CRITICAL
flash-plugin: multiple code execution issues fixed in APSB17-10
Published Apr 12, 2017
9.8
CRITICALCVSS 3.0
EPSS 8.89%
Description
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the ActionScript2 NetStream class. Successful exploitation could lead to arbitrary code execution.
Affected products
- Vendor n/a Product Adobe Flash Player 25.0.0.127 and earlier. Defaultn/a
- Version Adobe Flash Player 25.0.0.127 and earlier.StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Adobe Flash Player 25.0.0.127 and earlier. | n/a |
|
Configuration 1
AND
OR
- ≤ 25.0.0.127
- ≤ 25.0.0.127
Running on/with
OR
- n/a
- n/a
Configuration 2
AND
- ≤ 25.0.0.127
Configuration 3
AND
- ≤ 25.0.0.127
No data.
Red Hat Enterprise Linux 6 Supplementary
flash-plugin-0:25.0.0.148-1.el6_9
Fixed · RHSA-2017:0934
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Supplementary | flash-plugin-0:25.0.0.148-1.el6_9 | Fixed | RHSA-2017:0934 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- http://www.securityfocus.com/bid/97551 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038225 vdb-entryx_refsource_SECTRACK
- http://www.zerodayinitiative.com/advisories/ZDI-17-279/ Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:0934 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2017-3063 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1441308 Issue Tracking
- https://helpx.adobe.com/security/products/flash-player/apsb17-10.html x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-3063
- https://security.gentoo.org/glsa/201704-04 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2017-3063
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/97551 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id/1038225 | vdb-entryx_refsource_SECTRACK | |
| http://www.zerodayinitiative.com/advisories/ZDI-17-279/ | Third Party AdvisoryVDB Entry | |
| https://access.redhat.com/errata/RHSA-2017:0934 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2017-3063 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1441308 | Issue Tracking | |
| https://helpx.adobe.com/security/products/flash-player/apsb17-10.html | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-3063 | ||
| https://security.gentoo.org/glsa/201704-04 | vendor-advisoryx_refsource_GENTOO | |
| https://www.cve.org/CVERecord?id=CVE-2017-3063 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Apr 12, 2017
Updated Aug 5, 2024
Reserved Dec 2, 2016
Link CVE-2017-3063
CISA Vulnrichment
Updated n/a