Lucene search

K
hackeroneHhj4ckH1:122254
HistoryMar 11, 2016 - 3:54 a.m.

Internet Bug Bounty: Adobe Flash Player TextField Use-After-Free Vulnerability

2016-03-1103:54:25
hhj4ck
hackerone.com
22

EPSS

0.707

Percentile

98.1%

I. Summary
Adobe Flash Player is prone to a vulnerability which leads to Use-After-Free.

II. Description
If the variable parameter of a TextField instance equals to a getter property associated with swfRoot where the getter method includes a call to removeTextField(), the TextField instance is used after it is freed.

III. Impact
Use-After-Free

IV. Credit
Wen Guanxing from Venustech ADLAB is credited for this vulnerability.

It has been assigned by Adobe as CVE-2016-0990
https://helpx.adobe.com/security/products/flash-player/apsb16-08.html