ID

VAR-201504-0548


CVE

CVE-2015-3043


TITLE

Adobe Flash Player Vulnerable to arbitrary code execution

Trust: 0.8

sources: JVNDB: JVNDB-2015-002247

DESCRIPTION

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042. Attacks on this vulnerability 2015 Year 4 Observed on the moon. Failed exploit attempts will likely result in denial-of-service conditions. The product enables viewing of applications, content and video across screens and browsers. The following versions are affected: Adobe Flash Player 13.0.0.277 and earlier versions and 17.0.0.134 and earlier versions based on Windows and OS X platforms, Adobe Flash Player 11.2.202.451 and earlier versions based on Linux systems. (Widely exploited in April 2015). Background ========== The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Please review the CVE identifiers referenced below for details. Workaround ========== There is no known workaround at this time. Resolution ========== All Adobe Flash Player users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v ">=www-plugins/adobe-flash-11.2.202.457" References ========== [ 1 ] CVE-2015-0346 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0346 [ 2 ] CVE-2015-0347 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0347 [ 3 ] CVE-2015-0348 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0348 [ 4 ] CVE-2015-0349 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0349 [ 5 ] CVE-2015-0350 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0350 [ 6 ] CVE-2015-0351 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0351 [ 7 ] CVE-2015-0352 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0352 [ 8 ] CVE-2015-0353 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0353 [ 9 ] CVE-2015-0354 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0354 [ 10 ] CVE-2015-0355 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0355 [ 11 ] CVE-2015-0356 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0356 [ 12 ] CVE-2015-0357 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0357 [ 13 ] CVE-2015-0358 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0358 [ 14 ] CVE-2015-0359 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0359 [ 15 ] CVE-2015-0360 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0360 [ 16 ] CVE-2015-3038 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3038 [ 17 ] CVE-2015-3039 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3039 [ 18 ] CVE-2015-3040 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3040 [ 19 ] CVE-2015-3041 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3041 [ 20 ] CVE-2015-3042 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3042 [ 21 ] CVE-2015-3043 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3043 [ 22 ] CVE-2015-3044 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3044 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201504-07 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2015 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2015:0813-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2015-0813.html Issue date: 2015-04-15 CVE Names: CVE-2015-0346 CVE-2015-0347 CVE-2015-0348 CVE-2015-0349 CVE-2015-0350 CVE-2015-0351 CVE-2015-0352 CVE-2015-0353 CVE-2015-0354 CVE-2015-0355 CVE-2015-0356 CVE-2015-0357 CVE-2015-0358 CVE-2015-0359 CVE-2015-0360 CVE-2015-3038 CVE-2015-3039 CVE-2015-3040 CVE-2015-3041 CVE-2015-3042 CVE-2015-3043 CVE-2015-3044 ===================================================================== 1. Summary: An updated Adobe Flash Player package that fixes multiple security issues is now available for Red Hat Enterprise Linux 5 and 6 Supplementary. Red Hat Product Security has rated this update as having Critical security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash Player web browser plug-in. These vulnerabilities are detailed in the Adobe Security Bulletin APSB15-06 listed in the References section. Multiple flaws were found in the way flash-plugin displayed certain SWF content. An attacker could use these flaws to create a specially crafted SWF file that would cause flash-plugin to crash or, potentially, execute arbitrary code when the victim loaded a page containing the malicious SWF content. (CVE-2015-0346, CVE-2015-0347, CVE-2015-0348, CVE-2015-0349, CVE-2015-0350, CVE-2015-0351, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0356, CVE-2015-0358, CVE-2015-0359, CVE-2015-0360, CVE-2015-3038, CVE-2015-3039, CVE-2015-3041, CVE-2015-3042, CVE-2015-3043) A security bypass flaw was found in flash-plugin that could lead to the disclosure of sensitive information. (CVE-2015-3044) Two memory information leak flaws were found in flash-plugin that could allow an attacker to potentially bypass ASLR (Address Space Layout Randomization) protection, and make it easier to exploit other flaws. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1211869 - flash-plugin: multiple code execution issues fixed in APSB15-06 1211894 - CVE-2015-3044 flash-plugin: security bypass leading to information disclosure (APSB15-06) 1211898 - CVE-2015-0357 CVE-2015-3040 flash-plugin: information leaks leading to ASLR bypass (APSB15-06) 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 5): i386: flash-plugin-11.2.202.457-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.457-1.el5.i386.rpm Red Hat Enterprise Linux Server Supplementary (v. 5): i386: flash-plugin-11.2.202.457-1.el5.i386.rpm x86_64: flash-plugin-11.2.202.457-1.el5.i386.rpm Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-11.2.202.457-1.el6_6.i686.rpm x86_64: flash-plugin-11.2.202.457-1.el6_6.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-11.2.202.457-1.el6_6.i686.rpm x86_64: flash-plugin-11.2.202.457-1.el6_6.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-11.2.202.457-1.el6_6.i686.rpm x86_64: flash-plugin-11.2.202.457-1.el6_6.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-0346 https://access.redhat.com/security/cve/CVE-2015-0347 https://access.redhat.com/security/cve/CVE-2015-0348 https://access.redhat.com/security/cve/CVE-2015-0349 https://access.redhat.com/security/cve/CVE-2015-0350 https://access.redhat.com/security/cve/CVE-2015-0351 https://access.redhat.com/security/cve/CVE-2015-0352 https://access.redhat.com/security/cve/CVE-2015-0353 https://access.redhat.com/security/cve/CVE-2015-0354 https://access.redhat.com/security/cve/CVE-2015-0355 https://access.redhat.com/security/cve/CVE-2015-0356 https://access.redhat.com/security/cve/CVE-2015-0357 https://access.redhat.com/security/cve/CVE-2015-0358 https://access.redhat.com/security/cve/CVE-2015-0359 https://access.redhat.com/security/cve/CVE-2015-0360 https://access.redhat.com/security/cve/CVE-2015-3038 https://access.redhat.com/security/cve/CVE-2015-3039 https://access.redhat.com/security/cve/CVE-2015-3040 https://access.redhat.com/security/cve/CVE-2015-3041 https://access.redhat.com/security/cve/CVE-2015-3042 https://access.redhat.com/security/cve/CVE-2015-3043 https://access.redhat.com/security/cve/CVE-2015-3044 https://access.redhat.com/security/updates/classification/#critical https://helpx.adobe.com/security/products/flash-player/apsb15-06.html 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFVLmOuXlSAg2UNWIIRAhCpAKCQYartNTxOyN7YneEoLHmonLVYxwCeJeZL 9gBkw1TFVgaSAtPj0Xh+ubg= =LVW2 -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 2.25

