First published: Sat Apr 09 2016(Updated: )
Use-after-free vulnerability in the LoadVars.decode function in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1013, CVE-2016-1016, and CVE-2016-1031.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Flash Player | <=11.2.202.577 | |
Linux Kernel | ||
Adobe Flash Player | <=21.0.0.197 | |
Apple iOS and macOS | ||
Microsoft Windows Operating System | ||
Macromedia Flash Player | <=18.0.0.333 | |
Windows 10 | ||
Microsoft Windows | ||
Macromedia Flash Player | <=21.0.0.197 | |
Macromedia Flash Player | <=21.0.0.197 | |
Chrome OS | ||
Macromedia Flash Player | <=21.0.0.197 | |
Adobe AIR | <=21.0.0.176 | |
Adobe AIR | <=21.0.0.176 | |
iPhone OS | ||
Android | ||
Adobe AIR SDK & Compiler | <=21.0.0.176 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1017 is classified as a critical severity vulnerability that can allow attackers to execute arbitrary code.
To mitigate CVE-2016-1017, you should update Adobe Flash Player to version 18.0.0.343 or later, or to 21.0.0.213 or later.
Versions of Adobe Flash Player earlier than 18.0.0.343 and 19.x through 21.x before 21.0.0.213 are affected by CVE-2016-1017.
CVE-2016-1017 affects Adobe Flash Player on Windows, macOS, and Linux systems.
CVE-2016-1017 is a use-after-free vulnerability that can lead to arbitrary code execution.