CVE-2018-12824: Medium severity adobe flash player vulnerability
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
Other sources
Adobe Security Bulletin APSB18-25 for Adobe Flash Player describes a flaw that can possibly lead to information disclosure when Flash Player is used to play a specially crafted SWF file:
Out-of-bounds read -- CVE-2018-12824, CVE-2018-12826, CVE-2018-12827
External References:
https://helpx.adobe.com/security/products/flash-player/apsb18-25.html
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-12824?
CVE-2018-12824 is a vulnerability in Adobe Flash Player 30.0.0.134 and earlier versions that allows for an out-of-bounds read, potentially leading to information disclosure.
How severe is CVE-2018-12824?
CVE-2018-12824 has a severity level of high with a CVSS score of 5.9.
Which software versions are affected by CVE-2018-12824?
Adobe Flash Player versions 30.0.0.134 and earlier are affected by CVE-2018-12824.
How can I fix CVE-2018-12824?
To fix CVE-2018-12824, update your Adobe Flash Player to version 30.0.0.154 or later.
Are there any references for CVE-2018-12824?
Yes, you can find more information about CVE-2018-12824 at the following links: http://www.securityfocus.com/bid/105066, http://www.securitytracker.com/id/1041448, and https://access.redhat.com/errata/RHSA-2018:2435.