CVE-2017-3114
Description
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of providing language- and region- or country- specific functionality. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
Red Hat Affected 1 release
| Version | Status | Fixed in |
|---|---|---|
| 6.0 | Affected | โ |
Linux kernel Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| - | Not affected | โ |
macOS Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| - | Not affected | โ |
Windows Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| - | Not affected | โ |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| adobe | flash_player | {"endIncluding":"27.0.0.183"} | |
References
- http://www.securityfocus.com/bid/101837
- http://www.securitytracker.com/id/1039778
- https://access.redhat.com/errata/RHSA-2017:3222
- https://helpx.adobe.com/security/products/flash-player/apsb17-33.html
- https://security.gentoo.org/glsa/201711-13
- http://www.securityfocus.com/bid/101837
- http://www.securitytracker.com/id/1039778
- https://access.redhat.com/errata/RHSA-2017:3222
- https://helpx.adobe.com/security/products/flash-player/apsb17-33.html
- https://security.gentoo.org/glsa/201711-13
CWEs
CWE-125
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.