PT-2015-1512 · Adobe+3 · Flash Player+3

CVE-2015-5123

·

Publicado

2015-07-10

·

Atualizado

2025-02-14

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Flash Player versions 11.x through 11.2.202.481 Adobe Flash Player versions 12.x through 18.0.0.204 Adobe Flash Player versions 13.x through 13.0.0.302 Adobe Flash Player versions 14.x through 18.0.0.203
Description The issue is related to a use-after-free vulnerability in the BitmapData class in the ActionScript 3 implementation. This vulnerability can be exploited by remote attackers to execute arbitrary code or cause a denial of service via crafted Flash content that overrides a valueOf function. The vulnerability was exploited in the wild in July 2015.
Recommendations For Adobe Flash Player versions 11.x through 11.2.202.481, update to a version that contains a fix for this issue. For Adobe Flash Player versions 12.x through 18.0.0.204, update to a version that contains a fix for this issue. For Adobe Flash Player versions 13.x through 13.0.0.302, update to a version that contains a fix for this issue. For Adobe Flash Player versions 14.x through 18.0.0.203, update to a version that contains a fix for this issue. As a temporary workaround, consider disabling the use of crafted Flash content that overrides the valueOf function until a patch is available.

Exploit

Correção

RCE

DoS

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1610
ALT-PU-2015-1616
BDU:2015-10798
BDU:2015-10799
CVE-2015-5123
MGASA-2015-0275
RHSA-2015:1235
RHSA-2015_1235
SUSE-SU-2015:1255-1
SUSE-SU-2015:1258-1

Produtos afetados

Alt Linux
Flash Player
Red Hat
Suse