CVE-2017-3058: Use After Free
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the sound class. Successful exploitation could lead to arbitrary code execution.
Other sources
Adobe Security Bulletin APSB17-10 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB17-10:
These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2017-3058, CVE-2017-3059, CVE-2017-3062, CVE-2017-3063).
These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2017-3060, CVE-2017-3061, CVE-2017-3064).
External References:
https://helpx.adobe.com/security/products/flash-player/apsb17-10.html
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/flash-pluginto a version that resolves this vulnerability.Fixed in 25.0.0.148 - Upgrade
Upgrade
Adobe Flash Playerto a version that resolves this vulnerability.Fixed in 25.0.0.127 - Upgrade
Upgrade
Adobe Flash Playerto a version that resolves this vulnerability.Fixed in 25.0.0.127 and earlier
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3058?
CVE-2017-3058 has a critical severity rating due to its potential for arbitrary code execution.
How do I fix CVE-2017-3058?
To fix CVE-2017-3058, upgrade Adobe Flash Player to version 25.0.0.148 or later.
What versions of Adobe Flash Player are affected by CVE-2017-3058?
Adobe Flash Player versions 25.0.0.127 and earlier are affected by CVE-2017-3058.
What type of vulnerability is CVE-2017-3058?
CVE-2017-3058 is classified as a use-after-free vulnerability.
Can CVE-2017-3058 be exploited remotely?
Yes, successful exploitation of CVE-2017-3058 may lead to remote code execution.