First published: Sat Dec 09 2017(Updated: )
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of AdobePSDK metadata. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Enterprise Linux Desktop | =6.0 | |
Redhat Enterprise Linux Server | =6.0 | |
Redhat Enterprise Linux Workstation | =6.0 | |
Adobe Flash Player | <=27.0.0.183 | |
Apple macOS | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Adobe Flash Player | <=27.0.0.183 | |
Google Chrome OS | ||
Adobe Flash Player | <=27.0.0.183 | |
Adobe Flash Player | <=27.0.0.183 | |
Microsoft Windows 10 | ||
Microsoft Windows 8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3112 is a vulnerability in Adobe Flash Player 27.0.0.183 and earlier versions that occurs as a result of a computation that reads data past the end of the target buffer.
The severity of CVE-2017-3112 is critical with a CVSS score of 9.8.
Adobe Flash Player 27.0.0.183 and earlier versions running on Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server, and Redhat Enterprise Linux Workstation are affected by CVE-2017-3112.
To fix CVE-2017-3112, update Adobe Flash Player to the latest version provided by Adobe.
More information about CVE-2017-3112 can be found at the following references: [1] [2] [3].