PT-2015-2922 · Adobe+3 · Integrated Runtime+4

Published

2015-12-08

·

Updated

2023-05-08

·

CVE-2015-8050

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Flash Player (affected versions not specified) Adobe Integrated Runtime (affected versions not specified)
Description The issue is related to a use-after-free vulnerability in the implementation of the MovieClip object in Flash Player and Adobe Integrated Runtime. This vulnerability can be exploited by a remote attacker using a specially crafted call to the beginGradientFill function, potentially allowing the execution of arbitrary code.
Recommendations For Adobe Flash Player, consider disabling the beginGradientFill function as a temporary workaround until a patch is available. For Adobe Integrated Runtime, restrict access to the MovieClip object to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2079
BDU:2016-00019
CVE-2015-8050
MGASA-2015-0468
OPENSUSE-SU-2015_2239-1
RHSA-2015:2593
RHSA-2015_2593
SUSE-SU-2015:2236-1
SUSE-SU-2015:2247-1
ZDI-15-602

Affected Products

Alt Linux
Flash Player
Integrated Runtime
Red Hat
Suse