CVE-2017-3085: High severity adobe flash player vulnerability
Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.
Other sources
Adobe Security Bulletin APSB17-23 for Adobe Flash Player describes a flaw that can possibly lead to information disclosure when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB17-23:
Important Security Bypass vulnerability that could lead to Information Disclosure - CVE-2017-3085
External References:
https://helpx.adobe.com/security/products/flash-player/apsb17-23.html
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3085?
CVE-2017-3085 has been rated as a high-severity vulnerability due to its risk of information disclosure.
How do I fix CVE-2017-3085?
To mitigate CVE-2017-3085, users should upgrade Adobe Flash Player to version 26.0.0.151 or later.
What versions of Adobe Flash Player are affected by CVE-2017-3085?
CVE-2017-3085 affects Adobe Flash Player versions 26.0.0.137 and earlier.
Does CVE-2017-3085 affect all operating systems?
CVE-2017-3085 primarily affects Adobe Flash Player installed on supported operating systems running the vulnerable versions.
What is the main impact of CVE-2017-3085?
The main impact of CVE-2017-3085 is the potential for unauthorized information disclosure through a URL redirect.