CVE-2013-0634
Published · Updated
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 78%
from disclosure to weapon437 days
Published on NVDFeb 8
1st PoC+437d
metasploitFeb 8
VulnCheckFeb 8
exploitation probability
78%top 1% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Fixed
4 products
Red Hat Enterprise Linux Desktop Supplementary (v. 6) · Red Hat Enterprise Linux Server Supplementary (v. 5) · Red Hat Enterprise Linux Server Supplementary (v. 6) · Red Hat Enterprise Linux Workstation Supplementary (v. 6)
Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before 11.2.202.262 on Linux, before 11.1.111.32 on Android 2.x and 3.x, and before 11.1.115.37 on Android 4.x allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, as exploited in the wild in February 2013.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/32959⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-02/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-02/msg00007.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0243.htmlhttp://www.adobe.com/support/security/bulletins/apsb13-04.html