CVE-2015-3079
published 2015-05-13CVE-2015-3079: Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172…
PriorityP429medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
5.21%
91.6th percentile
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | air | <= 17.0.0.144 | — |
| adobe | air_sdk | <= 17.0.0.144 | — |
| adobe | air_sdk_compiler | <= 17.0.0.144 | — |
| adobe | flash_player | <= 13.0.0.264 | — |
| adobe | flash_player | <= 11.2.202.475 | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
| adobe | flash_player | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jjqw-3jh9-43m5: Adobe Flash Player before 13
ghsa_unreviewed·2022-05-17
CVE-2015-3079 [MEDIUM] GHSA-jjqw-3jh9-43m5: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
OSV
CVE-2015-3079: Adobe Flash Player before 13
osv·2015-05-13·CVSS 5.0
CVE-2015-3079 [MEDIUM] CVE-2015-3079: Adobe Flash Player before 13
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
Red Hat
flash-plugin: security bypass leading to information disclosure (APSB15-09)
vendor_redhat·2015-05-12·CVSS 5.0
CVE-2015-3079 [MEDIUM] flash-plugin: security bypass leading to information disclosure (APSB15-09)
flash-plugin: security bypass leading to information disclosure (APSB15-09)
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
No detection rules found.
No public exploits indexed.
HackerOne
Internet-based attacker can run Flash apps in local sandboxes by using special URL schemes (PSIRT-3299, CVE-2015-3079)
hackerone·2019-10-18·CVSS 5.0
CVE-2015-3079 [MEDIUM] Internet-based attacker can run Flash apps in local sandboxes by using special URL schemes (PSIRT-3299, CVE-2015-3079)
Internet-based attacker can run Flash apps in local sandboxes by using special URL schemes (PSIRT-3299, CVE-2015-3079)
Some of the sandbox logic of Flash Player can be circumvented on most web browsers by using special URL schemes. A website can deploy an SWF file via the data: or blob: URL schemes (perhaps others). An app started in this way runs in the "local with files" or "local with networking" sandbox, depending on the SWF attributes. This bug can be used in conjunction other attacks such as the Firefox-specific bug reported separately or MITM (CVE-2015-3044) to promote the local sandbox to "local trusted". This would allow unlimited cross-domain access.
On Chrome, the SWF can simply be encoded in a data: URL. This doesn't appear to work on other browsers (maybe there is a limit on
Bugzilla
CVE-2015-3079 flash-plugin: security bypass leading to information disclosure (APSB15-09)
bugzilla·2015-05-13·CVSS 5.0
CVE-2015-3079 [MEDIUM] CVE-2015-3079 flash-plugin: security bypass leading to information disclosure (APSB15-09)
CVE-2015-3079 flash-plugin: security bypass leading to information disclosure (APSB15-09)
Adobe Security Bulletin APSB15-09 for Adobe Flash Player describes a security bypass vulnerability that can be used to disclose sensitive information when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB15-09:
These updates resolve a security bypass vulnerability that could lead to information disclosure (CVE-2015-3079), and provide additional hardening to protect against CVE-2015-3044.
The CVE-2015-3044 was fixed via APSB15-06 and is tracked in Red Hat Bugzilla via bug 1211894.
External References:
https://helpx.adobe.com/security/products/flash-player/apsb15-09.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Ha
Zscaler
Zscaler detects Flash Player Vulnerabilities | 05-21-2015
blogs_zscaler
Zscaler detects Flash Player Vulnerabilities | 05-21-2015
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1005.htmlhttp://www.securityfocus.com/bid/74612http://www.securitytracker.com/id/1032285https://helpx.adobe.com/security/products/flash-player/apsb15-09.htmlhttps://security.gentoo.org/glsa/201505-02http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1005.htmlhttp://www.securityfocus.com/bid/74612http://www.securitytracker.com/id/1032285https://helpx.adobe.com/security/products/flash-player/apsb15-09.htmlhttps://security.gentoo.org/glsa/201505-02
2015-05-13
Published