“Use-after-free” error in Adobe Flash Player for Linux and Adobe Flash Player - CVE-2016-7863
Published: November 8, 2016 / Updated: March 3, 2017
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a use-after-free error when processing .swf files. A remote attacker can create a specially crafted .swf file, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of the vulnerable system.
Affected software
Adobe Flash Player
Adobe Flash Player for Microsoft Windows
Gentoo Linux
Microsoft Windows
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Windows Server
How to mitigate CVE-2016-7863
External References
Related Security Bulletins
- Multiple vulnerabilities in Adobe Flash Player
- Microsoft Security Update for Adobe Flash Player
- Security Update for Adobe Flash Player (3202790)
- Gentoo update for Adobe Flash Player
- OpenSUSE Linux update for flash-player
- SUSE Linux update for flash-player
- OpenSUSE Linux update for flash-player
- Microsoft Update for Adobe Flash Player
- Red Hat update for flash-plugin