CVE-2018-5002
09.07.2018, 19:29
Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.Enginsight
| Vendor | Product | Version |
|---|---|---|
| adobe | flash_player_desktop_runtime | 𝑥 ≤ 29.0.0.171 |
| adobe | flash_player | 𝑥 ≤ 29.0.0.171 |
| adobe | flash_player | 𝑥 ≤ 29.0.0.171 |
| adobe | flash_player | 𝑥 ≤ 29.0.0.171 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_workstation | 6.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| adobe-flashplugin |
| ||||||||
| flashplugin-nonfree |
|
Common Weakness Enumeration
- CWE-787 - Out-of-bounds WriteThe software writes data past the end, or before the beginning, of the intended buffer.
- CWE-121 - Stack-based Buffer OverflowA stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
References