CVE-2018-5002: Adobe Flash Player Stack-based Buffer Overflow Vulnerability
Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution.
Other sources
Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
— NVD
Adobe Security Bulletin APSB18-19 for Adobe Flash Player describes a flaw that can possibly lead to arbitrary code execution when Flash Player is used to play a specially crafted SWF file:
Stack-based buffer overflow -- CVE-2018-5002
External References:
https://helpx.adobe.com/security/products/flash-player/apsb18-19.html
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/flash-pluginto a version that resolves this vulnerability.Fixed in 30.0.0.113 - Compensating control
Disconnect or otherwise isolate the impacted Adobe/Macromedia Flash Player installations from networks/systems if still in use (the impacted product is end-of-life and should be disconnected).
Event History
Frequently Asked Questions
What is CVE-2018-5002?
CVE-2018-5002 is a Stack-based Buffer Overflow vulnerability in Adobe Flash Player.
What is the severity of CVE-2018-5002?
The severity of CVE-2018-5002 is critical, with a severity score of 9.8.
How does CVE-2018-5002 affect Adobe Flash Player?
CVE-2018-5002 affects Adobe Flash Player versions 29.0.0.171 and earlier.
How can CVE-2018-5002 be exploited?
Successful exploitation of CVE-2018-5002 could lead to arbitrary code execution in the context of the current user.
How can I fix CVE-2018-5002?
To fix CVE-2018-5002, update Adobe Flash Player to version 30.0.0.113.