CVE-2018-4932: Use After Free
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Use-After-Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Other sources
Adobe Security Bulletin APSB18-08 for Adobe Flash Player describes multiple flaws that can possibly lead to remote code execution when Flash Player is used to play a specially crafted SWF file:
Out-of-bounds write -- CVE-2018-4935, CVE-2018-4937 Use-After-Free -- CVE-2018-4932
External References:
https://helpx.adobe.com/security/products/flash-player/apsb18-08.html
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-4932?
CVE-2018-4932 is a vulnerability in Adobe Flash Player versions 29.0.0.113 and earlier, allowing for arbitrary code execution.
How severe is CVE-2018-4932?
CVE-2018-4932 has a severity value of 8.8, which is considered critical.
Which software versions are affected by CVE-2018-4932?
Adobe Flash Player versions 29.0.0.113 and earlier are affected by CVE-2018-4932.
How can I fix CVE-2018-4932?
To fix CVE-2018-4932, update Adobe Flash Player to version 29.0.0.140 or later.
Where can I find more information about CVE-2018-4932?
You can find more information about CVE-2018-4932 at the following references: [http://www.securityfocus.com/bid/103708](http://www.securityfocus.com/bid/103708), [http://www.securitytracker.com/id/1040648](http://www.securitytracker.com/id/1040648), [https://access.redhat.com/errata/RHSA-2018:1119](https://access.redhat.com/errata/RHSA-2018:1119).