PT-2016-1481 · Adobe+3 · Flash Player Esr+5

Abdulaziz Hariri

·

Published

2016-03-10

·

Updated

2022-12-14

·

CVE-2016-1005

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Flash Player (affected versions not specified) Adobe Flash Player ESR (affected versions not specified) Adobe Integrated Runtime (affected versions not specified)
Description The issue is caused by a buffer overflow. It may allow a remote attacker to execute arbitrary code or cause a denial of service (uninitialized pointer dereference, memory corruption) using specially crafted MPEG-4 data.
Recommendations For Adobe Flash Player, consider disabling the use of MPEG-4 data until a patch is available. For Adobe Flash Player ESR, restrict access to specially crafted MPEG-4 files to minimize the risk of exploitation. For Adobe Integrated Runtime, avoid using potentially vulnerable components that handle MPEG-4 data until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Access of Uninitialized Pointer

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1216
BDU:2016-00782
CVE-2016-1005
MGASA-2016-0109
OPENSUSE-SU-2016_0719-1
OPENSUSE-SU-2016_0734-1
RHSA-2016:0438
RHSA-2016_0438
SUSE-SU-2016:0715-1
SUSE-SU-2016:0716-1
ZDI-16-192

Affected Products

Alt Linux
Flash Player
Flash Player Esr
Integrated Runtime
Red Hat
Suse