flash-plugin: information leak leading to ASLR bypass (APSB15-11)
Published Jun 10, 2015
5.0
MEDIUMCVSS 2.0
EPSS 2.44%
Description
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors.
Affected products
No data.
Configuration 1
- ≤ 11.2.202.460
Running on/with
- n/a
Configuration 3
Configuration 4
- ≤ 13.0.0.289
- 14.0.0.125
- 14.0.0.145
- 14.0.0.176
- 14.0.0.179
- 15.0.0.152
- 15.0.0.167
- 15.0.0.189
- 15.0.0.223
- 15.0.0.239
- 15.0.0.246
- 16.0.0.235
- 16.0.0.257
- 16.0.0.287
- 16.0.0.296
- 17.0.0.134
- 17.0.0.169
- 17.0.0.188
No data.
Red Hat Enterprise Linux 5 Supplementary
flash-plugin-0:11.2.202.466-1.el5
Fixed · RHSA-2015:1086
Supplementary for Red Hat Enterprise Linux 6
flash-plugin-0:11.2.202.466-1.el6_6
Fixed · RHSA-2015:1086
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 Supplementary | flash-plugin-0:11.2.202.466-1.el5 | Fixed | RHSA-2015:1086 |
| Supplementary for Red Hat Enterprise Linux 6 | flash-plugin-0:11.2.202.466-1.el6_6 | Fixed | RHSA-2015:1086 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00005.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00009.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00011.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2015-1086.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/75084 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1032519 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2015-3108 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1230201 Issue Tracking
- https://helpx.adobe.com/security/products/flash-player/apsb15-11.html x_refsource_CONFIRMPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2015-3108
- https://security.gentoo.org/glsa/201506-01 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2015-3108
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00005.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00009.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00011.html | vendor-advisoryx_refsource_SUSE | |
| http://rhn.redhat.com/errata/RHSA-2015-1086.html | vendor-advisoryx_refsource_REDHAT | |
| http://www.securityfocus.com/bid/75084 | vdb-entryx_refsource_BID | |
| http://www.securitytracker.com/id/1032519 | vdb-entryx_refsource_SECTRACK | |
| https://access.redhat.com/security/cve/CVE-2015-3108 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1230201 | Issue Tracking | |
| https://helpx.adobe.com/security/products/flash-player/apsb15-11.html | x_refsource_CONFIRMPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2015-3108 | ||
| https://security.gentoo.org/glsa/201506-01 | vendor-advisoryx_refsource_GENTOO | |
| https://www.cve.org/CVERecord?id=CVE-2015-3108 |
Change history (0)
No recorded changes yet.