PT-2016-7410 · Adobe+3 · Flash Player+3

Kuchiki Toko

·

Publicado

2016-11-08

·

Atualizado

2019-05-16

·

CVE-2016-7865

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Flash Player versions 23.0.0.205 and earlier Adobe Flash Player versions 11.2.202.643 and earlier
Description The issue is related to a type confusion vulnerability that can be exploited, potentially leading to arbitrary code execution. This vulnerability may be related to a use-after-free condition in LocalConnection, which could allow for remote code execution.
Recommendations For Adobe Flash Player versions 23.0.0.205 and earlier, update to a version later than 23.0.0.205 to resolve the issue. For Adobe Flash Player versions 11.2.202.643 and earlier, update to a version later than 11.2.202.643 to resolve the issue. As a temporary workaround, consider disabling the LocalConnection feature until a patch is available.

Correção

Incorrect Type Conversion or Cast

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-2264
ALT-PU-2016-2266
CVE-2016-7865
MGASA-2016-0370
OPENSUSE-SU-2016_2774-1
OPENSUSE-SU-2016_2782-1
RHSA-2016:2676
RHSA-2016_2676
SUSE-SU-2016:2778-1
ZDI-16-598

Produtos afetados

Alt Linux
Flash Player
Red Hat
Suse