|
|||
Rule General Information |
---|
Release Date: | 2017-12-25 | |
Rule Name: | Adobe Flash MP3 ID3 Heap Buffer Overflow Vulnerability - 5 (CVE-2015-8446) | |
Severity: | ||
CVE ID: | ||
CNNVD ID: | ||
Rule Protection Details |
---|
Description: | Heap-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via an MP3 file with COMM tags that are mishandled during memory allocation. | |
Impact: | A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service. | |
Affected OS: | Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others | |
Reference: | SecurityFocusBID:78712 SecurityTrackerID:1034318 ZeroDayInitiative:ZDI-15-609 AdobeSecurityBulletins:apsb15-32 |
|
Solutions |
---|
Adobe has issued a fix on the official website. For more advisory, please visit: https://helpx.adobe.com/security/products/flash-player/apsb15-32.html |