MGASA-2014-0035
Dashboard / Vulnerabilities / MGASA-2014-0035
Summary: Updated flash-player-plugin packages fix CVE-2014-0497
Details: Adobe Flash Player 11.2.202.336 contains a fix to a critical security vulnerability found in earlier versions that could cause a crash and potentially allow an attacker to remotely take control of the affected system. This update resolves an integer underflow vulnerability that could be exploited to execute arbitrary code on the affected system (CVE-2014-0497). Adobe is aware of reports that an exploit for this vulnerability exists in the wild.
References: https://advisories.mageia.org/MGASA-2014-0035.html, http://helpx.adobe.com/security/products/flash-player/apsb14-04.html, https://bugs.mageia.org/show_bug.cgi?id=12581
Affected packages
Package
Name: flash-player-plugin
Purl: pkg:rpm/mageia/flash-player-plugin?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
