vendor:
Flash Player
by:
Google Security Research
9.3
CVSS
HIGH
Heap-Based Buffer Overflow
119
CWE
Product Name: Flash Player
Affected Version From: Adobe Flash Player versions prior to 18.0.0.232
Affected Version To: Adobe Flash Player versions prior to 18.0.0.232
Patch Exists: YES
Related CWE: CVE-2015-3043
CPE: a:adobe:flash_player:18.0.0.232
Metasploit:
https://www.rapid7.com/db/modules/exploit/multi/browser/adobe_flash_nellymoser_bof/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2015-0813/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-3038/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-3041/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-3043/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-0347/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-0350/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-0355/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-0350/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-0352/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-0353/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-0354/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-0355/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-0360/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-0347/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-3041/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-3042/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-3043/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-3038/, https://www.rapid7.com/db/vulnerabilities/adobe-flash-apsb15-06-cve-2015-0350/, https://www.rapid7.com/db/?q=CVE-2015-3043&type=&page=2, https://www.rapid7.com/db/?q=CVE-2015-3043&type=&page=3, https://www.rapid7.com/db/?q=CVE-2015-3043&type=&page=2
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2015
Heap-Based Buffer Overflow in Adobe Flash Player
A heap-based buffer overflow vulnerability was discovered in Adobe Flash Player. The vulnerability is caused due to a boundary error when handling a specially crafted .flv file. This can be exploited to cause a stack-based buffer overflow via a specially crafted .flv file. Successful exploitation may allow execution of arbitrary code.
Mitigation:
Users should update to the latest version of Adobe Flash Player.