CVE-2017-3112
published 2017-12-09CVE-2017-3112: An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is…
PriorityP350critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
6.22%
92.7th percentile
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of AdobePSDK metadata. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 27.0.0.183 | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qm8j-pmc4-xr8w: An issue was discovered in Adobe Flash Player 27
ghsa_unreviewed·2022-05-13
CVE-2017-3112 [CRITICAL] CWE-125 GHSA-qm8j-pmc4-xr8w: An issue was discovered in Adobe Flash Player 27
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of AdobePSDK metadata. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.
OSV
CVE-2017-3112: An issue was discovered in Adobe Flash Player 27
osv·2017-12-09·CVSS 9.8
CVE-2017-3112 [CRITICAL] CVE-2017-3112: An issue was discovered in Adobe Flash Player 27
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of AdobePSDK metadata. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.
Red Hat
flash-plugin: multiple code execution issues fixed in APSB17-33
vendor_redhat·2017-11-14·CVSS 9.8
CVE-2017-3112 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB17-33
flash-plugin: multiple code execution issues fixed in APSB17-33
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of AdobePSDK metadata. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.
Red Hat
chromium-browser: url spoofing in omnibox
vendor_redhat·2017-07-25·CVSS 6.5
CVE-2017-5106 [MEDIUM] chromium-browser: url spoofing in omnibox
chromium-browser: url spoofing in omnibox
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
Red Hat
chromium-browser: type confusion in pdfium
vendor_redhat·2017-07-25·CVSS 8.8
CVE-2017-5108 [HIGH] chromium-browser: type confusion in pdfium
chromium-browser: type confusion in pdfium
Type confusion in PDFium in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to potentially maliciously modify objects via a crafted PDF file.
Red Hat
chromium-browser: use after free in ppapi
vendor_redhat·2017-07-25·CVSS 8.8
CVE-2017-5092 [HIGH] CWE-416 chromium-browser: use after free in ppapi
chromium-browser: use after free in ppapi
Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Red Hat
chromium-browser: ui spoofing in blink
vendor_redhat·2017-07-25·CVSS 6.5
CVE-2017-5093 [MEDIUM] CWE-223 chromium-browser: ui spoofing in blink
chromium-browser: ui spoofing in blink
Inappropriate implementation in modal dialog handling in Blink in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to prevent a full screen warning from being displayed via a crafted HTML page.
Red Hat
chromium-browser: use after free in indexeddb
vendor_redhat·2017-07-25·CVSS 8.8
CVE-2017-5091 [HIGH] CWE-416 chromium-browser: use after free in indexeddb
chromium-browser: use after free in indexeddb
A use after free in IndexedDB in Google Chrome prior to 60.0.3112.78 for Linux, Android, Windows, and Mac allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Red Hat
chromium-browser: use after free in v8
vendor_redhat·2017-07-25·CVSS 8.8
CVE-2017-5098 [HIGH] CWE-416 chromium-browser: use after free in v8
chromium-browser: use after free in v8
A use after free in V8 in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Red Hat
chromium-browser: out-of-bounds read in skia
vendor_redhat·2017-07-25·CVSS 8.8
CVE-2017-5097 [HIGH] CWE-125 chromium-browser: out-of-bounds read in skia
chromium-browser: out-of-bounds read in skia
Insufficient validation of untrusted input in Skia in Google Chrome prior to 60.0.3112.78 for Linux allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Red Hat
chromium-browser: user information leak via android intents
vendor_redhat·2017-07-25·CVSS 4.3
CVE-2017-5096 [MEDIUM] CWE-200 chromium-browser: user information leak via android intents
chromium-browser: user information leak via android intents
Insufficient policy enforcement during navigation between different schemes in Google Chrome prior to 60.0.3112.78 for Android allowed a remote attacker to perform cross origin content download via a crafted HTML page, related to intents.
Red Hat
chromium-browser: uninitialized use in skia
vendor_redhat·2017-07-25·CVSS 4.3
CVE-2017-5103 [MEDIUM] chromium-browser: uninitialized use in skia
chromium-browser: uninitialized use in skia
Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Red Hat
chromium-browser: type confusion in extensions
vendor_redhat·2017-07-25·CVSS 6.5
CVE-2017-5094 [MEDIUM] CWE-843 chromium-browser: type confusion in extensions
chromium-browser: type confusion in extensions
Type confusion in extensions JavaScript bindings in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to potentially maliciously modify objects via a crafted HTML page.
Red Hat
chromium-browser: uninitialized use in skia
vendor_redhat·2017-07-25·CVSS 4.3
CVE-2017-5102 [MEDIUM] chromium-browser: uninitialized use in skia
chromium-browser: uninitialized use in skia
Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Red Hat
chromium-browser: out-of-bounds write in pdfium
vendor_redhat·2017-07-25·CVSS 8.8
CVE-2017-5095 [HIGH] CWE-787 chromium-browser: out-of-bounds write in pdfium
chromium-browser: out-of-bounds write in pdfium
Stack overflow in PDFium in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit stack corruption via a crafted PDF file.
Red Hat
chromium-browser: user information leak via svg
vendor_redhat·2017-07-25·CVSS 5.3
CVE-2017-5107 [MEDIUM] chromium-browser: user information leak via svg
chromium-browser: user information leak via svg
A timing attack in SVG rendering in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to extract pixel values from a cross-origin page being iframe'd via a crafted HTML page.
Red Hat
chromium-browser: url spoofing in omnibox
vendor_redhat·2017-07-25·CVSS 6.5
CVE-2017-5105 [MEDIUM] chromium-browser: url spoofing in omnibox
chromium-browser: url spoofing in omnibox
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
Red Hat
chromium-browser: ui spoofing in payments dialog
vendor_redhat·2017-07-25·CVSS 6.5
CVE-2017-5110 [MEDIUM] chromium-browser: ui spoofing in payments dialog
chromium-browser: ui spoofing in payments dialog
Inappropriate implementation of the web payments API on blob: and data: schemes in Web Payments in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to spoof the contents of the Omnibox via a crafted HTML page.
Red Hat
chromium-browser: out-of-bounds write in ppapi
vendor_redhat·2017-07-25·CVSS 8.8
CVE-2017-5099 [HIGH] CWE-787 chromium-browser: out-of-bounds write in ppapi
chromium-browser: out-of-bounds write in ppapi
Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to potentially gain privilege elevation via a crafted HTML page.
Red Hat
chromium-browser: url spoofing in omnibox
vendor_redhat·2017-07-25·CVSS 6.5
CVE-2017-5101 [MEDIUM] chromium-browser: url spoofing in omnibox
chromium-browser: url spoofing in omnibox
Inappropriate implementation in Omnibox in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to spoof the contents of the Omnibox via a crafted HTML page.
Red Hat
chromium-browser: ui spoofing in browser
vendor_redhat·2017-07-25·CVSS 4.3
CVE-2017-5109 [MEDIUM] chromium-browser: ui spoofing in browser
chromium-browser: ui spoofing in browser
Inappropriate implementation of unload handler handling in permission prompts in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to display UI on a non attacker controlled tab via a crafted HTML page.
Red Hat
chromium-browser: use after free in chrome apps
vendor_redhat·2017-07-25·CVSS 8.8
CVE-2017-5100 [HIGH] chromium-browser: use after free in chrome apps
chromium-browser: use after free in chrome apps
A use after free in Apps in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Red Hat
chromium-browser: ui spoofing in browser
vendor_redhat·2017-07-25·CVSS 6.5
CVE-2017-5104 [MEDIUM] chromium-browser: ui spoofing in browser
chromium-browser: ui spoofing in browser
Inappropriate implementation in interstitials in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to spoof the contents of the omnibox via a crafted HTML page.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-11213 CVE-2017-11215 CVE-2017-11225 CVE-2017-3112 CVE-2017-3114 flash-plugin: multiple code execution issues fixed in APSB17-33
bugzilla·2017-11-14·CVSS 9.8
CVE-2017-11213 [CRITICAL] CVE-2017-11213 CVE-2017-11215 CVE-2017-11225 CVE-2017-3112 CVE-2017-3114 flash-plugin: multiple code execution issues fixed in APSB17-33
CVE-2017-11213 CVE-2017-11215 CVE-2017-11225 CVE-2017-3112 CVE-2017-3114 flash-plugin: multiple code execution issues fixed in APSB17-33
Adobe Security Bulletin APSB17-33 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB17-33:
Out-of-bounds Read Remote Code Execution Critical CVE-2017-3112
Out-of-bounds Read Remote Code Execution Critical CVE-2017-3114
Out-of-bounds Read Remote Code Execution Critical CVE-2017-11213
Use after free Remote Code Execution Critical CVE-2017-11215
Use after free Remote Code Execution Critical CVE-2017-11225
External References:
https://helpx.adobe.com/security/products/flash-player/apsb17-33.html
Discussion:
This issue has been add
Talos
Vulnerability Spotlight: Google PDFium Tiff Code Execution
blogs_talos·2017-10-19·CVSS 8.8
[HIGH] Vulnerability Spotlight: Google PDFium Tiff Code Execution
## Overview
Talos is disclosing a single off-by-one read/write vulnerability found in the TIFF image decoder functionality of PDFium as used in Google Chrome up to and including version 60.0.3112.101. Google Chrome is the most widely used web browser today and a specially crafted PDF could trigger the vulnerability resulting in memory corruption, possible information leak, and potential code execution. This issue has been fixed in Google Chrome version 62.0.3202.62.
## TALOS-2017-0432
Discovered by Aleksandar Nikolic of Cisco Talos
Talos-2017-0432 / CVE-2017-5133 is an off-by-one read/write vulnerability residing in the TIFF image decoder functionality of PDFium. PDFium is an open sourced PDF renderer developed by Google and used in the Chrome web browser, online services, and other st
Talos
Vulnerability Spotlight: Google PDFium Tiff Code Execution
blogs_talos·2017-10-19·CVSS 8.8
[HIGH] Vulnerability Spotlight: Google PDFium Tiff Code Execution
## Vulnerability Spotlight: Google PDFium Tiff Code Execution
## Overview
Talos is disclosing a single off-by-one read/write vulnerability found in the TIFF image decoder functionality of PDFium as used in Google Chrome up to and including version 60.0.3112.101. Google Chrome is the most widely used web browser today and a specially crafted PDF could trigger the vulnerability resulting in memory corruption, possible information leak, and potential code execution. This issue has been fixed in Google Chrome version 62.0.3202.62 .
## TALOS-2017-0432
Discovered by Aleksandar Nikolic of Cisco Talos
Talos-2017-0432 / CVE-2017-5133 is an off-by-one read/write vulnerability residing in the TIFF image decoder functionality of PDFium. PDFium is an open sourced PDF renderer developed by Google a
Zscaler
Zscaler protects against 40 new vulnerabilities for Adobe Fl
blogs_zscaler
Zscaler protects against 40 new vulnerabilities for Adobe Fl
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
http://www.securityfocus.com/bid/101837http://www.securitytracker.com/id/1039778https://access.redhat.com/errata/RHSA-2017:3222https://helpx.adobe.com/security/products/flash-player/apsb17-33.htmlhttps://security.gentoo.org/glsa/201711-13http://www.securityfocus.com/bid/101837http://www.securitytracker.com/id/1039778https://access.redhat.com/errata/RHSA-2017:3222https://helpx.adobe.com/security/products/flash-player/apsb17-33.htmlhttps://security.gentoo.org/glsa/201711-13
2017-12-09
Published