First published: Wed Dec 05 2018(Updated: )
Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/flash-plugin | <32.0.0.101 | 32.0.0.101 |
Adobe Flash Player for Internet Explorer 11 | ||
All of | ||
Adobe Flash Player for Internet Explorer 11 | <=31.0.0.153 | |
Any of | ||
Apple Mac OS X | ||
Linux Kernel | ||
Microsoft Windows | ||
All of | ||
Adobe Flash Player for Internet Explorer 11 | <=31.0.0.153 | |
Any of | ||
Apple Mac OS X | ||
Google Chrome OS | ||
Linux Kernel | ||
Microsoft Windows | ||
All of | ||
Any of | ||
Adobe Flash Player for Internet Explorer 11 | <=31.0.0.153 | |
Adobe Flash Player for Internet Explorer 11 | <=31.0.0.153 | |
Any of | ||
Microsoft Windows 10 | ||
Microsoft Windows 8.1 | ||
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux workstation | =6.0 | |
All of | ||
Adobe Flash Player | <=31.0.0.108 | |
Microsoft Windows | ||
Adobe Flash Player for Internet Explorer 11 | <=31.0.0.153 | |
Apple Mac OS X | ||
Linux Kernel | ||
Microsoft Windows | ||
Adobe Flash Player for Internet Explorer 11 | <=31.0.0.153 | |
Google Chrome OS | ||
Adobe Flash Player for Internet Explorer 11 | <=31.0.0.153 | |
Adobe Flash Player for Internet Explorer 11 | <=31.0.0.153 | |
Microsoft Windows 10 | ||
Microsoft Windows 8.1 | ||
Adobe Flash Player | <=31.0.0.108 |
The impacted product is end-of-life and should be disconnected if still in use.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15982 is a use-after-free vulnerability in Adobe Flash Player.
CVE-2018-15982 has a severity rating of 9.8 out of 10, classified as critical.
Yes, Adobe Flash Player versions 31.0.0.153 and earlier, as well as 31.0.0.108 and earlier, are affected by CVE-2018-15982.
Successful exploitation of CVE-2018-15982 could lead to arbitrary code execution.
To fix CVE-2018-15982, update Adobe Flash Player to version 32.0.0.101 or later.