Adobe Flash Player versions 28.0.0.161 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/103383 | broken link third party advisory vdb entry |
https://access.redhat.com/errata/RHSA-2018:0520 | third party advisory vendor advisory |
https://helpx.adobe.com/security/products/flash-player/apsb18-05.html | patch vendor advisory |
http://www.securitytracker.com/id/1040509 | broken link third party advisory vdb entry |