---
title: "CVE-2013-1366\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2013-1366?format=md
keywords: index, follow
---

# CVE-2013-1366

Publication date 12 February 2013

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Buffer overflow in Adobe Flash Player before 10.3.183.63 and 11.x before
11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on
Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before
11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x;
Adobe AIR before 3.6.0.597; and Adobe AIR SDK before 3.6.0.599 allows
attackers to execute arbitrary code via unspecified vectors, a different
vulnerability than CVE-2013-0642, CVE-2013-0645, CVE-2013-1365,
CVE-2013-1367, CVE-2013-1368, CVE-2013-1369, CVE-2013-1370, CVE-2013-1372,
and CVE-2013-1373.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2013-1366?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| adobe-flashplugin | 12.10 quantal | Fixed 11.2.202.270-0quantal1 |
| 12.04 LTS precise | Fixed 11.2.202.270-0precise1 |
| 11.10 oneiric | Fixed 11.2.202.270-0oneiric1 |
| 10.04 LTS lucid | Fixed 11.2.202.270-0lucid1 |
| 8.04 LTS hardy | Ignored end of life |
| flashplugin-nonfree | 12.10 quantal | Fixed 11.2.202.270ubuntu0.12.10.1 |
| 12.04 LTS precise | Fixed 11.2.202.270ubuntu0.12.04.1 |
| 11.10 oneiric | Fixed 11.2.202.270ubuntu0.11.10.1 |
| 10.04 LTS lucid | Fixed 11.2.202.270ubuntu0.10.04.1 |
| 8.04 LTS hardy | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [jdstrand](https://launchpad.net/~jdstrand)

chriscoulson provides updates for partner (adobe-flashplugin)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1366)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2013-1366)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2013-1366)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2013-1366)

### Other references

* <http://www.adobe.com/support/security/bulletins/apsb13-05.html>
* <https://www.cve.org/CVERecord?id=CVE-2013-1366>
