PT-2015-2840 · Adobe+3 · Integrated Runtime+7

Published

2015-12-09

·

Updated

2023-05-08

·

CVE-2015-8406

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Integrated Runtime versions (affected versions not specified) Adobe Flash Player versions (affected versions not specified) Adobe AIR versions (affected versions not specified) Adobe AIR SDK versions (affected versions not specified) Adobe AIR SDK & Compiler versions (affected versions not specified)
Description The issue is related to the use of memory after it has been freed, which can allow a remote attacker to execute arbitrary code. This can be exploited by malicious actors to gain unauthorized access and control.
Recommendations For Adobe Integrated Runtime, update to a version that addresses the use-after-free issue. For Adobe Flash Player, consider disabling the vulnerable component until a patch is available. For Adobe AIR, restrict access to vulnerable modules to minimize the risk of exploitation. For Adobe AIR SDK, avoid using vulnerable parameters in affected API endpoints until the issue is resolved. For Adobe AIR SDK & Compiler, as a temporary workaround, consider disabling vulnerable functions until a patch is available.

Fix

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2079
BDU:2015-12206
CVE-2015-8406
MGASA-2015-0468
OPENSUSE-SU-2015_2239-1
RHSA-2015:2593
RHSA-2015_2593
SUSE-SU-2015:2236-1
SUSE-SU-2015:2247-1

Affected Products

Alt Linux
Air
Air Sdk
Air Sdk & Compiler
Flash Player
Integrated Runtime
Red Hat
Suse