PT-2016-1341 · Adobe+1 · Flash Player+2
Publicado
2015-12-09
·
Atualizado
2023-05-08
·
CVE-2015-8655
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Flash Player (affected versions not specified)
Adobe Integrated Runtime (affected versions not specified)
Description
The issue is related to a use-after-free error, which can be exploited by a remote attacker to execute arbitrary code using specially crafted MPEG-4 data.
Recommendations
For Adobe Flash Player, update to a version that addresses the use-after-free error in MPEG-4 handling.
For Adobe Integrated Runtime, update to a version that addresses the use-after-free error in MPEG-4 handling.
As a temporary workaround, consider restricting the use of MPEG-4 data in Adobe Flash Player and Adobe Integrated Runtime until a patch is available.
Correção
Use After Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Flash Player
Integrated Runtime
Red Hat