Vulnerability Description
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of AdobePSDK metadata. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Enterprise Linux Desktop | 6.0 |
| Redhat | Enterprise Linux Server | 6.0 |
| Redhat | Enterprise Linux Workstation | 6.0 |
| Adobe | Flash Player | <= 27.0.0.183 |
| Apple | Macos | - |
| Linux | Linux Kernel | - |
| Microsoft | Windows | - |
| Chrome Os | - | |
| Microsoft | Windows 10 | - |
| Microsoft | Windows 8.1 | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/101837Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039778Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:3222Third Party AdvisoryVDB Entry
- https://helpx.adobe.com/security/products/flash-player/apsb17-33.htmlPatchVendor Advisory
- https://security.gentoo.org/glsa/201711-13Third Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/101837Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039778Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:3222Third Party AdvisoryVDB Entry
- https://helpx.adobe.com/security/products/flash-player/apsb17-33.htmlPatchVendor Advisory
- https://security.gentoo.org/glsa/201711-13Third Party AdvisoryVDB Entry
FAQ
What is CVE-2017-3112?
CVE-2017-3112 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the com...
How severe is CVE-2017-3112?
CVE-2017-3112 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-3112?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server, Redhat Enterprise Linux Workstation, Adobe Flash Player, Apple Macos.