ID

VAR-201510-0432


CVE

CVE-2015-7648


TITLE

Adobe Flash Player and Adobe AIR Vulnerable to arbitrary code execution

Trust: 0.8

sources: JVNDB: JVNDB-2015-005344

DESCRIPTION

Adobe Flash Player before 18.0.0.255 and 19.x before 19.0.0.226 on Windows and OS X and before 11.2.202.540 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-7647. This vulnerability CVE-2015-7647 Is a different vulnerability. Supplementary information : CWE Vulnerability type by CWE-843:Access of Resource Using Incompatible Type ( Mixing of molds ) Has been identified. http://cwe.mitre.org/data/definitions/843.htmlUnspecified by attacker " Mixing of molds (type confusion)" May be used to execute arbitrary code. Failed exploit attempts will likely cause a denial-of-service condition. The product enables viewing of applications, content and video across screens and browsers. Background ========== The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Please review the CVE identifiers referenced below for details. Impact ====== A remote attacker could possibly execute arbitrary code with the privileges of the process, cause a Denial of Service condition, obtain sensitive information, or bypass security restrictions. Workaround ========== There is no known workaround at this time. Resolution ========== All Adobe Flash Player users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v ">=www-plugins/adobe-flash-11.2.202.548" References ========== [ 1 ] CVE-2015-5569 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5569 [ 2 ] CVE-2015-7625 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7625 [ 3 ] CVE-2015-7626 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7626 [ 4 ] CVE-2015-7627 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7627 [ 5 ] CVE-2015-7628 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7628 [ 6 ] CVE-2015-7629 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7629 [ 7 ] CVE-2015-7630 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7630 [ 8 ] CVE-2015-7631 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7631 [ 9 ] CVE-2015-7632 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7632 [ 10 ] CVE-2015-7633 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7633 [ 11 ] CVE-2015-7634 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7634 [ 12 ] CVE-2015-7643 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7643 [ 13 ] CVE-2015-7644 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7644 [ 14 ] CVE-2015-7645 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7645 [ 15 ] CVE-2015-7646 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7646 [ 16 ] CVE-2015-7647 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7647 [ 17 ] CVE-2015-7648 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7648 [ 18 ] CVE-2015-7651 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7651 [ 19 ] CVE-2015-7652 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7652 [ 20 ] CVE-2015-7653 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7653 [ 21 ] CVE-2015-7654 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7654 [ 22 ] CVE-2015-7655 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7655 [ 23 ] CVE-2015-7656 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7656 [ 24 ] CVE-2015-7657 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7657 [ 25 ] CVE-2015-7658 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7658 [ 26 ] CVE-2015-7659 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7659 [ 27 ] CVE-2015-7660 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7660 [ 28 ] CVE-2015-7661 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7661 [ 29 ] CVE-2015-7662 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7662 [ 30 ] CVE-2015-7663 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7663 [ 31 ] CVE-2015-8042 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8042 [ 32 ] CVE-2015-8043 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8043 [ 33 ] CVE-2015-8044 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8044 [ 34 ] CVE-2015-8046 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8046 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201511-02 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2015 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2015:1913-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2015-1913.html Issue date: 2015-10-16 CVE Names: CVE-2015-7645 CVE-2015-7647 CVE-2015-7648 ===================================================================== 1. Summary: An updated Adobe Flash Player package that fixes three security issues is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having Critical security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. These vulnerabilities, detailed in the Adobe Security Bulletin APSB15-27 listed in the References section, could allow an attacker to create a specially crafted SWF file that would cause flash-plugin to crash, execute arbitrary code, or disclose sensitive information when the victim loaded a page containing the malicious SWF content. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1271966 - CVE-2015-7645 CVE-2015-7647 CVE-2015-7648 flash-plugin: multiple code execution issue fixed in APSB15-27 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: flash-plugin-11.2.202.540-1.el6_7.i686.rpm x86_64: flash-plugin-11.2.202.540-1.el6_7.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: flash-plugin-11.2.202.540-1.el6_7.i686.rpm x86_64: flash-plugin-11.2.202.540-1.el6_7.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: flash-plugin-11.2.202.540-1.el6_7.i686.rpm x86_64: flash-plugin-11.2.202.540-1.el6_7.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-7645 https://access.redhat.com/security/cve/CVE-2015-7647 https://access.redhat.com/security/cve/CVE-2015-7648 https://access.redhat.com/security/updates/classification/#critical https://helpx.adobe.com/security/products/flash-player/apsb15-27.html 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFWIW/NXlSAg2UNWIIRApqoAJoDDP+CRbgmKdj4oKw5jnkbbFEuiQCfQZ34 X58Rs0/PxDIcNbEglTImjS8= =0kyk -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 2.34

sources: NVD: CVE-2015-7648 // JVNDB: JVNDB-2015-005344 // BID: 77116 // VULHUB: VHN-85609 // VULMON: CVE-2015-7648 // PACKETSTORM: 134414 // PACKETSTORM: 134310 // PACKETSTORM: 134007

