First published: Wed Jun 10 2015(Updated: )
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Player for Internet Explorer 11 | <=11.2.202.460 | |
Linux Kernel | ||
Adobe AIR | <=17.0.0.144 | |
Google Android | ||
Adobe AIR | <=17.0.0.172 | |
Adobe AIR SDK and Compiler | <=17.0.0.172 | |
Adobe AIR SDK & Compiler | <=17.0.0.172 | |
macOS Yosemite | ||
Microsoft Windows | ||
Adobe Flash Player for Internet Explorer 11 | <=13.0.0.289 | |
Adobe Flash Player for Internet Explorer 11 | =14.0.0.125 | |
Adobe Flash Player for Internet Explorer 11 | =14.0.0.145 | |
Adobe Flash Player for Internet Explorer 11 | =14.0.0.176 | |
Adobe Flash Player for Internet Explorer 11 | =14.0.0.179 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.152 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.167 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.189 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.223 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.239 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.246 | |
Adobe Flash Player for Internet Explorer 11 | =16.0.0.235 | |
Adobe Flash Player for Internet Explorer 11 | =16.0.0.257 | |
Adobe Flash Player for Internet Explorer 11 | =16.0.0.287 | |
Adobe Flash Player for Internet Explorer 11 | =16.0.0.296 | |
Adobe Flash Player for Internet Explorer 11 | =17.0.0.134 | |
Adobe Flash Player for Internet Explorer 11 | =17.0.0.169 | |
Adobe Flash Player for Internet Explorer 11 | =17.0.0.188 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3108 is classified as a critical vulnerability allowing potential remote code execution.
To fix CVE-2015-3108, update Adobe Flash Player to the latest version available.
CVE-2015-3108 affects Adobe Flash Player versions prior to 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X.
Yes, Adobe AIR versions prior to 18.0.0.144 on Windows and 18.0.0.143 on OS X are affected by CVE-2015-3108.
CVE-2015-3108 can allow attackers to execute arbitrary code via crafted Flash content, potentially compromising the affected system.