The SharedObject object implementation in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code by leveraging an unspecified type confusion during a getRemote call, a different vulnerability than CVE-2015-8456.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Air_sdk | Adobe | * | 19.0.0.241 (including) |
Air_sdk_&_compiler | Adobe | * | 19.0.0.241 (including) |
Red Hat Enterprise Linux 5 Supplementary | RedHat | flash-plugin-0:11.2.202.554-1.el5 | * |
Red Hat Enterprise Linux 6 Supplementary | RedHat | flash-plugin-0:11.2.202.554-1.el6_7 | * |
Adobe-flashplugin | Ubuntu | precise | * |
Adobe-flashplugin | Ubuntu | trusty | * |
Adobe-flashplugin | Ubuntu | upstream | * |
Adobe-flashplugin | Ubuntu | vivid | * |
Adobe-flashplugin | Ubuntu | wily | * |
Flashplugin-nonfree | Ubuntu | devel | * |
Flashplugin-nonfree | Ubuntu | precise | * |
Flashplugin-nonfree | Ubuntu | trusty | * |
Flashplugin-nonfree | Ubuntu | upstream | * |
Flashplugin-nonfree | Ubuntu | vivid | * |
Flashplugin-nonfree | Ubuntu | wily | * |