vendor:
Flash Player
by:
Google Security Research
7.5
CVSS
HIGH
Wild Pointer Target Increment
119
CWE
Product Name: Flash Player
Affected Version From: Adobe Flash Player 18.0.0.194 and earlier versions
Affected Version To: Adobe Flash Player 18.0.0.203 and earlier versions
Patch Exists: YES
Related CWE: CVE-2015-7645
CPE: a:adobe:flash_player:18.0.0.194
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2015-2024/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2015-1913/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-7645/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-7645/, https://www.rapid7.com/db/vulnerabilities/adobe-flash-apsb15-27-cve-2015-7645/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux x64
2015
Wild Pointer Target Increment Vulnerability in Adobe Flash Player
The attached sample file, signal_sigsegv_7ffff637297a_8900_e3f87b25c25db8f9ec3c975f8c1211cc.swf, crashes, perhaps relating to XML handling. The crash looks like this on Linux x64: rcx 0x303030303030300 217020518514230016. The wider context shows that the wild pointer target can be incremented with this vulnerability, which is typically enough for an exploit.
Mitigation:
Adobe has released a security update to address this vulnerability. Users should update to the latest version of Adobe Flash Player.