AFFECTED PRODUCTS

vendor:adobemodel:flash playerscope:lteversion:11.2.202.535

Trust: 1.0

vendor:adobemodel:flash playerscope:lteversion:19.0.0.207

Trust: 1.0

vendor:googlemodel:chromescope: - version: -

Trust: 0.8

vendor:adobemodel:flash playerscope:ltversion:11.2.202.540 (linux)

Trust: 0.8

vendor:adobemodel:flash playerscope:ltversion:19.0.0.225 (chrome os edition chrome)

Trust: 0.8

vendor:adobemodel:flash playerscope:ltversion:19.0.0.226 (windows 10 edition microsoft edge/internet explorer 11)

Trust: 0.8

vendor:adobemodel:flash playerscope:ltversion:19.0.0.226 (windows 8.0 and 8.1 edition internet explorer 10/11)

Trust: 0.8

vendor:adobemodel:flash playerscope:ltversion:19.0.0.226 (windows/macintosh/linux edition chrome)

Trust: 0.8

vendor:adobemodel:flash playerscope:ltversion:desktop runtime 19.0.0.226 (windows/macintosh)

Trust: 0.8

vendor:adobemodel:flash playerscope:ltversion:continuous support release 18.0.0.255 (windows/macintosh)

Trust: 0.8

vendor:microsoftmodel:edgescope:eqversion:(windows 10)

Trust: 0.8

vendor:microsoftmodel:internet explorerscope:eqversion:10 (windows 8/windows server 2012/windows rt)

Trust: 0.8

vendor:microsoftmodel:internet explorerscope:eqversion:11 (windows 8.1/windows server 2012 r2/windows rt 8.1/windows 10)

Trust: 0.8

vendor:adobemodel:flash playerscope:eqversion:11.2.202.535

Trust: 0.6

vendor:adobemodel:flash playerscope:eqversion:19.0.0.207

Trust: 0.6

vendor:redmodel:hat enterprise linux workstation supplementaryscope:eqversion:6

Trust: 0.3

vendor:redmodel:hat enterprise linux supplementary serverscope:eqversion:5

Trust: 0.3

vendor:redmodel:hat enterprise linux server supplementaryscope:eqversion:6

Trust: 0.3

vendor:redmodel:hat enterprise linux desktop supplementaryscope:eqversion:6

Trust: 0.3

vendor:redmodel:hat enterprise linux desktop supplementary clientscope:eqversion:5

Trust: 0.3

vendor:gentoomodel:linuxscope: - version: -

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.53.64

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.51.66

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.0.452

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.0.3218

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.0.22.87

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.0.15.3

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.0.12.36

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.0.12.35

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.262

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.2460

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.152.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.151.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.124.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.48.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.47.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.45.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.31.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.289.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.283.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.280

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.28.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.277.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.262.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.260.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.246.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.159.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.155.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9.0.115.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:9

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:8.0.35.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:8.0.34.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:8

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.73.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.70.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.69.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.68.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.67.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.66.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.61.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.60.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.53.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.24.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7.0.19.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:7

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:6.0.79

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:6.0.21.0

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.2.202.235

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.2.202.233

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.2.202.229

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.2.202.228

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.2.202.223

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.115.8

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.115.7

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.115.6

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.112.61

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.111.9

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.111.8

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.111.7

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.111.6

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.111.5

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.102.63

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.102.62

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.102.55

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.1.102.228

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:11.0.1.152

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.186.7

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.186.6

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.186.3

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.186.2

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.185.25

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.185.23

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.185.22

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.185.21

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.183.7

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.183.5

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.183.4

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.183.10

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.181.34

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.181.26

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.181.23

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.181.22

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.181.16

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.3.181.14

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.159.1

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.157.51

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.156.12

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.154.28

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.154.27

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.154.25

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.154.24

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.154.18

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.154.13

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.153.1

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.152.33

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.152.32

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.152.21

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.2.152

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.95.2

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.95.1

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.92.8

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.92.10

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.85.3

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.82.76

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.52.15

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.52.14.1

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.106.16

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.105.6

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.102.65

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.1.102.64

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.0.42.34

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10.0.32.18

Trust: 0.3

vendor:adobemodel:flash playerscope:eqversion:10

Trust: 0.3

sources: BID: 77116 // JVNDB: JVNDB-2015-005344 // CNNVD: CNNVD-201510-319 // NVD: CVE-2015-7648

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-7648
value: HIGH

Trust: 1.0

NVD: CVE-2015-7648
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201510-319
value: CRITICAL

