First published: Wed Oct 14 2015(Updated: )
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2.202.535 on Linux, Adobe AIR before 19.0.0.213, Adobe AIR SDK before 19.0.0.213, and Adobe AIR SDK & Compiler before 19.0.0.213 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-7629, CVE-2015-7631, and CVE-2015-7643.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe AIR | <=19.0.0.190 | |
Adobe AIR SDK and Compiler | <=19.0.0.190 | |
Adobe AIR SDK & Compiler | <=19.0.0.190 | |
macOS Yosemite | ||
Microsoft Windows | ||
Google Android | ||
Adobe Flash Player for Internet Explorer 11 | <=19.0.0.185 | |
Adobe Flash Player for Internet Explorer 11 | <=11.2.202.521 | |
Linux Kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7644 has a critical severity rating due to its potential to allow arbitrary code execution.
To fix CVE-2015-7644, update Adobe Flash Player and Adobe AIR to the latest versions provided by Adobe.
CVE-2015-7644 affects Adobe Flash Player versions before 18.0.0.252 and 19.x before 19.0.0.207, as well as Adobe AIR before 19.0.0.213.
Yes, using an outdated version of Adobe AIR SDK, specifically before 19.0.0.213, can make you vulnerable to CVE-2015-7644.
Yes, CVE-2015-7644 also affects Adobe Flash Player on macOS and Linux if they are of vulnerable versions.