UBUNTU-CVE-2015-5123

Source
https://ubuntu.com/security/CVE-2015-5123
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2015/UBUNTU-CVE-2015-5123.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2015-5123
Upstream
  • CVE-2015-5123
Published
2015-07-14T10:59:00Z
Modified
2025-11-19T16:48:16Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

References

Affected packages

Ubuntu:14.04:LTS / flashplugin-nonfree

Package

Name
flashplugin-nonfree
Purl
pkg:deb/ubuntu/flashplugin-nonfree@11.2.202.481ubuntu0.14.04.2?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
11.2.202.481ubuntu0.14.04.2

Affected versions

11.*
11.2.202.310ubuntu1
11.2.202.327ubuntu0.13.10.1
11.2.202.332ubuntu1
11.2.202.335ubuntu1
11.2.202.336ubuntu1
11.2.202.341ubuntu1
11.2.202.346ubuntu1
11.2.202.350ubuntu1
11.2.202.356ubuntu0.14.04.1
11.2.202.359ubuntu0.14.04.1
11.2.202.378ubuntu0.14.04.1
11.2.202.394ubuntu0.14.04.1
11.2.202.400ubuntu0.14.04.1
11.2.202.406ubuntu0.14.04.1
11.2.202.406ubuntu0.14.04.2
11.2.202.411ubuntu0.14.04.1
11.2.202.418ubuntu0.14.04.1
11.2.202.424ubuntu0.14.04.1
11.2.202.425ubuntu0.14.04.1
11.2.202.429ubuntu0.14.04.1
11.2.202.438ubuntu0.14.04.1
11.2.202.440ubuntu0.14.04.1
11.2.202.442ubuntu0.14.04.1
11.2.202.451ubuntu0.14.04.1
11.2.202.457ubuntu0.14.04.1
11.2.202.460ubuntu0.14.04.1
11.2.202.466ubuntu0.14.04.1
11.2.202.468ubuntu0.14.04.1
11.2.202.481ubuntu0.14.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "11.2.202.481ubuntu0.14.04.2",
            "binary_name": "flashplugin-downloader"
        },
        {
            "binary_version": "11.2.202.481ubuntu0.14.04.2",
            "binary_name": "flashplugin-installer"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2015/UBUNTU-CVE-2015-5123.json"