Advisories ยป MGASA-2015-0043

Updated flash-player-plugin packages fix security vulnerabilities

Publication date: 27 Jan 2015
Type: security
Affected Mageia releases : 4
CVE: CVE-2015-0311 , CVE-2015-0312

Description

Adobe Flash Player 11.2.202.440 contains fixes to critical security
vulnerabilities found in earlier versions that could cause a crash and
potentially allow an attacker to take control of the affected system.

Adobe reports that CVE-2015-0311 is already being actively exploited in the 
wild via drive-by-download attacks against systems running Internet Explorer
and Firefox on Windows.

This update resolves a use-after-free vulnerability that could lead to code
execution (CVE-2015-0311).

This update resolves a double-free vulnerability that could lead to code
execution (CVE-2015-0312). 
                

References

SRPMS

4/nonfree