vendor:
Adobe Flash
by:
Unknown
7.5
CVSS
HIGH
Use-After-Free
416
CWE
Product Name: Adobe Flash
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: a:adobe:flash
Platforms Tested: Adobe Flash (SWF) files are supported on various platforms including Windows, Mac, and Linux.
Unknown
Use-After-Free in TextField setFormat Method
The TextField setFormat method in Adobe Flash contains a use-after-free vulnerability. By passing an object parameter with a defined valueOf function, or by overriding a constructor of the object parameter, an attacker can free the TextField parent object. This can lead to subsequent use of the freed object, potentially allowing for arbitrary code execution.
Mitigation:
To mitigate this vulnerability, developers should ensure that the TextField parent object is not freed prematurely. Additionally, it is recommended to update to the latest version of Adobe Flash, as this vulnerability may have been patched.