flash-plugin: multiple code execution issues fixed in APSB15-32
Published Mar 4, 2016
8.8
HIGHCVSS 3.1
EPSS 7.66%
Description
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via crafted MPEG-4 data, a different vulnerability than CVE-2015-8048, CVE-2015-8049, CVE-2015-8050, CVE-2015-8055, CVE-2015-8056, CVE-2015-8057, CVE-2015-8058, CVE-2015-8059, CVE-2015-8061, CVE-2015-8062, CVE-2015-8063, CVE-2015-8064, CVE-2015-8065, CVE-2015-8066, CVE-2015-8067, CVE-2015-8068, CVE-2015-8069, CVE-2015-8070, CVE-2015-8071, CVE-2015-8401, CVE-2015-8402, CVE-2015-8403, CVE-2015-8404, CVE-2015-8405, CVE-2015-8406, CVE-2015-8410, CVE-2015-8411, CVE-2015-8412, CVE-2015-8413, CVE-2015-8414, CVE-2015-8420, CVE-2015-8421, CVE-2015-8422, CVE-2015-8423, CVE-2015-8424, CVE-2015-8425, CVE-2015-8426, CVE-2015-8427, CVE-2015-8428, CVE-2015-8429, CVE-2015-8430, CVE-2015-8431, CVE-2015-8432, CVE-2015-8433, CVE-2015-8434, CVE-2015-8435, CVE-2015-8436, CVE-2015-8437, CVE-2015-8441, CVE-2015-8442, CVE-2015-8447, CVE-2015-8448, CVE-2015-8449, CVE-2015-8450, CVE-2015-8452, CVE-2015-8454, CVE-2015-8653, CVE-2015-8655, and CVE-2015-8822.
Affected products
No data.
Configuration 1
- ≤ 11.2.202.548
Running on/with
- n/a
Configuration 2
Configuration 3
Configuration 4
Running on/with
- n/a
- n/a
- n/a
- ≤ 19.0.0.245
Configuration 5
- ≤ 19.0.0.245
Configuration 6
Running on/with
- n/a
- ≤ 19.0.0.245
Configuration 7
Configuration 8
Configuration 9
No data.
Red Hat Enterprise Linux 5 Supplementary
flash-plugin-0:11.2.202.554-1.el5
Fixed · RHSA-2015:2593
Red Hat Enterprise Linux 6 Supplementary
flash-plugin-0:11.2.202.554-1.el6_7
Fixed · RHSA-2015:2593
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 Supplementary | flash-plugin-0:11.2.202.554-1.el5 | Fixed | RHSA-2015:2593 |
| Red Hat Enterprise Linux 6 Supplementary | flash-plugin-0:11.2.202.554-1.el6_7 | Fixed | RHSA-2015:2593 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- http://www.securityfocus.com/bid/84162 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-15-663 x_refsource_MISCThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2015-8821 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1289771 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2015-8687 Advisory
- https://helpx.adobe.com/security/products/flash-player/apsb15-32.html x_refsource_CONFIRMPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2015-8821
- https://www.cve.org/CVERecord?id=CVE-2015-8821
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/84162 | vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.zerodayinitiative.com/advisories/ZDI-15-663 | x_refsource_MISCThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2015-8821 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1289771 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2015-8687 | Advisory | |
| https://helpx.adobe.com/security/products/flash-player/apsb15-32.html | x_refsource_CONFIRMPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2015-8821 | ||
| https://www.cve.org/CVERecord?id=CVE-2015-8821 |
Change history (0)
No recorded changes yet.