sources: NVD: CVE-2015-3043 // JVNDB: JVNDB-2015-002247 // BID: 74062 // VULHUB: VHN-81004 // VULMON: CVE-2015-3043 // PACKETSTORM: 131493 // PACKETSTORM: 131451

AFFECTED PRODUCTS

vendor:redhatmodel:enterprise linux serverscope:eqversion:5.0

Trust: 1.0

vendor:opensusemodel:evergreenscope:eqversion:11.4

Trust: 1.0

vendor:adobemodel:flash playerscope:ltversion:17.0.0.169

Trust: 1.0

vendor:opensusemodel:opensusescope:eqversion:13.2

Trust: 1.0

vendor:redhatmodel:enterprise linux serverscope:eqversion:6.0

Trust: 1.0

vendor:redhatmodel:enterprise linux server from rhuiscope:eqversion:5.0

Trust: 1.0

vendor:redhatmodel:enterprise linux workstationscope:eqversion:6.0

Trust: 1.0

vendor:redhatmodel:enterprise linux eusscope:eqversion:6.6

Trust: 1.0

vendor:redhatmodel:enterprise linux server from rhuiscope:eqversion:6.0

Trust: 1.0

vendor:opensusemodel:opensusescope:eqversion:13.1

Trust: 1.0

vendor:adobemodel:flash playerscope:ltversion:11.2.202.457

Trust: 1.0

vendor:adobemodel:flash playerscope:ltversion:13.0.0.281

Trust: 1.0

vendor:novellmodel:suse linux enterprise workstation extensionscope:eqversion:12.0

Trust: 1.0

vendor:adobemodel:flash playerscope:gteversion:14.0.0.125

Trust: 1.0

vendor:redhatmodel:enterprise linux desktopscope:eqversion:6.0

Trust: 1.0

vendor:redhatmodel:enterprise linux server ausscope:eqversion:6.6

Trust: 1.0

vendor:redhatmodel:enterprise linux desktopscope:eqversion:5.0

Trust: 1.0

vendor:novellmodel:suse linux enterprise desktopscope:eqversion:12.0

Trust: 1.0

vendor:novellmodel:suse linux enterprise desktopscope:eqversion:11.0

Trust: 1.0

vendor:redhatmodel:enterprise linux workstationscope:eqversion:5.0

Trust: 1.0

vendor:googlemodel:chromescope: - version: -

Trust: 0.8

vendor:adobemodel:flash playerscope:ltversion:11.2.202.457 (linux)

Trust: 0.8

vendor:adobemodel:flash playerscope:ltversion:17.0.0.169 (internet explorer 10/11)

Trust: 0.8

vendor:adobemodel:flash playerscope:ltversion:17.0.0.169 (windows/machintosh/linux edition chrome)

Trust: 0.8

vendor:adobemodel:flash playerscope:ltversion:desktop runtime 17.0.0.169 (windows/macintosh)

Trust: 0.8

vendor:adobemodel:flash playerscope:ltversion:continuous support release 13.0.0.281 (windows/macintosh)

Trust: 0.8

vendor:microsoftmodel:internet explorerscope:eqversion:10 (windows 8/windows server 2012/windows rt)

Trust: 0.8

vendor:microsoftmodel:internet explorerscope:eqversion:11 (windows 8.1/windows server 2012 r2/windows rt 8.1)

Trust: 0.8

vendor:redhatmodel:enterprise linux server supplementaryscope:eqversion:6.0

Trust: 0.6

vendor:redhatmodel:enterprise linux desktop supplementaryscope:eqversion:6.0

Trust: 0.6

vendor:redhatmodel:enterprise linux workstation supplementaryscope:eqversion:6.0

Trust: 0.6

vendor:redhatmodel:enterprise linux server supplementary eusscope:eqversion:6.6.z

Trust: 0.6

vendor:redhatmodel:enterprise linux desktop supplementaryscope:eqversion:5.0

Trust: 0.6

vendor:redhatmodel:enterprise linux supplementaryscope:eqversion:5.0

Trust: 0.6

vendor:redmodel:hat enterprise linux workstation supplementaryscope:eqversion:6

Trust: 0.3

vendor:redmodel:hat enterprise linux supplementary serverscope:eqversion:5

Trust: 0.3

vendor:redmodel:hat enterprise linux server supplementaryscope:eqversion:6

Trust: 0.3

vendor:redmodel:hat enterprise linux desktop supplementaryscope:eqversion:6

Trust: 0.3

vendor:redmodel:hat enterprise linux desktop supplementary clientscope:eqversion:5

Trust: 0.3

vendor:gentoomodel:linuxscope: - version: -

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.53.64

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.51.66

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.0.452

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.0.3218

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.0.22.87

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.0.15.3

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.0.12.36

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.0.12.35

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.262

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.2460

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.152.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.151.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.124.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.48.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.47.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.45.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.31.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.289.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.283.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.280

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.28.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.277.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.262.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.260.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.246.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.159.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.155.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.115.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:8.0.35.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:8.0.34.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:8

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.73.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.70.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.69.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.68.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.67.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.66.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.61.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.60.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.53.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.24.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.19.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.14.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:6.0.79

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:6.0.21.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.2.202.235

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.2.202.233

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.2.202.229

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.2.202.228

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.2.202.223

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.115.8

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.115.7

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.115.6

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.112.61

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.111.9

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.111.8

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.111.7

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.111.6

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.111.5

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.102.63

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.102.62

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.102.55

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.102.228

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.0.1.152

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.186.7

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.186.6

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.186.3

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.186.2

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.185.25

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.185.23

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.185.22

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.185.21

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.183.7

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.183.5

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.183.4

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.183.10

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.181.34

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.181.26

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.181.23

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.181.22

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.181.16

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.181.14

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.159.1

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.157.51

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.156.12

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.154.28

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.154.27

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.154.25

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.154.24

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.154.18

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.154.13

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.153.1

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.152.33

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.152.32

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.152.21

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.152

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.95.2

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.95.1

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.92.8

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.92.10

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.85.3

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.82.76

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.52.15

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.52.14.1

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.106.16

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.105.6

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.102.65

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.102.64

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.0.42.34

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.0.32.18

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10

Trust: 0.3

sources: BID: 74062 // JVNDB: JVNDB-2015-002247 // CNNVD: CNNVD-201504-209 // NVD: CVE-2015-3043

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-3043
value: CRITICAL

Trust: 1.0

NVD: CVE-2015-3043
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201504-209
value: CRITICAL

Trust: 0.6

VULHUB: VHN-81004
value: HIGH

Trust: 0.1

VULMON: CVE-2015-3043
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2015-3043
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-81004
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2015-3043
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: VULHUB: VHN-81004 // VULMON: CVE-2015-3043 // JVNDB: JVNDB-2015-002247 // CNNVD: CNNVD-201504-209 // NVD: CVE-2015-3043

PROBLEMTYPE DATA

problemtype:CWE-787

Trust: 1.0

sources: NVD: CVE-2015-3043

THREAT TYPE

remote

Trust: 0.7

sources: PACKETSTORM: 131493 // CNNVD: CNNVD-201504-209

TYPE

Unknown

Trust: 0.3

sources: BID: 74062

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-002247

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-81004 // VULMON: CVE-2015-3043

PATCH

title:APSB15-06url:http://helpx.adobe.com/security/products/flash-player/apsb15-06.html

Trust: 0.8

title:APSB15-06url:http://helpx.adobe.com/jp/security/products/flash-player/apsb15-06.html

Trust: 0.8

title:Google Chrome を更新するurl:https://support.google.com/chrome/answer/95414?hl=ja

Trust: 0.8

title:Google Chromeurl:https://www.google.com/intl/ja/chrome/browser/features.html

Trust: 0.8

title:Chrome Releasesurl:http://googlechromereleases.blogspot.jp/

Trust: 0.8

title:Update for Vulnerabilities in Adobe Flash Player in Internet Explorer (2755801)url:https://technet.microsoft.com/en-us/library/security/2755801

Trust: 0.8

title:Internet Explorer 上の Adobe Flash Player の脆弱性に対応する更新プログラム (2755801)url:https://technet.microsoft.com/ja-jp/library/security/2755801

Trust: 0.8

title:アドビ システムズ社 Adobe Flash Player の脆弱性に関するお知らせurl:http://www.fmworld.net/biz/common/adobe/20150416f.html

Trust: 0.8

title:Red Hat: CVE-2015-3043url:https://vulmon.com/vendoradvisory?qidtp=red_hat_cve_database&qid=CVE-2015-3043

Trust: 0.1

title:CVE-Studyurl:https://github.com/thdusdl1219/CVE-Study

Trust: 0.1

title:The Registerurl:https://www.theregister.co.uk/2015/04/20/russian_cyberspies_two_zero_days/

Trust: 0.1

title:The Registerurl:https://www.theregister.co.uk/2015/04/15/april_patch_tuesday/

Trust: 0.1

title:Threatposturl:https://threatpost.com/microsoft-patches-critical-http-sys-vulnerability/112251/

Trust: 0.1

sources: VULMON: CVE-2015-3043 // JVNDB: JVNDB-2015-002247

EXTERNAL IDS

db:NVDid:CVE-2015-3043

Trust: 3.1

db:BIDid:74062

Trust: 1.5

db:EXPLOIT-DBid:37536

Trust: 1.2

db:SECTRACKid:1032105

Trust: 1.2

db:JVNDBid:JVNDB-2015-002247

Trust: 0.8

db:CNNVDid:CNNVD-201504-209

Trust: 0.7

db:PACKETSTORMid:132525

Trust: 0.1

db:VULHUBid:VHN-81004

Trust: 0.1

db:VULMONid:CVE-2015-3043

Trust: 0.1

db:PACKETSTORMid:131493

Trust: 0.1

db:PACKETSTORMid:131451

Trust: 0.1

sources: VULHUB: VHN-81004 // VULMON: CVE-2015-3043 // BID: 74062 // JVNDB: JVNDB-2015-002247 // PACKETSTORM: 131493 // PACKETSTORM: 131451 // CNNVD: CNNVD-201504-209 // NVD: CVE-2015-3043

