UBUNTU-CVE-2019-7837

Source
https://ubuntu.com/security/CVE-2019-7837
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-7837.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2019-7837
Upstream
Published
2019-05-22T19:29:00Z
Modified
2025-07-16T07:40:19.800242Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Adobe Flash Player versions 32.0.0.171 and earlier, 32.0.0.171 and earlier, and 32.0.0.171 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

References

Affected packages

Ubuntu:16.04:LTS / flashplugin-nonfree

Package

Name
flashplugin-nonfree
Purl
pkg:deb/ubuntu/flashplugin-nonfree@32.0.0.192ubuntu0.16.04.1?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
32.0.0.192ubuntu0.16.04.1

Affected versions

11.*
11.2.202.540ubuntu2
11.2.202.548ubuntu1
11.2.202.554ubuntu1
11.2.202.559ubuntu1
11.2.202.569ubuntu1
11.2.202.577ubuntu1
11.2.202.616ubuntu1
11.2.202.621ubuntu0.16.04.1
11.2.202.626ubuntu0.16.04.1
11.2.202.632ubuntu0.16.04.1
11.2.202.635ubuntu0.16.04.1
11.2.202.637ubuntu0.16.04.1
11.2.202.643ubuntu0.16.04.1
11.2.202.644ubuntu0.16.04.1
24.*
24.0.0.186ubuntu0.16.04.1
24.0.0.194ubuntu0.16.04.1
24.0.0.221ubuntu0.16.04.1
25.*
25.0.0.127ubuntu0.16.04.1
25.0.0.148ubuntu0.16.04.1
25.0.0.171ubuntu0.16.04.1
26.*
26.0.0.126ubuntu0.16.04.1
26.0.0.131ubuntu0.16.04.1
26.0.0.137ubuntu0.16.04.1
26.0.0.151ubuntu0.16.04.1
27.*
27.0.0.130ubuntu0.16.04.1
27.0.0.159ubuntu0.16.04.1
27.0.0.170ubuntu0.16.04.1
27.0.0.183ubuntu0.16.04.1
27.0.0.187ubuntu0.16.04.1
28.*
28.0.0.126ubuntu0.16.04.1
28.0.0.137ubuntu0.16.04.1
28.0.0.161ubuntu0.16.04.1
29.*
29.0.0.113ubuntu0.16.04.1
29.0.0.140ubuntu0.16.04.1
29.0.0.171ubuntu0.16.04.1
30.*
30.0.0.113ubuntu0.16.04.1
30.0.0.134ubuntu0.16.04.1
30.0.0.154ubuntu0.16.04.1
31.*
31.0.0.108ubuntu0.16.04.1
31.0.0.122ubuntu0.16.04.1
31.0.0.148ubuntu0.16.04.1
31.0.0.153ubuntu0.16.04.1
32.*
32.0.0.101ubuntu0.16.04.1
32.0.0.114ubuntu0.16.04.1
32.0.0.142ubuntu0.16.04.1
32.0.0.156ubuntu0.16.04.1
32.0.0.171ubuntu0.16.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "32.0.0.192ubuntu0.16.04.1",
            "binary_name": "flashplugin-downloader"
        },
        {
            "binary_version": "32.0.0.192ubuntu0.16.04.1",
            "binary_name": "flashplugin-installer"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-7837.json"

Ubuntu:18.04:LTS / flashplugin-nonfree

Package

Name
flashplugin-nonfree
Purl
pkg:deb/ubuntu/flashplugin-nonfree@32.0.0.192ubuntu0.18.04.1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
32.0.0.192ubuntu0.18.04.1

Affected versions

27.*
27.0.0.170ubuntu1
27.0.0.187ubuntu1
28.*
28.0.0.126ubuntu1
28.0.0.137ubuntu1
28.0.0.161ubuntu1
28.0.0.161ubuntu2
28.0.0.161ubuntu3
29.*
29.0.0.113ubuntu1
29.0.0.140ubuntu1
29.0.0.171ubuntu1
30.*
30.0.0.113ubuntu0.18.04.1
30.0.0.134ubuntu0.18.04.1
30.0.0.154ubuntu0.18.04.1
31.*
31.0.0.108ubuntu0.18.04.1
31.0.0.122ubuntu0.18.04.1
31.0.0.148ubuntu0.18.04.1
31.0.0.153ubuntu0.18.04.1
32.*
32.0.0.101ubuntu0.18.04.1
32.0.0.114ubuntu0.18.04.1
32.0.0.142ubuntu0.18.04.1
32.0.0.156ubuntu0.18.04.1
32.0.0.171ubuntu0.18.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "32.0.0.192ubuntu0.18.04.1",
            "binary_name": "flashplugin-downloader"
        },
        {
            "binary_version": "32.0.0.192ubuntu0.18.04.1",
            "binary_name": "flashplugin-installer"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-7837.json"