vendor:
Flash Media Server
by:
Unknown
7.5
CVSS
HIGH
Denial-of-Service
400
CWE
Product Name: Flash Media Server
Affected Version From: All versions prior to 4.5.2
Affected Version To: 4.5.2002
Patch Exists: YES
Related CWE: CVE-2011-2460
CPE: a:adobe:flash_media_server
Metasploit:
https://www.rapid7.com/db/vulnerabilities/hpsim-cve-2011-2455/, https://www.rapid7.com/db/vulnerabilities/adobe-apsb11-28-CVE-2011-2452/, https://www.rapid7.com/db/vulnerabilities/hpsim-cve-2011-2445/, https://www.rapid7.com/db/vulnerabilities/hpsim-cve-2011-2453/, https://www.rapid7.com/db/vulnerabilities/hpsim-cve-2011-2454/, https://www.rapid7.com/db/vulnerabilities/hpsim-cve-2011-2459/, https://www.rapid7.com/db/vulnerabilities/adobe-air-cve-2011-2445/, https://www.rapid7.com/db/vulnerabilities/adobe-air-cve-2011-2451/, https://www.rapid7.com/db/vulnerabilities/adobe-air-cve-2011-2452/, https://www.rapid7.com/db/vulnerabilities/adobe-air-cve-2011-2453/, https://www.rapid7.com/db/vulnerabilities/adobe-air-cve-2011-2459/, https://www.rapid7.com/db/vulnerabilities/adobe-air-cve-2011-2460/, https://www.rapid7.com/db/vulnerabilities/adobe-apsb11-28-CVE-2011-2451/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2011-2445/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2011-2452/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2011-2455/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2011-2460/, https://www.rapid7.com/db/vulnerabilities/hpsim-cve-2011-2452/, https://www.rapid7.com/db/vulnerabilities/hpsim-cve-2011-2460/, https://www.rapid7.com/db/vulnerabilities/adobe-apsb11-28-CVE-2011-2460/, https://www.rapid7.com/db/?q=CVE-2011-2460&type=&page=2, https://www.rapid7.com/db/?q=CVE-2011-2460&type=&page=3, https://www.rapid7.com/db/?q=CVE-2011-2460&type=&page=2
Platforms Tested: Windows, Linux, Mac
2011
Remote Denial-of-Service Vulnerability in Adobe Flash Media Server
The Adobe Flash Media Server is prone to a remote denial-of-service vulnerability. Successful exploits will allow attackers to crash the affected application, denying service to legitimate users. Due to the nature of this issue, arbitrary code execution may be possible; however, this has not been confirmed.
Mitigation:
Apply the latest security patches provided by Adobe.