Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation could lead to arbitrary code execution.
The product does not correctly convert an object, resource, or structure from one type to a different type.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/42480/ | exploit vdb entry third party advisory |
http://www.securitytracker.com/id/1039088 | vdb entry third party advisory broken link |
http://www.securityfocus.com/bid/100190 | vdb entry third party advisory |
https://security.gentoo.org/glsa/201709-16 | third party advisory vendor advisory |
https://access.redhat.com/errata/RHSA-2017:2457 | third party advisory vendor advisory |
https://helpx.adobe.com/security/products/flash-player/apsb17-23.html | patch vendor advisory |