ALT-BU-2014-2601-1
Branch p7 update bulletin.
Package adobe-flash-player updated to version 11-alt26 for branch p7 in task 114961.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2014-0498
Stack-based buffer overflow in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows attackers to execute arbitrary code via unspecified vectors.
- http://helpx.adobe.com/security/products/flash-player/apsb14-07.html
- http://helpx.adobe.com/security/products/flash-player/apsb14-07.html
- openSUSE-SU-2014:0277
- openSUSE-SU-2014:0277
- openSUSE-SU-2014:0278
- openSUSE-SU-2014:0278
- SUSE-SU-2014:0290
- SUSE-SU-2014:0290
- RHSA-2014:0196
- RHSA-2014:0196
- GLSA-201405-04
- GLSA-201405-04
Modified: 2024-11-21
CVE-2014-0499
Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 do not prevent access to address information, which makes it easier for attackers to bypass the ASLR protection mechanism via unspecified vectors.
- http://helpx.adobe.com/security/products/flash-player/apsb14-07.html
- http://helpx.adobe.com/security/products/flash-player/apsb14-07.html
- openSUSE-SU-2014:0277
- openSUSE-SU-2014:0277
- openSUSE-SU-2014:0278
- openSUSE-SU-2014:0278
- SUSE-SU-2014:0290
- SUSE-SU-2014:0290
- RHSA-2014:0196
- RHSA-2014:0196
- GLSA-201405-04
- GLSA-201405-04
Modified: 2024-11-21
CVE-2014-0502
Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.
- http://helpx.adobe.com/security/products/flash-player/apsb14-07.html
- http://helpx.adobe.com/security/products/flash-player/apsb14-07.html
- openSUSE-SU-2014:0277
- openSUSE-SU-2014:0277
- openSUSE-SU-2014:0278
- openSUSE-SU-2014:0278
- SUSE-SU-2014:0290
- SUSE-SU-2014:0290
- RHSA-2014:0196
- RHSA-2014:0196
- GLSA-201405-04
- GLSA-201405-04
- http://www.alienvault.com/open-threat-exchange/blog/analysis-of-an-attack-exploiting-the-adobe-zero-day-cve-2014-0502/
- http://www.alienvault.com/open-threat-exchange/blog/analysis-of-an-attack-exploiting-the-adobe-zero-day-cve-2014-0502/
- https://volatility-labs.blogspot.com/2014/04/building-decoder-for-cve-2014-0502.html
- https://volatility-labs.blogspot.com/2014/04/building-decoder-for-cve-2014-0502.html