CVE-2015-3108: Infoleak
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3108?
CVE-2015-3108 is classified as a critical vulnerability allowing potential remote code execution.
How do I fix CVE-2015-3108?
To fix CVE-2015-3108, update Adobe Flash Player to the latest version available.
Which software versions are affected by CVE-2015-3108?
CVE-2015-3108 affects Adobe Flash Player versions prior to 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X.
Is Adobe AIR impacted by CVE-2015-3108?
Yes, Adobe AIR versions prior to 18.0.0.144 on Windows and 18.0.0.143 on OS X are affected by CVE-2015-3108.
What types of attacks are possible due to CVE-2015-3108?
CVE-2015-3108 can allow attackers to execute arbitrary code via crafted Flash content, potentially compromising the affected system.