PT-2016-1411 · Adobe+1 · Flash Player+2
Abdulaziz Hariri
·
Published
2015-12-09
·
Updated
2023-05-08
·
CVE-2015-8656
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Flash Player (affected versions not specified)
Adobe Integrated Runtime (affected versions not specified)
Description
The issue is caused by a buffer overflow. It may allow a remote attacker to execute arbitrary code or cause a denial of service (out-of-bounds memory read, memory corruption) using specially crafted MPEG-4 data.
Recommendations
For Adobe Flash Player, consider disabling the use of MPEG-4 data until a patch is available.
For Adobe Integrated Runtime, restrict the processing of specially crafted MPEG-4 files to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Flash Player
Integrated Runtime
Red Hat