Explore top 10 tips to secure your open-source projects now. Read More
×The updated packages fix a security vulnerability: Use after free that leads to arbitrary code execution in the context of the current user. (CVE-2020-9633) References: . MGASA-2020-0264 - Updated flash-player-plugin packages fix security vulnerability Publication date: 15 Jun 2020 URL: https://advisories.mageia.org/MGASA-2020-0264.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-9633 The updated packages fix a security vulnerability: Use after free that leads to arbitrary code execution in the context of the current user. (CVE-2020-9633) References: - https://bugs.mageia.org/show_bug.cgi?id=26779 - - https://www.cve.org/CVERecord?id=CVE-2020-9633 SRPMS: - 7/nonfree/flash-player-plugin-32.0.0.387-1.mga7.nonfree . This advisory for Mageia 7 emphasizes vital updates for the Flash Player plugin, addressing vulnerabilities that could affect users' systems and ensure software security.. Mageia Security, Flash Player Update, Arbitrary Code Execution. . Severity: Critical. LinuxSecurity.com Team
Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201911-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Adobe Flash Player: Multiple vulnerabilities Date: November 25, 2019 Bugs: #694352 ID: 201911-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which could result in the arbitrary execution of code. Background ========= The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-plugins/adobe-flash < 32.0.0.255 > = 32.0.0.255 Description ========== Multiple vulnerabilities have been discovered in Adobe Flash Player. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Adobe Flash Player users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =www-plugins/adobe-flash-32.0.0.255" References ========= [ 1 ] CVE-2019-8069 https://nvd.nist.gov/vuln/detail/CVE-2019-8069 [ 2 ] CVE-2019-8070 https://nvd.nist.gov/vuln/detail/CVE-2019-8070 Availability =========== This GLSA and any updates to it are available forviewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201911-05 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201908-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Adobe Flash Player: Multiple vulnerabilities Date: August 18, 2019 Bugs: #683006, #687894 ID: 201908-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which could result in the arbitrary execution of code. Background ========= The Adobe Flash Player is a renderer for the SWF file format, which is commonly used to provide interactive websites. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-plugins/adobe-flash < 32.0.0.207 > = 32.0.0.207 Description ========== Multiple vulnerabilities have been discovered in Adobe Flash Player. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could possibly execute arbitrary code with the privileges of the process or bypass security restrictions. Workaround ========= There is no known workaround at this time. Resolution ========= All Adobe Flash Player users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =www-plugins/adobe-flash-32.0.0.207" References ========= [ 1 ] CVE-2019-7096 https://nvd.nist.gov/vuln/detail/CVE-2019-7096 [ 2 ] CVE-2019-7108 https://nvd.nist.gov/vuln/detail/CVE-2019-7108 [ 3 ]CVE-2019-7845 https://nvd.nist.gov/vuln/detail/CVE-2019-7845 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201908-21 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
MGASA-2019-0178 - Updated flash-player-plugin packages fix security vulnerability Publication date: 18 May 2019 URL: https://advisories.mageia.org/MGASA-2019-0178.html Type: security Affected Mageia releases: 6 CVE: CVE-2019-7837 A use after free that leads to arbitrary code execution. (CVE-2019-7837) References: - https://bugs.mageia.org/show_bug.cgi?id=24822 - - https://www.cve.org/CVERecord?id=CVE-2019-7837 SRPMS: - 6/nonfree/flash-player-plugin-32.0.0.192-1.mga6.nonfree . A use after free that leads to arbitrary code execution. (CVE-2019-7837) References: - https://bugs.mageia.org/show_bug.cgi?id=24822 - . MGASA-2021-0034 highlights a serious vulnerability in pdf-viewer for Mageia 7 requiring an urgent patch.. flash Player security update, Mageia advisories, code execution risk. . Severity: Critical. LinuxSecurity.com Team
An out-of-bounds read that leads to information disclosure. (CVE-2019-7108) A use after free that leads to arbitrary code execution. (CVE-2019-7096) References: . MGASA-2019-0149 - Updated flash-player-plugin packages fix security vulnerability Publication date: 10 Apr 2019 URL: https://advisories.mageia.org/MGASA-2019-0149.html Type: security Affected Mageia releases: 6 CVE: CVE-2019-7096, CVE-2019-7108 An out-of-bounds read that leads to information disclosure. (CVE-2019-7108) A use after free that leads to arbitrary code execution. (CVE-2019-7096) References: - https://bugs.mageia.org/show_bug.cgi?id=24643 - - https://www.cve.org/CVERecord?id=CVE-2019-7096 - https://www.cve.org/CVERecord?id=CVE-2019-7108 SRPMS: - 6/nonfree/flash-player-plugin-32.0.0.171-1.mga6.nonfree . Newly released packages for the flash-player-plugin address security vulnerabilities in Mageia, with corresponding CVE identifiers listed for further information.. Flash Player Update, Mageia Security, Code Execution Risk, Information Disclosure, Software Patch. . Severity: Critical. LinuxSecurity.com Team