Trust: 0.6

VULHUB: VHN-85609
value: HIGH

Trust: 0.1

VULMON: CVE-2015-7648
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2015-7648
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-85609
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-85609 // VULMON: CVE-2015-7648 // JVNDB: JVNDB-2015-005344 // CNNVD: CNNVD-201510-319 // NVD: CVE-2015-7648

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:CWE-Other

Trust: 0.8

sources: JVNDB: JVNDB-2015-005344 // NVD: CVE-2015-7648

THREAT TYPE

remote

Trust: 0.7

sources: PACKETSTORM: 134414 // CNNVD: CNNVD-201510-319

TYPE

Unknown

Trust: 0.3

sources: BID: 77116

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-005344

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-85609 // VULMON: CVE-2015-7648

PATCH

title:APSB15-27url:https://helpx.adobe.com/security/products/flash-player/apsb15-27.html

Trust: 0.8

title:APSB15-27url:https://helpx.adobe.com/jp/security/products/flash-player/apsb15-27.html

Trust: 0.8

title:Google Chromeurl:https://www.google.com/intl/ja/chrome/browser/features.html

Trust: 0.8

title:Chrome Releasesurl:http://googlechromereleases.blogspot.jp/

Trust: 0.8

title:Google Chrome を更新するurl:https://support.google.com/chrome/answer/95414?hl=ja

Trust: 0.8

title:Update for Vulnerabilities in Adobe Flash Player in Internet Explorer and Microsoft Edge (2755801)url:https://technet.microsoft.com/en-us/library/security/2755801

Trust: 0.8

title:Internet Explorer および Microsoft Edge 上の Adobe Flash Player の脆弱性に対応する更新プログラム (2755801)url:https://technet.microsoft.com/ja-jp/library/security/2755801

Trust: 0.8

title:アドビ システムズ社 Adobe Flash Player の脆弱性に関するお知らせurl:http://www.fmworld.net/biz/common/adobe/20151020f.html

Trust: 0.8

title:Adobe Flash Player Fixes for arbitrary code execution vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=58167

Trust: 0.6

title:Red Hat: CVE-2015-7648url:https://vulmon.com/vendoradvisory?qidtp=red_hat_cve_database&qid=CVE-2015-7648

Trust: 0.1

title:CVE-Studyurl:https://github.com/thdusdl1219/CVE-Study

Trust: 0.1

title:Threatposturl:https://threatpost.com/emergency-adobe-flash-zero-day-patch-arrives-ahead-of-schedule/115073/

Trust: 0.1

sources: VULMON: CVE-2015-7648 // JVNDB: JVNDB-2015-005344 // CNNVD: CNNVD-201510-319

EXTERNAL IDS

db:NVDid:CVE-2015-7648

Trust: 3.2

db:BIDid:77116

Trust: 1.5

db:SECTRACKid:1033850

Trust: 1.2

db:EXPLOIT-DBid:38970

Trust: 1.2

db:JVNDBid:JVNDB-2015-005344

Trust: 0.8

db:CNNVDid:CNNVD-201510-319

Trust: 0.7

db:PACKETSTORMid:134809

Trust: 0.1

db:VULHUBid:VHN-85609

Trust: 0.1

db:VULMONid:CVE-2015-7648

Trust: 0.1

db:PACKETSTORMid:134414

Trust: 0.1

db:PACKETSTORMid:134310

Trust: 0.1

db:PACKETSTORMid:134007

Trust: 0.1

sources: VULHUB: VHN-85609 // VULMON: CVE-2015-7648 // BID: 77116 // JVNDB: JVNDB-2015-005344 // PACKETSTORM: 134414 // PACKETSTORM: 134310 // PACKETSTORM: 134007 // CNNVD: CNNVD-201510-319 // NVD: CVE-2015-7648

REFERENCES

url:https://helpx.adobe.com/security/products/flash-player/apsb15-27.html

Trust: 2.0

url:http://www.securityfocus.com/bid/77116

Trust: 1.3

url:https://www.exploit-db.com/exploits/38970/

Trust: 1.3

url:https://security.gentoo.org/glsa/201511-02

Trust: 1.3

url:http://rhn.redhat.com/errata/rhsa-2015-1913.html

Trust: 1.3

url:http://rhn.redhat.com/errata/rhsa-2015-2024.html

Trust: 1.3

url:http://www.securitytracker.com/id/1033850

Trust: 1.2

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-7648

Trust: 0.8

url:https://www.ipa.go.jp/security/ciadr/vul/20151015-adobeflashplayer.html

Trust: 0.8

url:https://www.jpcert.or.jp/at/2015/at150037.html

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-7648

Trust: 0.8

url:https://www.npa.go.jp/cyberpolice/topics/?seq=17064

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2015-7645

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2015-7647

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2015-7648

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2015-7633

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-5569

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-7643

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-7629

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-7631

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-7634

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-7627

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-7626

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-7644

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-7652

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-7651

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-7653

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-7632

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-7625

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-7630

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-7654

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-7628

Trust: 0.2

url:https://access.redhat.com/articles/11258

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2015-7647

Trust: 0.2

url:https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.2

url:https://bugzilla.redhat.com/):

