Vulnerability CVE-2016-7874: Information

Description

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable memory corruption vulnerability in the NetConnection class when handling the proxy types. Successful exploitation could lead to arbitrary code execution.

Severity: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: Dec. 15, 2016
Modified: Nov. 17, 2022
Error type identifier: CWE-787

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
adobe-flash-player-ppapip924-alt132-alt118ALT-PU-2016-2445-1174384Fixed
adobe-flash-player-ppapip824-alt132-alt118ALT-PU-2016-2449-1174385Fixed
adobe-flash-player-ppapic9f224-alt132-alt115ALT-PU-2016-2445-1174384Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://helpx.adobe.com/security/products/flash-player/apsb16-39.html
  • Patch
  • Vendor Advisory
94866
  • Third Party Advisory
  • VDB Entry
1037442
  • Broken Link
  • Third Party Advisory
  • VDB Entry
RHSA-2016:2947
  • Third Party Advisory
openSUSE-SU-2016:3160
  • Broken Link
SUSE-SU-2016:3148
  • Broken Link
GLSA-201701-17
  • Third Party Advisory
MS16-154
  • Patch
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

      Configuration 2

      cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:*

      cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:*

      Running on/with:
      cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:google:chrome_os:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*