PT-2016-1666 · Adobe+3 · Flash Player+3

Yuki Chen

·

Published

2016-04-08

·

Updated

2023-01-26

·

CVE-2016-1016

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Flash Player (affected versions not specified)
Description The issue is related to the implementation of the Transform object in the Flash Player platform, specifically a use-after-free vulnerability involving memory usage after it has been freed. This can be exploited by a remote attacker to execute arbitrary code using the flash.geom.Matrix callback.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1305
BDU:2016-00992
CVE-2016-1016
MGASA-2016-0134
OPENSUSE-SU-2016_1306-1
RHSA-2016:0610
RHSA-2016_0610
SUSE-SU-2016:1305-1
ZDI-16-226

Affected Products

Alt Linux
Flash Player
Red Hat
Suse