Vulnerability Description
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Flash Player | >= 18.0.0.160, <= 18.0.0.252 |
| Apple | Mac Os X | - |
| Microsoft | Windows | - |
| Linux | Linux Kernel | - |
| Opensuse | Evergreen | 11.4 |
| Opensuse | Opensuse | 13.1 |
| Suse | Linux Enterprise Desktop | 11 |
| Suse | Linux Enterprise Workstation Extension | 12 |
| Redhat | Enterprise Linux Desktop | 5.0 |
| Redhat | Enterprise Linux Eus | 6.7 |
| Redhat | Enterprise Linux Server | 5.0 |
| Redhat | Enterprise Linux Server From Rhui | 5.0 |
| Redhat | Enterprise Linux Workstation | 5.0 |
References
- http://blog.trendmicro.com/trendlabs-security-intelligence/new-adobe-flash-zero-Broken Link
- http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00015.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00016.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00017.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00018.htmlMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/134009/Adobe-Flash-IExternalizable.writeExtThird Party AdvisoryVDB Entry
- http://rhn.redhat.com/errata/RHSA-2015-1913.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-2024.htmlThird Party Advisory
- http://www.securityfocus.com/bid/77081Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1033850Broken LinkThird Party AdvisoryVDB Entry
- https://helpx.adobe.com/security/products/flash-player/apsa15-05.htmlBroken LinkPatchVendor Advisory
- https://helpx.adobe.com/security/products/flash-player/apsb15-27.htmlBroken Link
- https://security.gentoo.org/glsa/201511-02Third Party Advisory
- https://www.exploit-db.com/exploits/38490/Third Party AdvisoryVDB Entry
- http://blog.trendmicro.com/trendlabs-security-intelligence/new-adobe-flash-zero-Broken Link
FAQ
What is CVE-2015-7645?
CVE-2015-7645 is a vulnerability with a CVSS score of 7.8 (HIGH). Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF fi...
How severe is CVE-2015-7645?
CVE-2015-7645 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-7645?
Check the references section above for vendor advisories and patch information. Affected products include: Adobe Flash Player, Apple Mac Os X, Microsoft Windows, Linux Linux Kernel, Opensuse Evergreen.