vendor:
Adobe Animate
by:
John Page aka hyp3rlinx
9,8
CVSS
CRITICAL
Critical Memory Corruption Vulnerability
119
CWE
Product Name: Adobe Animate
Affected Version From: 15.2.1.95 and earlier versions
Affected Version To: 15.2.1.95 and earlier versions
Patch Exists: YES
Related CWE: CVE-2016-7866, APSB16-38
CPE: a:adobe:animate:15.2.1.95
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows / Macintosh
2016
Adobe Animate Memory Corruption Vulnerability
Adobe Animate suffers from a Buffer Overflow when creating .FLA files with ActionScript Classes that use overly long Class names. This causes memory corruption leading to possible arbitrary code execution upon opening a maliciously created .Fla Flash file.
Mitigation:
Upgrade to Adobe Animate version 15.2.2.96 or later.