MGASA-2019-0090 - Updated flash-player-plugin packages fix security vulnerability Publication date: 17 Feb 2019 URL: https://advisories.mageia.org/MGASA-2019-0090.html Type: security Affected Mageia releases: 6 CVE: CVE-2019-7090 Information disclosure in the context of the current user. (CVE-2019-7090) References: - https://bugs.mageia.org/show_bug.cgi?id=24363 - - https://www.cve.org/CVERecord?id=CVE-2019-7090 SRPMS: - 6/nonfree/flash-player-plugin-32.0.0.142-1.mga6.nonfree . Information disclosure in the context of the current user. (CVE-2019-7090) References: - https://bugs.mageia.org/show_bug.cgi?id=24363 - . Information disclosure in the context of the current user. (CVE-2019-7090) References: - https://b. mgasa-2019-0090, updated, flash-player-plugin, packages, security, vulnerability, publication. . LinuxSecurity.com Team
Use after free flaw enabling arbitrary code execution. (CVE-2018-15982) Insecure Library Loading (DLL hijacking) flaw enabling privilege escalation. (CVE-2018-15983) . MGASA-2018-0478 - Updated flash-player-plugin packages fix security vulnerability Publication date: 07 Dec 2018 URL: https://advisories.mageia.org/MGASA-2018-0478.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-15982, CVE-2018-15983 Use after free flaw enabling arbitrary code execution. (CVE-2018-15982) Insecure Library Loading (DLL hijacking) flaw enabling privilege escalation. (CVE-2018-15983) References: - https://bugs.mageia.org/show_bug.cgi?id=23950 - - https://www.cve.org/CVERecord?id=CVE-2018-15982 - https://www.cve.org/CVERecord?id=CVE-2018-15983 SRPMS: - 6/nonfree/flash-player-plugin-32.0.0.101-1.mga6.nonfree . Critical patch for Mageia's flash-player add-on resolving vulnerabilities related to potential code execution and privilege elevation risks.. Mageia Security, Flash Player, Security Update, Plugin Update. . LinuxSecurity.com Team
An update that fixes 13 vulnerabilities is now available. An update that fixes 13 vulnerabilities is now available. An update that fixes 13 vulnerabilities is now available.. SUSE Security Update: Security update for flash-player ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:0108-1 Rating: important References: #1019129 Cross-References: CVE-2017-2925 CVE-2017-2926 CVE-2017-2927 CVE-2017-2928 CVE-2017-2930 CVE-2017-2931 CVE-2017-2932 CVE-2017-2933 CVE-2017-2934 CVE-2017-2935 CVE-2017-2936 CVE-2017-2937 CVE-2017-2938 Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP1 SUSE Linux Enterprise Desktop 12-SP1 ______________________________________________________________________________ An update that fixes 13 vulnerabilities is now available. Description: This update to Adobe Flash 24.0.0.194 fixes the following vulnerabilities advised under APSB17-02: - security bypass vulnerability that could lead to information disclosure (CVE-2017-2938) - use-after-free vulnerabilities that could lead to code execution (CVE-2017-2932, CVE-2017-2936, CVE-2017-2937) - heap buffer overflow vulnerabilities that could lead to code execution (CVE-2017-2927, CVE-2017-2933, CVE-2017-2934, CVE-2017-2935) - memory corruption vulnerabilities that could lead to code execution (CVE-2017-2925, CVE-2017-2926, CVE-2017-2928, CVE-2017-2930, CVE-2017-2931) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP1: zypper in -t patch SUSE-SLE-WE-12-SP1-2017-51=1 - SUSE Linux Enterprise Desktop 12-SP1: zypper in -t patch SUSE-SLE-DESKTOP-12-SP1-2017-51=1 To bring your system up-to-date, use "zypperpatch". Package List: - SUSE Linux Enterprise Workstation Extension 12-SP1 (x86_64): flash-player-24.0.0.194-155.1 flash-player-gnome-24.0.0.194-155.1 - SUSE Linux Enterprise Desktop 12-SP1 (x86_64): flash-player-24.0.0.194-155.1 flash-player-gnome-24.0.0.194-155.1 References: https://www.suse.com/security/cve/CVE-2017-2925.html https://www.suse.com/security/cve/CVE-2017-2926.html https://www.suse.com/security/cve/CVE-2017-2927.html https://www.suse.com/security/cve/CVE-2017-2928.html https://www.suse.com/security/cve/CVE-2017-2930.html https://www.suse.com/security/cve/CVE-2017-2931.html https://www.suse.com/security/cve/CVE-2017-2932.html https://www.suse.com/security/cve/CVE-2017-2933.html https://www.suse.com/security/cve/CVE-2017-2934.html https://www.suse.com/security/cve/CVE-2017-2935.html https://www.suse.com/security/cve/CVE-2017-2936.html https://www.suse.com/security/cve/CVE-2017-2937.html https://www.suse.com/security/cve/CVE-2017-2938.html https://bugzilla.suse.com/1019129 . SUSE has released a security update for flash-player that fixes several critical vulnerabilities. It is important to implement these updates promptly.. SUSE Security, Flash Player Update, Vulnerability Fix, Linux Patch Management. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.