PT-2016-1409 · Adobe+1 · Flash Player+2
Abdulaziz Hariri
·
Published
2015-12-09
·
Updated
2023-05-08
·
CVE-2015-8658
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Flash Player (affected versions not specified)
Adobe Integrated Runtime (affected versions not specified)
Description
The issue is caused by a buffer overflow in the Flash Player and Adobe Integrated Runtime platforms. It can be exploited by a remote attacker using specially crafted MPEG-4 data, potentially allowing the execution of arbitrary code or causing a denial of service due to a dangling pointer or memory corruption.
Recommendations
For Adobe Flash Player, update to a version that addresses the buffer overflow issue in MPEG-4 parsing.
For Adobe Integrated Runtime, apply the necessary patch or update to resolve the buffer overflow vulnerability in handling MPEG-4 data.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Flash Player
Integrated Runtime
Red Hat