Back

CRITICAL

flash-plugin: multiple code execution issues fixed in APSB17-33

Published Dec 9, 2017

Description

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer due to an integer overflow; the computation is part of the abstraction that creates an arbitrarily sized transparent or opaque bitmap image. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Dec 9, 2017
Updated Aug 5, 2024
Reserved Jul 13, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Nov 14, 2017