Back

HIGH

flash-plugin: multiple code execution issues fixed in APSB15-32

Published Dec 10, 2015

Description

Heap-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via an MP3 file with COMM tags that are mishandled during memory allocation, a different vulnerability than CVE-2015-8438.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Dec 10, 2015
Updated Aug 6, 2024
Reserved Dec 2, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Dec 8, 2015