CISA KEV 정보
| 취약점명 | Adobe Flash Player ASLR Bypass Vulnerability |
|---|---|
| 설명 | Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism. |
| 조치사항 | The impacted product is end-of-life and should be disconnected if still in use. |
| 랜섬웨어 캠페인 악용 | Unknown |
| CWE | CWE-264 |
| 등록일 (KEV) | 2022-05-25 |
| 조치 기한 | 2022-06-15 |
| 추가 참고 | https://nvd.nist.gov/vuln/detail/CVE-2015-0310 |
NVD 상세 정보
CVSS v3.1: 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVSS v2.0: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C설명: Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015.
CWE: CWE-200
참조
- http://helpx.adobe.com/security/products/flash-player/apsb15-02.html [Patch, Vendor Advisory]
- http://secunia.com/advisories/62452 [Broken Link]
- http://secunia.com/advisories/62601 [Broken Link]
- http://secunia.com/advisories/62660 [Broken Link]
- http://secunia.com/advisories/62740 [Broken Link]
- http://security.gentoo.org/glsa/glsa-201502-02.xml [Third Party Advisory]
- http://www.securityfocus.com/bid/72261 [Broken Link, Third Party Advisory, VDB Entry]
- http://www.securitytracker.com/id/1031609 [Broken Link, Third Party Advisory, VDB Entry]
- http://helpx.adobe.com/security/products/flash-player/apsb15-02.html [Patch, Vendor Advisory]
- http://secunia.com/advisories/62452 [Broken Link]
- http://secunia.com/advisories/62601 [Broken Link]
- http://secunia.com/advisories/62660 [Broken Link]
- http://secunia.com/advisories/62740 [Broken Link]
- http://security.gentoo.org/glsa/glsa-201502-02.xml [Third Party Advisory]
- http://www.securityfocus.com/bid/72261 [Broken Link, Third Party Advisory, VDB Entry]
- ... 외 3건
This product uses the NVD API but is not endorsed or certified by the NVD.