CVE-2018-4945: Incorrect Type Cast
Adobe Flash Player versions 29.0.0.171 and earlier have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Other sources
Adobe Security Bulletin APSB18-19 for Adobe Flash Player describes a flaw that can possibly lead to arbitrary code execution when Flash Player is used to play a specially crafted SWF file:
Type Confusion -- CVE-2018-4945
External References:
https://helpx.adobe.com/security/products/flash-player/apsb18-19.html
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-4945?
CVE-2018-4945 is a Type Confusion vulnerability in Adobe Flash Player versions 29.0.0.171 and earlier.
What is the severity of CVE-2018-4945?
CVE-2018-4945 has a severity rating of 8.8 (high).
How can CVE-2018-4945 be exploited?
Exploiting CVE-2018-4945 can lead to arbitrary code execution in the context of the current user.
How can I fix CVE-2018-4945?
To fix CVE-2018-4945, update Adobe Flash Player to version 30.0.0.113.
Where can I find more information about CVE-2018-4945?
You can find more information about CVE-2018-4945 on the following websites: [1] http://www.securityfocus.com/bid/104413 [2] http://www.securitytracker.com/id/1041058 [3] https://access.redhat.com/errata/RHSA-2018:1827