First published: Fri Aug 14 2015(Updated: )
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allow attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-5554, CVE-2015-5558, and CVE-2015-5562.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe AIR | <=18.0.0.180 | |
Adobe AIR SDK and Compiler | <=18.0.0.180 | |
Adobe AIR SDK & Compiler | <=18.0.0.180 | |
Adobe Flash Player for Internet Explorer 11 | <=11.2.202.491 | |
Linux Kernel | ||
Adobe Flash Player for Internet Explorer 11 | <=18.0.0.209 | |
macOS Yosemite | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5555 is classified as a critical vulnerability due to its ability to allow attackers to execute arbitrary code.
To fix CVE-2015-5555, update Adobe Flash Player to version 18.0.0.232 or later and Adobe AIR to version 18.0.0.199 or later.
CVE-2015-5555 affects Adobe Flash Player versions before 18.0.0.232 and Adobe AIR versions before 18.0.0.199.
Yes, CVE-2015-5555 is exploitable on Linux for versions of Adobe Flash Player prior to 11.2.202.508.
Disabling Adobe Flash Player and avoiding the use of Adobe AIR can serve as temporary workarounds for CVE-2015-5555.