CVE Vulnerabilities

CVE-2017-3106

Incorrect Type Conversion or Cast

Published: Aug 11, 2017 | Modified: Apr 20, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
8.8 CRITICAL
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation could lead to arbitrary code execution.

Weakness

The product does not correctly convert an object, resource, or structure from one type to a different type.

Affected Software

NameVendorStart VersionEnd Version
Enterprise_linuxRedhat6.0 (including)6.0 (including)
Enterprise_linux_desktopRedhat6.0 (including)6.0 (including)
Enterprise_linux_workstationRedhat6.0 (including)6.0 (including)
Red Hat Enterprise Linux 6 SupplementaryRedHatflash-plugin-0:26.0.0.151-1.el6_9*
Adobe-flashpluginUbuntudevel*
Adobe-flashpluginUbuntutrusty*
Adobe-flashpluginUbuntuupstream*
Adobe-flashpluginUbuntuxenial*
Adobe-flashpluginUbuntuzesty*
Flashplugin-nonfreeUbuntudevel*
Flashplugin-nonfreeUbuntuesm-apps/xenial*
Flashplugin-nonfreeUbuntutrusty*
Flashplugin-nonfreeUbuntuupstream*
Flashplugin-nonfreeUbuntuxenial*
Flashplugin-nonfreeUbuntuzesty*

References