Vulnerability CVE-2016-7877: Information

Description

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the Action Message Format serialization (AFM0). Successful exploitation could lead to arbitrary code execution.

Severity: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: Dec. 15, 2016
Modified: Nov. 17, 2022
Error type identifier: CWE-416

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
adobe-flash-player-ppapip924-alt132-alt118ALT-PU-2016-2445-1174384Fixed
adobe-flash-player-ppapip824-alt132-alt118ALT-PU-2016-2449-1174385Fixed
adobe-flash-player-ppapic9f224-alt132-alt115ALT-PU-2016-2445-1174384Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://helpx.adobe.com/security/products/flash-player/apsb16-39.html
  • Patch
  • Vendor Advisory
94873
  • Third Party Advisory
  • VDB Entry
1037442
  • Broken Link
  • Third Party Advisory
  • VDB Entry
RHSA-2016:2947
  • Third Party Advisory
openSUSE-SU-2016:3160
  • Broken Link
SUSE-SU-2016:3148
  • Broken Link
GLSA-201701-17
  • Third Party Advisory
MS16-154
  • Patch
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:adobe:flash_player_desktop_runtime:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

      Configuration 2

      cpe:2.3:a:adobe:flash_player:*:*:*:*:*:edge:*:*

      cpe:2.3:a:adobe:flash_player:*:*:*:*:*:internet_explorer:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:a:adobe:flash_player:*:*:*:*:*:chrome:*:*

      Running on/with:
      cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:google:chrome_os:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*