Updated flash-player-plugin packages fix security vulnerabilities
Publication date: 27 Jan 2015Modification date: 27 Jan 2015
Type: security
Affected Mageia releases : 4
CVE: CVE-2015-0311 , CVE-2015-0312
Description
Adobe Flash Player 11.2.202.440 contains fixes to critical security
vulnerabilities found in earlier versions that could cause a crash and
potentially allow an attacker to take control of the affected system.
Adobe reports that CVE-2015-0311 is already being actively exploited in the
wild via drive-by-download attacks against systems running Internet Explorer
and Firefox on Windows.
This update resolves a use-after-free vulnerability that could lead to code
execution (CVE-2015-0311).
This update resolves a double-free vulnerability that could lead to code
execution (CVE-2015-0312).
References
SRPMS
4/nonfree
- flash-player-plugin-11.2.202.440-1.1.mga4.nonfree