Adobe Flash Player remote code execution vulnerability in CVE-2014-8439)
Release date:
Updated on:
Affected Systems:
Adobe Flash Player 15.x
Adobe Flash Player 14.x
Adobe Flash Player 13.x
Description:
Bugtraq id: 71289
CVE (CAN) ID: CVE-2014-8439
Adobe Flash Player is an integrated multimedia Player. Adobe AIR is a technology developed based on the combination of network and desktop applications. It can control cloud programs on the network without having to use a browser.
Adobe Flash Player versions earlier than 13.0.0.258, 14.x, 15.0.0.239 (Windows and OS X), and 11.2.202.424 (Linux ), the remote code execution vulnerability exists in Adobe AIR versions earlier than 0.0.0.293, Adobe air sdk 15.0.0.302, and Adobe air sdk & Compiler 15.0.0.302, attackers can exploit this vulnerability to execute arbitrary code in the context of the affected application.
<X Source: S & #195; & #169; bastien Duquette
Timo Hirvonen
Link: http://helpx.adobe.com/security/products/flash-player/apsb14-26.html
*>
Suggestion:
Vendor patch:
Adobe
-----
Adobe has released a Security Bulletin (apsb14-26) and patches for this:
Apsb14-26: Security updates available for Adobe Flash Player
Link: http://helpx.adobe.com/security/products/flash-player/apsb14-26.html
This article permanently updates the link address: