CVE-2018-4871
published 2018-01-09CVE-2018-4871: An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of computation that reads data that is…
PriorityP343high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
5.51%
91.9th percentile
An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of computation that reads data that is past the end of the target buffer. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 28.0.0.126 | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
flash-plugin: out-of-bounds read causing information leak (APSB18-01)
vendor_redhat·2018-01-09·CVSS 7.5
CVE-2018-4871 [HIGH] CWE-125 flash-plugin: out-of-bounds read causing information leak (APSB18-01)
flash-plugin: out-of-bounds read causing information leak (APSB18-01)
An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of computation that reads data that is past the end of the target buffer. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.
GHSA
GHSA-jhfm-prjw-6726: An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28
ghsa_unreviewed·2022-05-13
CVE-2018-4871 [HIGH] CWE-125 GHSA-jhfm-prjw-6726: An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28
An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of computation that reads data that is past the end of the target buffer. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1000852 freerdp: out of bounds read in drdynvc_process_capability_request
bugzilla·2018-12-21·CVSS 6.5
CVE-2018-1000852 [MEDIUM] CVE-2018-1000852 freerdp: out of bounds read in drdynvc_process_capability_request
CVE-2018-1000852 freerdp: out of bounds read in drdynvc_process_capability_request
FreeRDP 2.0.0-rc3 contains an out of bounds read vulnerability in drdynvc_process_capability_request function in channels/drdynvc/client/drdynvc_main.c file. To exploit this RDPClient must connect to the rdp server with the echo option. This can lead to a two-byte outbound reading from the client memory.
References:
https://github.com/FreeRDP/FreeRDP/issues/4866
Upstream Patch:
https://github.com/FreeRDP/FreeRDP/pull/4871/commits/baee520e3dd9be6511c45a14c5f5e77784de1471
Discussion:
Created freerdp tracking bugs for this issue:
Affects: epel-6 [bug 1661641]
Affects: fedora-28 [bug 1661642]
Created freerdp1.2 tracking bugs for this issue:
Affects: fedora-all [bug 1661643]
---
The same memory disclo
Bugzilla
CVE-2018-4871 flash-plugin: out-of-bounds read causing information leak (APSB18-01)
bugzilla·2018-01-09·CVSS 7.5
CVE-2018-4871 [HIGH] CVE-2018-4871 flash-plugin: out-of-bounds read causing information leak (APSB18-01)
CVE-2018-4871 flash-plugin: out-of-bounds read causing information leak (APSB18-01)
Adobe Security Bulletin APSB18-01 for Adobe Flash Player describes an out-of-bounds read flaw that can possibly lead to information disclosure when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB18-01:
Out-of-bounds Read Information Disclosure Important CVE-2018-4871
External References:
https://helpx.adobe.com/security/products/flash-player/apsb18-01.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0081 https://access.redhat.com/errata/RHSA-2018:0081
http://www.securityfocus.com/bid/102465http://www.securitytracker.com/id/1040155https://access.redhat.com/errata/RHSA-2018:0081https://helpx.adobe.com/security/products/flash-player/apsb18-01.htmlhttp://www.securityfocus.com/bid/102465http://www.securitytracker.com/id/1040155https://access.redhat.com/errata/RHSA-2018:0081https://helpx.adobe.com/security/products/flash-player/apsb18-01.html
2018-01-09
Published