vendor:
Chrome
by:
bilou
7.5
CVSS
HIGH
Use-After-Free
416
CWE
Product Name: Chrome
Affected Version From: Chrome stable 42.0.2311.90 with Flash 17.0.0.169
Affected Version To: Chrome stable 42.0.2311.90 with Flash 17.0.0.169
Patch Exists: YES
Related CWE: N/A
CPE: a:google:chrome:42.0.2311.90
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Win7 x64 SP1
2015
Color.setRGB UAF in AS2
When calling Color.setRGB in AS2 it is possible to free the target_mc object used in the Color constructor while a reference remains in the stack.
Mitigation:
Update to the latest version of Chrome and Flash Player.