PT-2016-2955 · Adobe+3 · Flash Player+3

Published

2016-12-14

·

Updated

2022-11-16

·

CVE-2016-7873

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Flash Player versions 23.0.0.207 and earlier Adobe Flash Player versions 11.2.202.644 and earlier
Description The issue is caused by a buffer overflow in the memory, allowing a remote attacker to execute arbitrary code or cause a denial of service due to memory corruption. This is related to the ad policy functionality method in the PSDK class of the Flash Player platform.
Recommendations For Adobe Flash Player versions 23.0.0.207 and earlier, update to a version later than 23.0.0.207 to resolve the issue. For Adobe Flash Player versions 11.2.202.644 and earlier, update to a version later than 11.2.202.644 to resolve the issue.

Fix

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2445
BDU:2016-02386
BDU:2017-00026
CVE-2016-7873
MGASA-2017-0014
RHSA-2016:2947
RHSA-2016_2947
SUSE-SU-2016:3148-1

Affected Products

Alt Linux
Flash Player
Red Hat
Suse