Trust: 0.2

url:https://access.redhat.com/security/team/contact/

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2015-7648

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2015-7645

Trust: 0.2

url:https://access.redhat.com/security/updates/classification/#critical

Trust: 0.2

url:https://access.redhat.com/security/team/key/

Trust: 0.2

url:https://cwe.mitre.org/data/definitions/.html

Trust: 0.1

url:https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-7648

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://threatpost.com/emergency-adobe-flash-zero-day-patch-arrives-ahead-of-schedule/115073/

Trust: 0.1

url:http://tools.cisco.com/security/center/viewalert.x?alertid=41528

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7630

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7625

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-8043

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-7655

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7662

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7657

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7643

Trust: 0.1

url:https://security.gentoo.org/

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7659

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7648

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7660

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-8046

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7626

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7647

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7654

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-7661

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7661

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-7656

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7628

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-7657

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7633

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-8044

Trust: 0.1

url:http://creativecommons.org/licenses/by-sa/2.5

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7663

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7653

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7656

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-7659

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7644

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-7658

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7655

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7658

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-8042

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7631

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7652

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-5569

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-7660

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7645

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7646

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7632

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7634

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7651

Trust: 0.1

url:https://bugs.gentoo.org.

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7629

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-7646

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7627

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7633

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7658

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7635

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7644

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7627

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7641

Trust: 0.1

url:https://helpx.adobe.com/security/products/flash-player/apsb15-28.html

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7628

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-7642

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7653

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7661

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7639

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7659

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-7638

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7630

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7663

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7660

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7657

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7632

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7642

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7643

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7638

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-8046

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7629

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7655

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7654

Trust: 0.1

url:https://helpx.adobe.com/security/products/flash-player/apsb15-25.html

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7634

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7662

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-7635

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-8044

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-7639

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7631

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-7640

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7656

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7652

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-7636

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-7641

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7626

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-8043

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7625

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7651

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-7637

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7636

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7637

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-8042

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-7640

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2015-5569

Trust: 0.1

sources: VULHUB: VHN-85609 // VULMON: CVE-2015-7648 // JVNDB: JVNDB-2015-005344 // PACKETSTORM: 134414 // PACKETSTORM: 134310 // PACKETSTORM: 134007 // CNNVD: CNNVD-201510-319 // NVD: CVE-2015-7648

CREDITS

Natalie Silvanovich of Google Project Zero

Trust: 0.3

sources: BID: 77116

SOURCES

db:VULHUBid:VHN-85609
db:VULMONid:CVE-2015-7648
db:BIDid:77116
db:JVNDBid:JVNDB-2015-005344
db:PACKETSTORMid:134414
db:PACKETSTORMid:134310
db:PACKETSTORMid:134007
db:CNNVDid:CNNVD-201510-319
db:NVDid:CVE-2015-7648

LAST UPDATE DATE

2024-11-23T21:43:37.120000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-85609date:2017-09-13T00:00:00
db:VULMONid:CVE-2015-7648date:2017-09-13T00:00:00
db:BIDid:77116date:2016-01-12T02:05:00
db:JVNDBid:JVNDB-2015-005344date:2015-10-21T00:00:00
db:CNNVDid:CNNVD-201510-319date:2015-10-19T00:00:00
db:NVDid:CVE-2015-7648date:2024-11-21T02:37:08.487

SOURCES RELEASE DATE

db:VULHUBid:VHN-85609date:2015-10-18T00:00:00
db:VULMONid:CVE-2015-7648date:2015-10-18T00:00:00
db:BIDid:77116date:2015-10-16T00:00:00
db:JVNDBid:JVNDB-2015-005344date:2015-10-20T00:00:00
db:PACKETSTORMid:134414date:2015-11-17T17:17:12
db:PACKETSTORMid:134310date:2015-11-12T01:52:11
db:PACKETSTORMid:134007date:2015-10-18T21:06:34
db:CNNVDid:CNNVD-201510-319date:2015-10-19T00:00:00
db:NVDid:CVE-2015-7648date:2015-10-18T10:59:14.350