REFERENCES

url:https://helpx.adobe.com/security/products/flash-player/apsb15-06.html

Trust: 1.9

url:https://www.exploit-db.com/exploits/37536/

Trust: 1.3

url:https://security.gentoo.org/glsa/201504-07

Trust: 1.3

url:http://rhn.redhat.com/errata/rhsa-2015-0813.html

Trust: 1.3

url:http://www.securityfocus.com/bid/74062

Trust: 1.2

url:http://www.securitytracker.com/id/1032105

Trust: 1.2

url:http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00011.html

Trust: 1.2

url:http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00012.html

Trust: 1.2

url:http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00010.html

Trust: 1.2

url:http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.html

Trust: 1.2

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-3043

Trust: 0.8

url:http://www.ipa.go.jp/security/ciadr/vul/20150415-adobeflashplayer.html

Trust: 0.8

url:http://www.jpcert.or.jp/at/2015/at150011.html

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-3043

Trust: 0.8

url:http://www.npa.go.jp/cyberpolice/topics/?seq=16044

Trust: 0.8

url:http://www.adobe.com

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2015-0350

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-0348

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-0353

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-0352

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-0356

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-3043

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-0355

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-3040

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-3042

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-0357

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-0347

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-0354

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-0349

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-0360

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-0358

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-3044

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-0351

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-0346

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-3041

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-3039

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-0359

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-3038

Trust: 0.2

url:https://cwe.mitre.org/data/definitions/.html

Trust: 0.1

url:http://tools.cisco.com/security/center/viewalert.x?alertid=41243

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://threatpost.com/microsoft-patches-critical-http-sys-vulnerability/112251/

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-0357

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-3042

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-3043

Trust: 0.1

url:https://security.gentoo.org/

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-0360

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-0346

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-0347

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-0352

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-0350

Trust: 0.1

url:http://creativecommons.org/licenses/by-sa/2.5

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-0348

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-0358

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-0355

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-0354

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-0349

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-3041

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-0351

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-3039

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-0356

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-3038

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-3040

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-0353

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-3044

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-0359

Trust: 0.1

url:https://bugs.gentoo.org.

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-0359

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-3043

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-0350

Trust: 0.1

url:https://access.redhat.com/security/updates/classification/#critical

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-0349

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-0348

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-0354

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-0357

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-0347

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-0346

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-3044

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-3042

Trust: 0.1

url:https://access.redhat.com/articles/11258

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-0352

Trust: 0.1

url:https://access.redhat.com/security/team/contact/

Trust: 0.1

url:https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-3038

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-3039

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-0356

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-0351

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-3041

Trust: 0.1

url:https://bugzilla.redhat.com/):

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-3040

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-0358

Trust: 0.1

url:https://access.redhat.com/security/team/key/

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-0353

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-0360

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-0355

Trust: 0.1

sources: VULHUB: VHN-81004 // VULMON: CVE-2015-3043 // BID: 74062 // JVNDB: JVNDB-2015-002247 // PACKETSTORM: 131493 // PACKETSTORM: 131451 // CNNVD: CNNVD-201504-209 // NVD: CVE-2015-3043

CREDITS

s3tm3m, working with HP's Zero Day Initiative, Steven Vittitoe of Google Project Zero, Chris Evans of Google Project, instruder of Alibaba Security Research Team, Jihui Lu of KeenTeam (@K33nTeam), working with the Chromium Vulnerability Reward Program, Mic

Trust: 0.3

sources: BID: 74062

SOURCES

db:VULHUBid:VHN-81004
db:VULMONid:CVE-2015-3043
db:BIDid:74062
db:JVNDBid:JVNDB-2015-002247
db:PACKETSTORMid:131493
db:PACKETSTORMid:131451
db:CNNVDid:CNNVD-201504-209
db:NVDid:CVE-2015-3043

LAST UPDATE DATE

2024-11-23T20:53:56.439000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-81004date:2018-10-30T00:00:00
db:VULMONid:CVE-2015-3043date:2018-10-30T00:00:00
db:BIDid:74062date:2015-11-03T19:09:00
db:JVNDBid:JVNDB-2015-002247date:2015-04-22T00:00:00
db:CNNVDid:CNNVD-201504-209date:2015-04-15T00:00:00
db:NVDid:CVE-2015-3043date:2024-11-21T02:28:32.663

SOURCES RELEASE DATE

db:VULHUBid:VHN-81004date:2015-04-14T00:00:00
db:VULMONid:CVE-2015-3043date:2015-04-14T00:00:00
db:BIDid:74062date:2015-04-14T00:00:00
db:JVNDBid:JVNDB-2015-002247date:2015-04-16T00:00:00
db:PACKETSTORMid:131493date:2015-04-19T17:34:12
db:PACKETSTORMid:131451date:2015-04-16T04:28:51
db:CNNVDid:CNNVD-201504-209date:2015-04-15T00:00:00
db:NVDid:CVE-2015-3043date:2015-04-14T22:59:21.323