Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors.
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/98932 | vdb entry third party advisory |
https://www.f-secure.com/weblog/archives/00002768.html | third party advisory |
http://www.securitytracker.com/id/1031259 | vdb entry third party advisory |
http://lists.opensuse.org/opensuse-security-announce/2014-12/msg00004.html | third party advisory vendor advisory |
http://www.securityfocus.com/bid/71289 | vdb entry third party advisory |
http://secunia.com/advisories/60217 | third party advisory permissions required |
http://lists.opensuse.org/opensuse-security-announce/2014-12/msg00001.html | third party advisory vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00020.html | third party advisory vendor advisory |
http://rhn.redhat.com/errata/RHSA-2014-1915.html | vendor advisory |
http://helpx.adobe.com/security/products/flash-player/apsb14-22.html | vendor advisory |
http://helpx.adobe.com/security/products/flash-player/apsb14-26.html | vendor advisory |