RULE(RULE ID:320650)

Rule General Information
Release Date: 2017-12-25
Rule Name: Adobe Flash MP3 ID3 Heap Buffer Overflow Vulnerability - 11 (CVE-2015-8446)
Severity:
CVE ID:
Rule Protection Details
Description: Heap-based buffer overflow in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via an MP3 file with COMM tags that are mishandled during memory allocation.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:78712
SecurityTrackerID:1034318
ZeroDayInitiative:ZDI-15-609
AdobeSecurityBulletins:apsb15-32
Solutions
Adobe has issued a fix on the official website. For more advisory, please visit:
https://helpx.adobe.com/security/products/flash-player/apsb15-32.html