CVE-2011-0611

Publication date 13 April 2011

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

8.8 · High

Score breakdown

Description

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a “group of included constants,” object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.

Read the notes from the security team

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
adobeair 11.04 natty
Fixed 1:2.6.0.19140-0natty1
10.10 maverick
Fixed 1:2.6.0.19140-0maverick1
10.04 LTS lucid
Fixed 1:2.6.0.19140-0lucid1
8.04 LTS hardy Ignored end of life
6.06 LTS dapper Not in release
acroread 11.04 natty
Not affected
10.10 maverick
Not affected
10.04 LTS lucid
Not affected
9.10 karmic
Not affected
8.04 LTS hardy
Not affected
6.06 LTS dapper Ignored
adobe-flashplugin 11.04 natty
Fixed 10.2.159.1-0natty1
10.10 maverick
Fixed 10.2.159.1-0maverick1
10.04 LTS lucid
Fixed 10.2.159.1-0lucid1
9.10 karmic
Fixed 10.2.159.1-0karmic1
8.04 LTS hardy
Fixed 10.2.159.1-0hardy1
6.06 LTS dapper Not in release
flashplugin-nonfree 11.04 natty
Fixed 10.2.159.1ubuntu1
10.10 maverick
Fixed 10.2.159.1ubuntu0.10.10.1
10.04 LTS lucid
Fixed 10.2.159.1ubuntu0.10.04.1
9.10 karmic
Fixed 10.2.159.1ubuntu0.9.10.1
8.04 LTS hardy
Fixed 10.2.159.1ubuntu0.8.04.1
6.06 LTS dapper Ignored end of life

Notes


mdeslaur

adobe reader for Unix isn’t affected

Severity score breakdown

Parameter Value
Base score 8.8 · High
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H