CVE-2015-3044
published 2015-04-14CVE-2015-3044: Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to bypass…
PriorityP431medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
9.40%
94.9th percentile
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 13.0.0.264 | — |
| adobe | flash_player | <= 11.2.202.451 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| novell | suse_linux_enterprise_desktop | — | — |
| novell | suse_linux_enterprise_desktop | — | — |
| novell | suse_linux_enterprise_workstation_extension | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop_supplementary | — | — |
| redhat | enterprise_linux_desktop_supplementary | — | — |
| redhat | enterprise_linux_server_supplementary | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5xcc-vqv2-73j8: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-14
CVE-2015-3044 [MEDIUM] CWE-200 GHSA-5xcc-vqv2-73j8: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
OSV
CVE-2015-3044: Adobe Flash Player before 13
osv·2015-04-14·CVSS 5.0
CVE-2015-3044 [MEDIUM] CVE-2015-3044: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
Red Hat
flash-plugin: security bypass leading to information disclosure (APSB15-06)
vendor_redhat·2015-04-14·CVSS 5.0
CVE-2015-3044 [MEDIUM] flash-plugin: security bypass leading to information disclosure (APSB15-06)
flash-plugin: security bypass leading to information disclosure (APSB15-06)
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
No detection rules found.
No public exploits indexed.
HackerOne
Flash Player information disclosure (etc.) CVE-2015-3044, PSIRT-3298
hackerone·2019-10-18·CVSS 5.0
CVE-2015-3044 [MEDIUM] Flash Player information disclosure (etc.) CVE-2015-3044, PSIRT-3298
Flash Player information disclosure (etc.) CVE-2015-3044, PSIRT-3298
The vulnerability allows a malicious Flash app on a website to read and write Local Shared Objects belonging to any website. As a special case, LSO's of macromedia.com contain global Flash settings. Overwriting them allows e.g. unlimited access to camera and microphone of the target user. Other attacks are possible too, e.g. disclosure of sensitive information in LSO's (website-dependent) and triggering the double free bug in Flash Player Settings Manager reported separately.
The bug can be exploited with malformed jar: URLs on Firefox. Other browsers require other ways of spoofing the host, e.g. HTTP MITM or DNS spoofing.
The bug was patched in April 2015 and additional hardening in May 2015.
HackerOne
Internet-based attacker can run Flash apps in local sandboxes by using special URL schemes (PSIRT-3299, CVE-2015-3079)
hackerone·2019-10-18·CVSS 5.0
CVE-2015-3079 [MEDIUM] Internet-based attacker can run Flash apps in local sandboxes by using special URL schemes (PSIRT-3299, CVE-2015-3079)
Internet-based attacker can run Flash apps in local sandboxes by using special URL schemes (PSIRT-3299, CVE-2015-3079)
Some of the sandbox logic of Flash Player can be circumvented on most web browsers by using special URL schemes. A website can deploy an SWF file via the data: or blob: URL schemes (perhaps others). An app started in this way runs in the "local with files" or "local with networking" sandbox, depending on the SWF attributes. This bug can be used in conjunction other attacks such as the Firefox-specific bug reported separately or MITM (CVE-2015-3044) to promote the local sandbox to "local trusted". This would allow unlimited cross-domain access.
On Chrome, the SWF can simply be encoded in a data: URL. This doesn't appear to work on other browsers (maybe there is a limit on
Bugzilla
CVE-2015-3079 flash-plugin: security bypass leading to information disclosure (APSB15-09)
bugzilla·2015-05-13·CVSS 5.0
CVE-2015-3079 [MEDIUM] CVE-2015-3079 flash-plugin: security bypass leading to information disclosure (APSB15-09)
CVE-2015-3079 flash-plugin: security bypass leading to information disclosure (APSB15-09)
Adobe Security Bulletin APSB15-09 for Adobe Flash Player describes a security bypass vulnerability that can be used to disclose sensitive information when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB15-09:
These updates resolve a security bypass vulnerability that could lead to information disclosure (CVE-2015-3079), and provide additional hardening to protect against CVE-2015-3044.
The CVE-2015-3044 was fixed via APSB15-06 and is tracked in Red Hat Bugzilla via bug 1211894.
External References:
https://helpx.adobe.com/security/products/flash-player/apsb15-09.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Ha
Bugzilla
CVE-2015-3044 flash-plugin: security bypass leading to information disclosure (APSB15-06)
bugzilla·2015-04-15·CVSS 5.0
CVE-2015-3044 [MEDIUM] CVE-2015-3044 flash-plugin: security bypass leading to information disclosure (APSB15-06)
CVE-2015-3044 flash-plugin: security bypass leading to information disclosure (APSB15-06)
Adobe Security Bulletin APSB15-06 for Adobe Flash Player describes a security bypass vulnerability that can be used to disclose sensitive information when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB15-06:
These updates resolve a security bypass vulnerability that could lead to information disclosure (CVE-2015-3044).
External References:
https://helpx.adobe.com/security/products/flash-player/apsb15-06.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Supplementary for Red Hat Enterprise Linux 5
Via RHSA-2015:0813 https://rhn.redhat.com/errata/RHSA-2015-0813.html
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0813.htmlhttp://www.securityfocus.com/bid/74065http://www.securitytracker.com/id/1032105https://helpx.adobe.com/security/products/flash-player/apsb15-06.htmlhttps://security.gentoo.org/glsa/201504-07https://security.gentoo.org/glsa/201505-02http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0813.htmlhttp://www.securityfocus.com/bid/74065http://www.securitytracker.com/id/1032105https://helpx.adobe.com/security/products/flash-player/apsb15-06.htmlhttps://security.gentoo.org/glsa/201504-07https://security.gentoo.org/glsa/201505-02
2015-04-14
Published