First published: Sun Oct 18 2015(Updated: )
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2.202.535 on Linux, Adobe AIR before 19.0.0.213, Adobe AIR SDK before 19.0.0.213, and Adobe AIR SDK & Compiler before 19.0.0.213 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-7629, CVE-2015-7631, CVE-2015-7635, CVE-2015-7636, CVE-2015-7637, CVE-2015-7638, CVE-2015-7639, CVE-2015-7641, CVE-2015-7642, CVE-2015-7643, and CVE-2015-7644.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Flash Player | <=11.2.202.521 | |
Linux Kernel | ||
Macromedia Flash Player | <=19.0.0.185 | |
Apple iOS and macOS | ||
Microsoft Windows Operating System | ||
Adobe | <=19.0.0.190 | |
Android | ||
Adobe AIR | <=19.0.0.190 | |
Adobe AIR SDK & Compiler | <=19.0.0.190 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7640 is classified as a critical severity vulnerability due to its potential for remote code execution.
To fix CVE-2015-7640, update Adobe Flash Player and Adobe AIR to the latest versions beyond 18.0.0.252 or 19.x 19.0.0.207.
Adobe Flash Player versions prior to 18.0.0.252 and 19.x versions before 19.0.0.207 are affected by CVE-2015-7640.
Yes, Adobe AIR versions before 19.0.0.213 are also vulnerable to CVE-2015-7640.
CVE-2015-7640 affects Adobe Flash Player on Windows, OS X, and Linux platforms.