Heap-based buffer overflow vulnerability in Adobe Flash Player or Adobe AIR via an MP3 file with COMM tags that are mishandled during memory allocationID: oval:org.secpod.oval:def:31857 | Date: (C)2015-12-16 (M)2024-03-06 |
Class: VULNERABILITY | Family: windows |
The host is installed with Adobe Flash Player before 18.0.0.268, 19.x, 20.x before 20.0.0.228 or Adobe AIR before 20.0.0.204 and is prone to a heap-based buffer overflow vulnerability. A flaw is present in the applications, which fail to properly handle an MP3 file with COMM tags that are mishandled during memory allocation. Successful exploitation could allow attackers to execute arbitrary code.
Platform: |
Microsoft Windows 11 |
Microsoft Windows Server 2022 |
Microsoft Windows Server 2019 |
Microsoft Windows XP |
Microsoft Windows 7 |
Microsoft Windows 10 |
Microsoft Windows 8 |
Microsoft Windows Server 2016 |
Microsoft Windows 8.1 |
Microsoft Windows Server 2003 |
Microsoft Windows Server 2008 |
Microsoft Windows Server 2012 |
Microsoft Windows Server 2008 R2 |
Microsoft Windows Server 2012 R2 |
Microsoft Windows Vista |
Product: |
Adobe Flash Player |
Adobe AIR |
Microsoft Internet Explorer 10 |
Microsoft Internet Explorer 11 |
Microsoft Edge |