CVE-2015-3113: Adobe Flash Player Heap-Based Buffer Overflow Vulnerability
Adobe Security Bulletin APSB15-14 for Adobe Flash Player describes a flaw that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB15-14:
Adobe has released security updates for Adobe Flash Player for Windows, Macintosh and Linux. These updates address a critical vulnerability (CVE-2015-3113) that could potentially allow an attacker to take control of the affected system.
Adobe is aware of reports that CVE-2015-3113 is being actively exploited in the wild via limited, targeted attacks. Systems running Internet Explorer for Windows 7 and below, as well as Firefox on Windows XP, are known targets.
External References:
https://helpx.adobe.com/security/products/flash-player/apsb15-14.html
Other sources
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015.
— NVD
Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/flash-pluginto a version that resolves this vulnerability.Fixed in 11.2.202.468 - Upgrade
Upgrade
Adobe Flash Playerto a version that resolves this vulnerability.Fixed in 13.0.0.296 - Upgrade
Upgrade
Adobe Flash Playerto a version that resolves this vulnerability.Fixed in 18.0.0.194 - Upgrade
Upgrade
Adobe Flash Playerto a version that resolves this vulnerability.Fixed in 11.2.202.468 - Compensating control
Disconnect affected, end-of-life Flash Player systems from the network if they are still in use (APSB15-14 notes the impacted product is end-of-life and should be disconnected if still in use).
- Compensating control
Ensure Windows Internet Explorer on Windows 7 and below and Firefox on Windows XP are not used with the affected Flash Player versions; these environments are described as known targets in APSB15-14.
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3113?
CVE-2015-3113 is rated as critical due to its potential for remote code execution through a heap-based buffer overflow in Adobe Flash Player.
How do I fix CVE-2015-3113?
To fix CVE-2015-3113, update Adobe Flash Player to version 18.0.0.194 or later.
Which versions of Adobe Flash Player are vulnerable to CVE-2015-3113?
Adobe Flash Player versions prior to 18.0.0.194, including 13.0.0.296 and 14.x through 18.x before 18.0.0.194 are vulnerable.
Can CVE-2015-3113 affect Linux systems?
Yes, CVE-2015-3113 affects Adobe Flash Player on Linux systems running versions prior to 11.2.202.468.
What types of attacks can CVE-2015-3113 facilitate?
CVE-2015-3113 can enable remote attackers to execute arbitrary code on affected systems.