vendor:
Flash Player
by:
Google Security Research
9.3
CVSS
HIGH
Use-after-free
416
CWE
Product Name: Flash Player
Affected Version From: 17.0.0.188
Affected Version To: 17.0.0.188
Patch Exists: YES
Related CWE: CVE-2015-5122
CPE: o:adobe:flash_player:17.0.0.188
Metasploit:
https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-5122/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-5122/, https://www.rapid7.com/db/vulnerabilities/hpsim-cve-2015-5122/, https://www.rapid7.com/db/vulnerabilities/adobe-flash-apsb15-18-cve-2015-5122/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2015-1235/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux x64
2015
Use-after-free Vulnerability in Adobe Flash Player
A use-after-free vulnerability exists in Adobe Flash Player versions 17.0.0.188 and earlier. The vulnerability is caused by a non-deterministic condition that can lead to a crash when accessing memory after it has been freed. This can be exploited to execute arbitrary code by tricking a user into opening a specially crafted SWF file.
Mitigation:
Upgrade to the latest version of Adobe Flash Player.