First published: Sat Mar 12 2016(Updated: )
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0987, CVE-2016-0988, CVE-2016-0991, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, and CVE-2016-1000.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | <=20.0.0.306 | |
Apple iOS and macOS | ||
Chrome OS | ||
Linux Kernel | ||
Microsoft Windows | ||
Adobe AIR SDK | <=20.0.0.233 | |
Android | ||
Adobe AIR | <=20.0.0.260 | |
Samsung X14J eu | =t-ms14jakucb-1102.5 | |
iOS | ||
Adobe Acrobat Reader | <=11.2.202.569 | |
Adobe Flash Player | <=20.2.2.306 | |
Adobe Acrobat Reader | <=20.0.0.306 | |
Microsoft Windows 10 | ||
Adobe Acrobat Reader | <=20.0.0.306 | |
Microsoft Windows 8.1 | ||
Adobe AIR | <=20.0.0.260 | |
Adobe AIR SDK & Compiler | <=20.0.0.260 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0990 has a critical severity level as it allows attackers to execute arbitrary code on affected systems.
To fix CVE-2016-0990, update Adobe Flash Player or Adobe AIR to a version that is not vulnerable, specifically versions 18.0.0.334 or later for Flash and 21.0.0.176 or later for AIR.
CVE-2016-0990 affects Adobe Flash Player before version 18.0.0.334 and 19.x through 21.x before version 21.0.0.182, along with earlier versions of Adobe AIR.
Users of Adobe Flash Player and Adobe AIR on Windows, macOS, and Linux are impacted by CVE-2016-0990 if they are running vulnerable versions.
Yes, CVE-2016-0990 is a use-after-free vulnerability that can lead to remote code execution if exploited.