HomeSecurityAdobe Flash Player v16.0.0.235 fixes vulnerabilities

Adobe Flash Player v16.0.0.235 fixes vulnerabilities

Adobe has patched six vulnerabilities in the latest Flash Player security update , 16.0.0.235 , and an exploit for one of them is already available.

Adobe Flash Player update

The vulnerability CVE-2014-9163, reported by bilou from the HP Zero Day Initiative (ZDI), is a stack-based buffer overflow bug that can be exploited to execute arbitrary code on the system.

There are no further details at this time, but users are advised to install the latest version of Flash as soon as possible. Google Chrome (regardless of operating system) and Internet Explorer apply the new version automatically, via their built-in update mechanism.

The company informs in a security bulletin that not all previous versions of the program are vulnerable and that users who have already installed version 15.0.0.246 are out of the danger zone regarding CVE-2014-9163. Nevertheless, the new update should be applied because it also incorporates other security fixes.

Most of the vulnerabilities being fixed could allow an attacker to execute arbitrary code on affected systems. To mitigate this risk, the company addressed two memory corruption and a use-after-free glitch.

Two additional patches address an information disclosure vulnerability (CVE-2014-9162) and an exploitable vulnerability (CVE-2014-0580), which does not allow for code interference from outside the application.

The latest Flash security update is 16.0.0.235 for Windows and Mac platforms , for which it was classified as top priority by the developer. In the case of Linux , the latest version is 11.2.202.425, and Adobe recommends that administrators install it "at their discretion."

In case the automatic update feature is not enabled, the latest Flash Player must be installed manually.

In addition to Flash, Adobe also released 20 patches for its Reader and Acrobat , increasing the version number to 11.0.10.

One of the issues being fixed is identified as CVE-2014-9150, and could allow an attacker to bypass the sandbox and write code to areas of the system, via an NTFS junction.

However, exploiting this vulnerability in an earlier version of Adobe Reader is nearly impossible because the company implemented modifications that prevent the attack, according to James Forshaw of Google Project Zero, who disclosed the issue.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS