First published: Thu Jul 09 2015(Updated: )
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3135 and CVE-2015-4432.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Flash Player | <=13.0.0.289 | |
Macromedia Flash Player | =14.0.0.125 | |
Macromedia Flash Player | =14.0.0.145 | |
Macromedia Flash Player | =14.0.0.176 | |
Macromedia Flash Player | =14.0.0.179 | |
Macromedia Flash Player | =15.0.0.152 | |
Macromedia Flash Player | =15.0.0.167 | |
Macromedia Flash Player | =15.0.0.189 | |
Macromedia Flash Player | =15.0.0.223 | |
Macromedia Flash Player | =15.0.0.239 | |
Macromedia Flash Player | =15.0.0.246 | |
Macromedia Flash Player | =16.0.0.235 | |
Macromedia Flash Player | =16.0.0.257 | |
Macromedia Flash Player | =16.0.0.287 | |
Macromedia Flash Player | =16.0.0.296 | |
Macromedia Flash Player | =17.0.0.134 | |
Macromedia Flash Player | =17.0.0.169 | |
Macromedia Flash Player | =17.0.0.188 | |
Macromedia Flash Player | =17.0.0.190 | |
Macromedia Flash Player | =18.0.0.160 | |
Macromedia Flash Player | =18.0.0.194 | |
Apple iOS and macOS | ||
Microsoft Windows Operating System | ||
Macromedia Flash Player | <=11.2.202.468 | |
Linux Kernel | ||
Adobe | <=18.0.0.144 | |
Adobe AIR | <=18.0.0.144 | |
Adobe AIR SDK & Compiler | <=18.0.0.144 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5118 has been rated as critical due to its potential to allow remote code execution.
To remediate CVE-2015-5118, update Adobe Flash Player to version 18.0.0.203 or later, or to the latest version available.
CVE-2015-5118 affects Adobe Flash Player versions prior to 13.0.0.302 and the 14.x through 18.x series prior to 18.0.0.203.
Yes, Adobe AIR versions prior to 18.0.0.180 and its SDK and Compiler versions before 18.0.0.180 are affected by CVE-2015-5118.
CVE-2015-5118 impacts Adobe Flash Player on Windows, macOS, and Linux operating systems.