Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the ActionScript2 code parser. Successful exploitation could lead to arbitrary code execution.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://security.gentoo.org/glsa/201704-04 | vendor advisory |
http://www.securitytracker.com/id/1038225 | vdb entry |
https://helpx.adobe.com/security/products/flash-player/apsb17-10.html | vendor advisory |
http://www.securityfocus.com/bid/97557 | third party advisory vdb entry |
https://access.redhat.com/errata/RHSA-2017:0934 | vendor advisory |
http://www.zerodayinitiative.com/advisories/ZDI-17-247/ | third party advisory vdb entry |