MGASA-2018-0120
Dashboard / Vulnerabilities / MGASA-2018-0120
Summary: Updated flash-player-plugin packages fix security vulnerability
Details: Adobe Flash Player 28.0.0.161 addresses critical use-after-free vulnerabilities that could lead to remote code execution (CVE-2018-4877, CVE-2018-4878). Successful exploitation could potentially allow an attacker to take control of the affected system. Adobe is aware of a report that an exploit for CVE-2018-4878 exists in the wild, and is being used in limited, targeted attacks against Windows users. These attacks leverage Office documents with embedded malicious Flash content distributed via email.
References: https://advisories.mageia.org/MGASA-2018-0120.html, https://bugs.mageia.org/show_bug.cgi?id=22534, https://helpx.adobe.com/security/products/flash-player/apsb18-03.html
Affected packages
Package
Name: flash-player-plugin
Purl: pkg:rpm/mageia/flash-player-plugin?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
