PT-2016-3141 · Adobe+3 · Flash Player For Linux+14

Published

2015-12-29

·

Updated

2023-05-08

·

CVE-2016-0959

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Flash Player Desktop Runtime versions prior to 20.0.0.267 Adobe Flash Player Extended Support Release versions prior to 18.0.0.324 Adobe Flash Player for Google Chrome versions prior to 20.0.0.267 Adobe Flash Player for Microsoft Edge and Internet Explorer 11 versions prior to 20.0.0.267 Adobe Flash Player for Internet Explorer 10 and 11 versions prior to 20.0.0.267 Adobe Flash Player for Linux versions prior to 11.2.202.559 AIR Desktop Runtime versions prior to 20.0.0.233 AIR SDK versions prior to 20.0.0.233 AIR SDK & Compiler versions prior to 20.0.0.233 AIR for Android versions prior to 20.0.0.233
Description The issue is related to a use after free vulnerability. This vulnerability can be exploited by a remote attacker to gain access to protected information.
Recommendations For Adobe Flash Player Desktop Runtime versions prior to 20.0.0.267, update to version 20.0.0.267 or later. For Adobe Flash Player Extended Support Release versions prior to 18.0.0.324, update to version 18.0.0.324 or later. For Adobe Flash Player for Google Chrome versions prior to 20.0.0.267, update to version 20.0.0.267 or later. For Adobe Flash Player for Microsoft Edge and Internet Explorer 11 versions prior to 20.0.0.267, update to version 20.0.0.267 or later. For Adobe Flash Player for Internet Explorer 10 and 11 versions prior to 20.0.0.267, update to version 20.0.0.267 or later. For Adobe Flash Player for Linux versions prior to 11.2.202.559, update to version 11.2.202.559 or later. For AIR Desktop Runtime versions prior to 20.0.0.233, update to version 20.0.0.233 or later. For AIR SDK versions prior to 20.0.0.233, update to version 20.0.0.233 or later. For AIR SDK & Compiler versions prior to 20.0.0.233, update to version 20.0.0.233 or later. For AIR for Android versions prior to 20.0.0.233, update to version 20.0.0.233 or later.

Fix

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2017-01631
CVE-2016-0959
RHSA-2015:2697
RHSA-2015_2697

Affected Products

Air Desktop Runtime
Air Sdk
Air Sdk & Compiler
Air For Android
Flash Player
Flash Player Desktop Runtime
Adobe Flash Player Extended Support Release
Flash Player For Google Chrome
Adobe Flash Player For Internet Explorer 10/11
Flash Player For Linux
Adobe Flash Player For Microsoft Edge/Internet Explorer 11
Google Chrome
Internet Explorer
Edge
Red Hat