vendor:
Flash Player
by:
Google Security Research
9,3
CVSS
HIGH
Use-after-free
416
CWE
Product Name: Flash Player
Affected Version From: Adobe Flash Player versions prior to 18.0.0.203
Affected Version To: Adobe Flash Player versions prior to 18.0.0.203
Patch Exists: YES
Related CWE: CVE-2015-5119
CPE: o:adobe:flash_player:18.0.0.203
Metasploit:
https://www.rapid7.com/db/vulnerabilities/freebsd-vid-348bfa69-25a2-11e5-ade1-0011d823eebd/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-5119/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-5119/, https://www.rapid7.com/db/vulnerabilities/adobe-air-cve-2015-5119/, https://www.rapid7.com/db/vulnerabilities/adobe-flash-apsb15-16-cve-2015-5119/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2015-1214/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2015
Use-after-free in TextField.replaceText function
There is a use-after-free vulnerability in the TextField.replaceText function of Adobe Flash Player. If the function is called with a string parameter with toString defined, or an integer parameter with valueOf defined, the parent object of the TextField can be used after it is freed. This can be exploited to execute arbitrary code. Proof of Concept code is provided in the description.
Mitigation:
Upgrade to Adobe Flash Player version 18.0.0.203 or later.