First published: Tue Sep 22 2015(Updated: )
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to bypass the Same Origin Policy and obtain sensitive information via unspecified vectors.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe AIR | <=18.0.0.143 | |
Google Android | ||
Adobe Flash Player for Internet Explorer 11 | <=11.2.202.508 | |
Linux Kernel | ||
Adobe AIR | <=18.0.0.199 | |
Adobe AIR SDK and Compiler | <=18.0.0.199 | |
Adobe AIR SDK & Compiler | <=18.0.0.180 | |
macOS Yosemite | ||
Microsoft Windows | ||
Adobe Flash Player for Internet Explorer 11 | <=13.0.0.289 | |
Adobe Flash Player for Internet Explorer 11 | =14.0.0.125 | |
Adobe Flash Player for Internet Explorer 11 | =14.0.0.145 | |
Adobe Flash Player for Internet Explorer 11 | =14.0.0.176 | |
Adobe Flash Player for Internet Explorer 11 | =14.0.0.179 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.152 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.167 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.189 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.223 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.239 | |
Adobe Flash Player for Internet Explorer 11 | =15.0.0.246 | |
Adobe Flash Player for Internet Explorer 11 | =16.0.0.235 | |
Adobe Flash Player for Internet Explorer 11 | =16.0.0.257 | |
Adobe Flash Player for Internet Explorer 11 | =16.0.0.287 | |
Adobe Flash Player for Internet Explorer 11 | =16.0.0.296 | |
Adobe Flash Player for Internet Explorer 11 | =17.0.0.134 | |
Adobe Flash Player for Internet Explorer 11 | =17.0.0.169 | |
Adobe Flash Player for Internet Explorer 11 | =17.0.0.188 | |
Adobe Flash Player for Internet Explorer 11 | =17.0.0.190 | |
Adobe Flash Player for Internet Explorer 11 | =17.0.0.191 | |
Adobe Flash Player for Internet Explorer 11 | =18.0.0.160 | |
Adobe Flash Player for Internet Explorer 11 | =18.0.0.194 | |
Adobe Flash Player for Internet Explorer 11 | =18.0.0.203 | |
Adobe Flash Player for Internet Explorer 11 | =18.0.0.209 | |
Adobe Flash Player for Internet Explorer 11 | =18.0.0.232 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6679 has been classified as a critical severity vulnerability due to its potential to bypass the Same Origin Policy.
To remediate CVE-2015-6679, update Adobe Flash Player and Adobe AIR to the latest versions provided by Adobe.
CVE-2015-6679 affects Adobe Flash Player versions prior to 18.0.0.241 and 19.x prior to 19.0.0.185 on Windows and macOS, and Adobe AIR before version 19.0.0.190.
If exploited, CVE-2015-6679 can allow an attacker to bypass security mechanisms and potentially access sensitive information.
The best approach is to update to patched versions, but users may reduce exposure by disabling Adobe Flash Player and Adobe AIR until updates are applied.