First published: Sun Oct 18 2015(Updated: )
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2.202.535 on Linux, Adobe AIR before 19.0.0.213, Adobe AIR SDK before 19.0.0.213, and Adobe AIR SDK & Compiler before 19.0.0.213 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-7629, CVE-2015-7631, CVE-2015-7635, CVE-2015-7636, CVE-2015-7637, CVE-2015-7638, CVE-2015-7639, CVE-2015-7640, CVE-2015-7642, CVE-2015-7643, and CVE-2015-7644.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Flash Player | <=19.0.0.185 | |
Apple iOS and macOS | ||
Microsoft Windows Operating System | ||
Macromedia Flash Player | <=11.2.202.521 | |
Linux Kernel | ||
Adobe | <=19.0.0.190 | |
Android | ||
Adobe AIR | <=19.0.0.190 | |
Adobe AIR SDK & Compiler | <=19.0.0.190 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7641 is considered critical due to the potential for arbitrary code execution.
To fix CVE-2015-7641, upgrade Adobe Flash Player and Adobe AIR to the latest versions released after the vulnerabilities were identified.
Affected versions include Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207.
Yes, CVE-2015-7641 can potentially exploit applications built with Adobe AIR versions prior to 19.0.0.213.
CVE-2015-7641 affects multiple platforms including Windows, OS X, and Linux distributions that run vulnerable versions of Adobe's software.