PT-2015-3071 · Adobe+2 · Flash Player+2
Published
2015-10-16
·
Updated
2017-09-13
·
CVE-2015-7648
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Flash Player versions prior to 18.0.0.255
Adobe Flash Player versions 19.x prior to 19.0.0.226
Adobe Flash Player versions prior to 11.2.202.540 on Linux
Description
The issue is related to a type confusion error, allowing attackers to execute arbitrary code. This can be achieved by leveraging an unspecified type confusion, enabling remote attackers to execute arbitrary code by causing a type inconsistency.
Recommendations
For Adobe Flash Player versions prior to 18.0.0.255, update to version 18.0.0.255 or later.
For Adobe Flash Player versions 19.x prior to 19.0.0.226, update to version 19.0.0.226 or later.
For Adobe Flash Player versions prior to 11.2.202.540 on Linux, update to version 11.2.202.540 or later.
Exploit
Fix
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Flash Player
Red Hat