First published: Tue Sep 22 2015(Updated: )
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5567.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe AIR | <=18.0.0.143 | |
Google Android | ||
Adobe Flash Player for Internet Explorer 11 | <=11.2.202.508 | |
Linux Kernel | ||
Adobe AIR | <=18.0.0.199 | |
Adobe AIR SDK and Compiler | <=18.0.0.199 | |
Adobe AIR SDK & Compiler | <=18.0.0.180 | |
macOS Yosemite | ||
Microsoft Windows | ||
Adobe Flash Player for Internet Explorer 11 | <=13.0.0.289 | |
Adobe Flash Player for Internet Explorer 11 | =14.0.0.125 | |
Adobe Flash Player for Internet Explorer 11 | =14.0.0.145 | |
Adobe Flash Player for Internet Explorer 11 | =14.0.0.176 | |
Adobe Flash Player for Internet Explorer 11 | =14.0.0.179 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.152 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.167 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.189 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.223 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.239 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.246 | |
Adobe Flash Player for Internet Explorer 11 | =16.0.0.235 | |
Adobe Flash Player for Internet Explorer 11 | =16.0.0.257 | |
Adobe Flash Player for Internet Explorer 11 | =16.0.0.287 | |
Adobe Flash Player for Internet Explorer 11 | =16.0.0.296 | |
Adobe Flash Player for Internet Explorer 11 | =17.0.0.134 | |
Adobe Flash Player for Internet Explorer 11 | =17.0.0.169 | |
Adobe Flash Player for Internet Explorer 11 | =17.0.0.188 | |
Adobe Flash Player for Internet Explorer 11 | =17.0.0.190 | |
Adobe Flash Player for Internet Explorer 11 | =17.0.0.191 | |
Adobe Flash Player for Internet Explorer 11 | =18.0.0.160 | |
Adobe Flash Player for Internet Explorer 11 | =18.0.0.194 | |
Adobe Flash Player for Internet Explorer 11 | =18.0.0.203 | |
Adobe Flash Player for Internet Explorer 11 | =18.0.0.209 | |
Adobe Flash Player for Internet Explorer 11 | =18.0.0.232 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5579 is classified as a critical vulnerability that allows attackers to execute arbitrary code or cause a denial of service.
To fix CVE-2015-5579, you should update Adobe Flash Player to version 18.0.0.241 or later, and Adobe AIR to version 19.0.0.190 or later.
CVE-2015-5579 affects Adobe Flash Player versions prior to 18.0.0.241 and Adobe AIR versions prior to 19.0.0.190 on Windows and OS X, as well as Adobe Flash Player for Linux before version 11.2.202.521.
Exploitation of CVE-2015-5579 can lead to unauthorized access to system resources, allowing attackers to execute malicious code.
Mitigating the risks of CVE-2015-5579 primarily involves applying the appropriate security updates from Adobe promptly.