Back

CRITICAL

flash-plugin: multiple code execution issues fixed in APSB17-33

Published Dec 9, 2017

Description

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of providing language- and region- or country- specific functionality. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Dec 9, 2017
Updated Aug 5, 2024
Reserved Dec 2, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Nov 14, 2017