HomeSecurityAdobe: Patches four security vulnerabilities in Flash Player

Adobe: Patches four security vulnerabilities in Flash Player

Four-Vulnerabilities-Fixed-With-the-Release-of-Adobe-Flash-Player-13-0-0-182

Adobe recently released an updated version of Flash Playerthat fixes four security vulnerabilities. Windows and Mac users are urged to upgrade to Flash version 13.0.0.182, while Linux users are urged to upgrade to version 11.2.202.350.

The first vulnerability fixed (CVE-2014-050) concerns a use-after-free bug, which could be used to execute arbitrary code. This vulnerability was discovered by a VUPEN researcher as part of the Pwn2Own 2014.

The second vulnerability (CVE-2014-0507) concerns a buffer overflow that could also lead to remote code execution. The issue was also identified on Pwn2Own by Zeguang Zhao and Liang Chen.

Finally, the update fixes a vulnerability that could lead to security bypass and sensitive data leakage (CVE-2014-0508), as well as a cross-site scripting vulnerability (CVE-2014-0509).

Some of the vulnerabilities were rated critical, as they could be exploited by attackers to gain control of affected systems. So far, there is no evidence that exploits have been created to exploit these vulnerabilities, but users are urged to upgrade to the new update as soon as possible as a precaution.

You can download Adobe Flash Player for Windows from Softpedia.  Adobe Flash Player for Mac and Adobe Flash Player for Linux are also available for download.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS