CVE-2018-15982: Adobe Flash Player Use-After-Free Vulnerability
Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability
Other sources
Adobe Security Bulletin APSB18-42 for Adobe Flash Player describes a flaw that can possibly lead to arbitrary code execution when Flash Player is used to play a specially crafted SWF file:
Use after free -- CVE-2018-15982
External References:
https://helpx.adobe.com/security/products/flash-player/apsb18-42.html
— Red Hat
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/flash-pluginto a version that resolves this vulnerability.Fixed in 32.0.0.101 - Remove
Remove
Adobe Flash Playerfrom your environment.If still in use, disconnect/remove the end-of-life Adobe Flash Player from the environment.
Event History
Frequently Asked Questions
What is CVE-2018-15982?
CVE-2018-15982 is a use-after-free vulnerability in Adobe Flash Player.
How severe is CVE-2018-15982?
CVE-2018-15982 has a severity rating of 9.8 out of 10, classified as critical.
Is Adobe Flash Player affected by CVE-2018-15982?
Yes, Adobe Flash Player versions 31.0.0.153 and earlier, as well as 31.0.0.108 and earlier, are affected by CVE-2018-15982.
What is the potential impact of exploiting CVE-2018-15982?
Successful exploitation of CVE-2018-15982 could lead to arbitrary code execution.
How can I fix CVE-2018-15982?
To fix CVE-2018-15982, update Adobe Flash Player to version 32.0.0.101 or later.