CERT-In Vulnerability Note
CIVN-2014-0283
Multiple Vulnerabilities in Adobe flash Player
Original Issue Date:December 11, 2014
Severity Rating: HIGH
Systems Affected
- Adobe Flash Player 15.0.0.242 and earlier versions
- Adobe Flash Player 13.0.0.258 and earlier 13.x versions
- Adobe Flash Player 11.2.202.424 and earlier versions for Linux
Overview
Multiple vulnerabilities have been reported in Adobe Flash which could allow an unauthenticated remote attacker to execute arbitrary code , bypass security restrictions, or gain access to sensitive information on the affected system.
Description
These vulnerabilities are caused due to improper memory operations while processing Adobe Flash Content. Remote attackers could exploit these vulnerabilities by tricking a user to visit a crafted page or malformed file via unspecified vectors.
Successful exploitation of these vulnerabilities could allow remote attackers to execute arbitrary code, bypass security restrictions, or gain access to sensitive information on the affected system.
Solution
Apply appropriate patches as mentioned in Adobe Security Bulletin
APSB14-27
Vendor Information
Adobe
http://helpx.adobe.com/security/products/flash-player/apsb14-27.html
References
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=36704
Redhat
https://access.redhat.com/security/cve/CVE-2014-0580
https://access.redhat.com/security/cve/CVE-2014-0587
https://access.redhat.com/security/cve/CVE-2014-8443
https://access.redhat.com/security/cve/CVE-2014-9162
https://access.redhat.com/security/cve/CVE-2014-9163
https://access.redhat.com/security/cve/CVE-2014-9164
CVE Name
CVE-2014-0580
CVE-2014-0587
CVE-2014-8443
CVE-2014-9162
CVE-2014-9163
CVE-2014-9164
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|