apsb08-22.htmlPatch, Vendor Advisory
- http://www.isecpartners.com/advisories/2008-01-flash.txtThird Party Advisory
- http://www.securityfocus.com/archive/1/498561/100/0/threadedThird Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-5363?
How severe is CVE-2008-5363?
How do I fix CVE-2008-5363?
Are you affected by CVE-2008-5363?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
