PT-2015-3161 · Adobe+3 · Integrated Runtime+4

Published

2015-12-08

·

Updated

2017-02-17

·

CVE-2015-8453

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adobe Flash Player (affected versions not specified) Adobe Integrated Runtime (affected versions not specified)
Description The issue is related to the lack of protection for internal data in Flash Player and Adobe Integrated Runtime. This can be exploited by a remote attacker to bypass the Address Space Layout Randomization (ASLR) security mechanism using Just-In-Time (JIT) data.
Recommendations For Adobe Flash Player, consider disabling the JIT compiler as a temporary workaround until a patch is available. For Adobe Integrated Runtime, restrict access to sensitive data to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2079
BDU:2016-00391
CVE-2015-8453
MGASA-2015-0468
OPENSUSE-SU-2015_2239-1
RHSA-2015:2593
RHSA-2015_2593
SUSE-SU-2015:2236-1
SUSE-SU-2015:2247-1
ZDI-15-614

Affected Products

Alt Linux
Flash Player
Integrated Runtime
Red Hat
Suse